coder/skills/gh/SKILL.md
GitHub CLI, git, and git-lfs — the single-responsibility home for all git/GitHub tooling. Ships the noscripts + post-install dance for git-lfs so the RPM's systemd trigger doesn't fail at build time. Use when composing git + gh + git-lfs into a box, or when deciding which candy should own a git-related binary.
npx skillsauth add overthinkos/overthink-plugins ghInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Property | Value |
|----------|-------|
| Install files | charly.yml (packages + one post-install run: step) |
| Depends | (none) |
--setopt=tsflags=noscripts): gh, git, git-lfsgithub-cli, git, git-lfstsflags=noscripts + a post-install run: stepThe git-lfs RPM's %post scriptlet runs git-lfs install --system
which tries to modify /etc/ and talk to systemd — operations that
fail (loudly or silently) inside a buildah container. We install with
noscripts and then run the git-lfs hook configuration manually:
# a child step node under the gh candy entity
gh-configure-git-lfs:
run: configure git-lfs system hooks
command: /usr/bin/git-lfs install --system --skip-repo 2>/dev/null || true
run_as: root
The || true tolerates distros/versions where the command layout
differs; --skip-repo prevents git-lfs from trying to touch a repo
that doesn't exist in the build container.
This candy is the exclusive home for gh, git, and git-lfs — no other
candy (including /charly-coder:dev-tools) installs them. That keeps ownership
unambiguous ("which candy do I look at to update the git-lfs version?" — this
one) and avoids duplicate test ids (gh-binary collisions).
Effect for candy authors: any box that wants git tooling composes gh
explicitly. The four power-user boxes (charly-arch, charly-fedora,
fedora-coder, githubrunner via the charly chain) all list gh
explicitly.
Six build-scope tests:
| Test | Purpose |
|---|---|
| gh-binary | /usr/bin/gh exists |
| gh-version | gh --version exits 0 |
| git-binary | /usr/bin/git exists |
| git-version | git --version exits 0 |
| git-lfs-binary | /usr/bin/git-lfs exists |
| git-lfs-version | git-lfs --version exits 0 |
rpm: (Fedora — from the github-cli COPR / community repo), pac: (Arch — github-cli from extra), deb: (Debian/Ubuntu — adds https://cli.github.com/packages as an apt repo with signed-by key; ships gh, git, git-lfs). Full parity across all three package families.
# box or candy charly.yml — composition is a child node, not a top-level list
my-box:
candy:
base: fedora
my-box-candy:
candy:
- gh
/charly-coder:charly-arch, /charly-distros:charly-fedora, /charly-coder:fedora-coder — power-user boxes that compose gh explicitly/charly-openclaw:openclaw-desktop — streaming-desktop siblinghermes-full/charly-coder:dev-tools — does not install git/gh/git-lfs (this candy owns them)/charly-distros:agent-forwarding — pairs with gh for SSH/GPG agent access (you usually want both when driving gh from inside a container with the host's GPG keys forwarded)/charly-distros:github-runner — self-hosted Actions runner; different candy, different purpose/charly-coder:github-actions — installs act + actionlint for local Actions testing; also different from this candy/charly-build:secrets — provision GITHUB_TOKEN for gh auth login/charly-core:shell — run gh interactively inside a containerMUST be invoked when:
gh, git, or git-lfs to any other candy's packages).git-lfs install fails at build time (the noscripts +
post-install pattern here is the fix)./charly-coder:dev-tools does not install gh
(this candy holds single-responsibility ownership of git tooling)./charly-image:layer — candy authoring reference (charly.yml schema, plan-step verbs, service declarations)/charly-check:check — declarative testing (check: block, charly check box, charly check live)tools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).