castai-install-auth

v2026.09.24

Choose and configure the correct CAST AI authentication boundary for castctl, REST API, Terraform, or enterprise child-organization access. Use when connecting a cluster, provisioning an automation identity, or repairing region and organization mismatches. Trigger with: "authenticate CAST AI", "set up a CAST AI API key", "configure CAST AI access".

GitHub
安装命令
npx skhub add jeremylongshore/castai-install-auth
Markdown
SKILL.md

CAST AI Authentication Boundary

Overview

Keep human castctl login, service API keys, enterprise organization targeting, and cluster installation secrets separate. Choose the narrowest identity for one client, region, organization, and lifecycle.

Prerequisites

  • The intended client: castctl, REST, Terraform, CI, or another approved integration
  • CAST AI organization, role binding, and environment region
  • An approved secret manager, rotation owner, and expiration or review date

Instructions

Step 1: Classify the actor

Use Read and Grep to find existing CAST AI environment variables, provider configuration, CI secrets, Helm values, and runbooks. Distinguish a human interactive session from non-interactive automation; do not reuse one credential across both.

Step 2: Select the authentication path

For human cluster connection, use Bash(castctl:*) with browser login; castctl stores its own local token and organization selection. For REST or Terraform automation, create an API access key whose inherited role bindings match the required operations.

Step 3: Pin region and organization

Use the documented US, EU, or India API base that matches the CAST AI environment. Send API keys only in the X-API-Key header. For an enterprise key targeting a child organization, also provide X-CastAI-Organization-Id; never infer that identifier from a cluster name.

Step 4: Store without exposure

Use Write or Edit to add secret references, not values, to configuration. Keep keys out of Git, command history, URLs, Terraform outputs, plan artifacts, Helm-rendered output, logs, and support bundles.

Step 5: Verify minimally

Use Bash(curl:*) only against a documented read endpoint selected from the current CAST AI API specification. Limit output to status and a non-sensitive identifier, set a timeout, and test the expected 401 or 403 path with no credential.

Step 6: Record lifecycle

Document owner, client, role basis, organization, region, storage location, creation time, review date, rotation procedure, and revocation condition. Because a created key cannot be viewed again, loss requires replacement rather than recovery.

Tool Discipline

Use Read and Grep for credential-reference discovery. Use Write and Edit only for secret references and lifecycle documentation. Use Bash(castctl:) for documented interactive auth and Bash(curl:) for a bounded read-only verification; never print headers or key values.

Output

  • Actor/client authentication decision
  • Region and organization boundary
  • Secret-reference configuration
  • Minimal verification and rotation record

Examples

A developer uses castctl browser login for a reviewed sandbox connection. A CI job uses a separate organization-scoped read-only API key against the EU endpoint and cannot target sibling organizations.

Error Handling

FailureResponse
A key appears in history or logsRevoke it, remove exposure, and create a replacement
API returns 401Verify key validity and regional base without widening permissions
API returns 403Review role bindings and organization targeting
Enterprise call hits wrong childStop and correct the explicit organization header

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/castai-install-auth

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8