Auth Setup

goldsky-io/goldsky-agent/skills/auth-setup

作者 goldsky-ioaa52f88312de無授權條款12 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫今天更新

Set up Goldsky CLI authentication and project configuration. Use this skill when the user needs to: install the goldsky CLI (what's the official install command?), run goldsky login (including when the browser opens but 'authentication failed'), run goldsky project list and see 'not logged in' or 'unauthorized', switch between Goldsky projects, check which project they're currently authenticated to, or fix 'unauthorized' errors when running goldsky turbo commands. Also use for 'walk me through setting up goldsky CLI from scratch for the first time', and when they just installed Goldsky and say 'Set it up and help me get started'. If any other Goldsky skill hits an auth error, redirect here first.

包含腳本DevOps & Cloud
AI 產生的概覽

安裝 Goldsky CLI,並引導完成瀏覽器登入與專案驗證,用於 Goldsky 管線與子圖。

功能
使用隨附的安裝指令碼安裝 Goldsky CLI、Compose 與 Turbo,接著執行以瀏覽器為基礎的登入流程,並透過專案列表指令驗證身分驗證。它也涵蓋專案建立、使用者邀請、帳號切換以及常見驗證錯誤的疑難排解。最終產出設定完成且已驗證的 Goldsky 環境以及一份設定摘要。
適用情境
當使用者需要安裝 Goldsky CLI、首次登入、解決「未登入」或「未授權」錯誤,或在 Goldsky 專案之間切換時使用。當其他 Goldsky 技能遇到驗證失敗時,也會重新導向到此處。
執行需求
macOS、Linux 或搭配 WSL 的 Windows;Bash、curl、CA 憑證、標準 Unix 工具、網際網路存取以及可寫入的家目錄。Goldsky 帳號在登入過程中透過瀏覽器建立。隨附可執行安裝指令碼(scripts/install.sh 與 scripts/install.ps1)。

Goldsky Authentication & Project Setup

Set up the Goldsky CLI, authenticate your account, and configure projects for your pipelines and subgraphs.

Prerequisites

  • macOS, Linux, or Windows with WSL (see Step 1 for binary compatibility)
  • Internet connection
  • A Goldsky account. Creating one happens in the browser during Step 3. Do not send the user to sign up as a separate step.

Authentication Workflow

Follow this workflow and verify each step. Execute commands and check results.

Step 1: Install and verify the CLI

Install missing tools yourself. Do not ask the user to install binaries or enter a sudo password. You run login in Step 3. The user only approves it in the browser.

On macOS and Linux (including WSL), run the bundled installer [blocked] from this skill's directory. Resolve that path yourself. Do not ask the user where it is.

bash
bash scripts/install.sh

The default installs Goldsky, Compose, and Turbo. Pass cli when only the base CLI is needed. For a Compose-only or Turbo-only task, pass compose or turbo; both include the base Goldsky CLI. The script uses user-writable directories, disables installation prompts even in a PTY, checks download failures and empty responses, and requires each requested binary to run successfully. It reuses working installations and repairs broken ones. No sudo or login is needed.

Every new shell/tool call must restore PATH, including authentication and project commands below. An export in a previous tool call does not persist:

bash
export PATH="$HOME/.local/bin:$HOME/.goldsky/bin:$PATH"goldsky --versiongoldsky compose --versiongoldsky turbo --version

Check only the components requested. Do not trigger Turbo's interactive auto-installer when its binary is absent. Do not report setup complete if the installer or a required version check fails.

Platform limits: Goldsky and Compose publish macOS Intel/Apple Silicon and Linux x64/ARM64 binaries. The current Linux Turbo binary requires x64 and glibc 2.39+ (for example Ubuntu 24.04). A full install on Linux ARM64, older glibc, or musl must report incomplete; compose can still be installed separately. These are upstream binary limits, not reasons to ask for sudo or silently omit Turbo. The current Turbo Mac binary is Apple Silicon-only; Intel Macs can install Goldsky and Compose, but a full install must report incomplete.

