The source-controller can not read the repo because the secretRef secret is missing, has the wrong keys, or the token died - so every Kustomization/HelmRelease downstream stalls on the old revision. Check the secret exists with the right keys (username/password for HTTPS, identity/known_hosts for SSH), recreate it with flux create secret git, and the source goes Ready.

## The error
```text
unable to clone 'https://github.com/YOUR-ORG/YOUR-REPO': authentication required
```

## What to do
1. See the failing source:
```bash
flux get sources git -A
```
   Expected: GitRepository shows FetchFailed / authentication required.
2. Check the referenced secret value ```bash
kubectl -n flux-system get secret [secret-name] -o jsonpath='{.data}'
```
   Expected: Missing secret, or wrong keys.
3. Recreate it:
```bash
flux create secret git [secret-name] --namespace flux-system --url=https://github.com/YOUR-ORG/YOUR-REPO --username [user] --password [token]
```
   Expected: Secret created with username/password keys.
4. Force a retry:
```bash
flux reconcile source git [name] -n flux-system
```
   Expected: Source becomes Ready=True.

## When this applies
- GitRepository FetchFailed with authentication required
- secretRef pointing at a deleted or wrong-keyed secret
- expired tokens in git secrets

## When it does NOT apply
- repository not found (wrong URL)
- branch or tag not found (wrong ref)

## Works with
flux CLI 2.x; source-controller

### SSH sources failing: identity/known_hosts wrong
Same FetchFailed shape for SSH. The secret needs identity (private key) and known_hosts keys.

## Why it happens
source-controller clones with exactly the credential in the referenced secret - nothing else. A missing secret or a secret with keys the controller does not read (e.g. token instead of username/password) authenticates as nothing.

## Edge cases
- For HTTPS, flux create secret git needs BOTH username and password - password-only secrets fail (flux2#778).
- TLS errors on self-hosted git mean the secret also needs the caFile key.

## Resolved from
gh:dod-platform-one/bigbang (troubleshooting guide) - https://github.com/dod-platform-one/bigbang/blob/HEAD/docs/operations/troubleshooting/index.md