Kustomize shells out to git for remote bases, and git has no valid credential for that host - an expired token, a password where GitHub now demands a token, or a credential helper (like Argo CD CodeConnections) sending the wrong credential to the URL. Make the private base fetch work with plain git first (token with repo read scope), then kustomize build succeeds. For public bases hit by a misbehaving helper, vendor the base instead.

## The error
```text
fatal: Authentication failed for 'https://github.com/[org]/[repo]/'
remote: Invalid username or token. Password authentication is not supported for Git operations.
```

## What to do
1. Reproduce with plain git:
```bash
git ls-remote https://github.com/[org]/[repo].git HEAD
```
   Expected: Same auth failure outside kustomize.
2. Fix the credential: use a personal access token (classic) or fine-grained token with contents read, as the password; check git credential helpers for stale entries.
   Expected: git ls-remote succeeds.
3. Rebuild:
```bash
kustomize build [dir]
```
   Expected: Remote base fetches and builds.
4. If a platform credential helper poisons public URLs, vendor the remote base into the repo and reference it locally.
   Expected: No network fetch at build time.

## When this applies
- fatal: Authentication failed on kustomize remote bases
- private GitHub bases
- credential helpers sending wrong credentials to public URLs

## When it does NOT apply
- repository not found (wrong URL, not auth)
- load-restrictor errors on local files

## Works with
kustomize 4.x/5.x with git remote bases

### remote: Repository not found. fatal: ... could not read from remote repository
Same fetch path, but the repo does not exist or the token can not see it. Check the URL and token scope.

## Why it happens
Remote bases are just git clones under the hood. Kustomize inherits your git credential setup wholesale - when git can not authenticate, the build can not either.

## Edge cases
- SSH-based remote bases ([contact email]:...) need an SSH key with a working agent, not an HTTPS token.
- Pin remote bases with ?ref=[sha] so a working build does not drift when the upstream moves.

## Resolved from
dev.to kustomize remote bases guide - https://dev.to/jajera/why-your-kustomize-remote-bases-break-on-managed-argo-cd-and-how-to-fix-it-26i6