flux GitRepository: unable to clone 'https://github.com/YOUR-ORG/YOUR-REPO' - authentication required
Routes Flux GitRepository source auth failures. Use when a GitRepository shows authentication required / unable to clone. Not for branch-not-found or URL typos.
The source-controller can not read the repo because the secretRef secret is missing, has the wrong keys, or the token died - so every Kustomization/HelmRelease downstream stalls on the old revision. Check the secret exists with the right keys (username/password for HTTPS, identity/known_hosts for SSH), recreate it with flux create secret git, and the source goes Ready.
The error
unable to clone 'https://github.com/YOUR-ORG/YOUR-REPO': authentication requiredWhat to do
- See the failing source:
flux get sources git -AExpected: GitRepository shows FetchFailed / authentication required.
- Check the referenced secret value ```bash
kubectl -n flux-system get secret [secret-name] -o jsonpath='{.data}'
Expected: Missing secret, or wrong keys.
3. Recreate it:
```bash
flux create secret git [secret-name] --namespace flux-system --url=https://github.com/YOUR-ORG/YOUR-REPO --username [user] --password [token]Expected: Secret created with username/password keys.
- Force a retry:
flux reconcile source git [name] -n flux-systemExpected: Source becomes Ready=True.
When this applies
- GitRepository FetchFailed with authentication required
- secretRef pointing at a deleted or wrong-keyed secret
- expired tokens in git secrets
When it does NOT apply
- repository not found (wrong URL)
- branch or tag not found (wrong ref)
Works with
flux CLI 2.x; source-controller
SSH sources failing: identity/known_hosts wrong
Same FetchFailed shape for SSH. The secret needs identity (private key) and known_hosts keys.
Why it happens
source-controller clones with exactly the credential in the referenced secret - nothing else. A missing secret or a secret with keys the controller does not read (e.g. token instead of username/password) authenticates as nothing.
Edge cases
- For HTTPS, flux create secret git needs BOTH username and password - password-only secrets fail (flux2#778).
- TLS errors on self-hosted git mean the secret also needs the caFile key.
Resolved from
gh:dod-platform-one/bigbang (troubleshooting guide) - https://github.com/dod-platform-one/bigbang/blob/HEAD/docs/operations/troubleshooting/index.md
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.