add-user
Installation
SKILL.md
Add User
Add a new namespace-owner to the cluster. Two modes: automated (preferred) and manual (fallback).
SOPS state encryption access is automatically provisioned by the vault stack — per-stack Transit keys, policies, identity groups, and group aliases are all created from the k8s_users map. No manual SOPS setup required.
Automated Flow (Preferred)
Admin creates an Authentik invite → user signs up → provisioning happens automatically.
Steps
- Create Authentik Invitation
- Go to Authentik Admin
- Create a new invitation
- Pre-assign the user to the
kubernetes-namespace-ownersgroup - Copy the invite link