Windows: the complete toolset currently runs inside WSL, not native PowerShell or Git Bash: Compose has no published Windows binary. Use an existing x64 Ubuntu 24.04+ WSL distribution for all three tools. See Windows setup [blocked] for PowerShell invocation and prerequisites. Keep installation, subsequent CLI commands, project files, and goldsky login in the same WSL environment. Run login yourself there. Installing/enabling WSL itself may require administrator access and a reboot; do not claim that prerequisite can always be automated without intervention.

Prerequisites inside the selected environment: Bash, curl, CA certificates, standard Unix utilities, internet access, and a writable home directory. If an environment lacks these, report the missing prerequisite instead of claiming installation succeeded.

Step 2: Check Authentication Status

bash
goldsky project list 2>&1

Already logged in: Output shows a table with project IDs and Names. Skip to Step 4.

Not logged in: Output contains Make sure to run 'goldsky login'. Continue to Step 3.

Step 3: Log in

Never handle the user's API token in the chat. A token pasted into the conversation ends up in the transcript and is sent to the model. Do not ask for one, and do not pass --token.

Run goldsky login yourself, with PATH restored, and leave it running for up to 5 minutes. It prints a URL, opens the browser, and writes the token to disk. The token is not printed. The user only approves the login in that browser, on this same machine. Creating an account or choosing a project happens there too. If the browser does not open, open the printed URL yourself. Give the user that URL only when you cannot open a browser.

If this host kills the command before login finishes, run it again. Hand the user the command only when you have no shell. Then verify (Step 4).

Step 4: Verify Login

ALWAYS verify after login:

bash
goldsky project list

Success: Exit code 0, shows table with projects

Failure indicators:

  • Make sure to run 'goldsky login' still appears
  • invalid token or unauthorized

If verification fails, run goldsky login again.

Completion Summary

After successful setup, provide a summary to the user:

## Setup Complete
**What was done:**- ✓ Goldsky CLI installed (version X.X.X)- Turbo: verified version, not requested, or explicit installation failure- Compose: verified version, not requested, or explicit installation failure- ✓ Authenticated to Goldsky- ✓ Connected to project: [project-name]
**Your available projects:**[List projects from goldsky project list output]
**Next steps - try these skills:**- `/secrets` - Set up credentials for pipeline sinks (PostgreSQL, ClickHouse, Kafka)- Ask "create a pipeline" to start building data pipelines- Ask "deploy a subgraph" to deploy a subgraph to Goldsky

If they have not said what they are trying to do, ask, and suggest only jobs the installed skills can do. Do not create a secret, pipeline, subgraph, or deployment until they pick one and agree.

Command Reference

CommandPurposeKey Flags
goldsky loginAuthenticate with GoldskyOpens the browser. Do not pass --token
goldsky logoutRemove local credentials
goldsky project listList all projects you belong to
goldsky project createCreate a new project--name (required)
goldsky project users listList users in current project
goldsky project users inviteInvite user to project--emails, --role

Common Patterns

Create a New Project

bash
goldsky project create --name "my-new-project"

Invite Team Members

bash
goldsky project users invite --emails [email protected] --role Editor

Available roles: Owner, Admin, Editor, Viewer

Switching accounts

bash
goldsky logoutgoldsky login# MUST verify after: goldsky project list

Error Patterns

PatternMeaning
Make sure to run 'goldsky login'Not authenticated
invalid token / unauthorizedToken is incorrect or expired
Permission denied / 403User lacks required role
token expired / session expiredNeed to re-authenticate

Troubleshooting

IssueAction
Installer asks for confirmation or sudoUse the bundled installer, which creates a writable destination and passes -f. Do not retry with sudo
turbo or compose is missing or cannot runRe-run the bundled installer for that component; check its exit status and platform requirements
Not logged inRun goldsky login yourself and leave it running until the browser login finishes
Invalid tokenRun goldsky login again. Do not ask for a token
Permission deniedUser needs role upgrade from project Owner/Admin
Session expiredRun goldsky login again

Related

After authentication is complete, suggest next steps:

  • /turbo-builder — Build and deploy a new pipeline interactively
  • /datasets — Find the right dataset for your use case
  • /secrets — Set up credentials for pipeline sinks (PostgreSQL, ClickHouse, Kafka, etc.)

來源與署名

來源:goldsky-io/goldsky-agent位於skills/auth-setup提交aa52f88

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架