After you mint a token, FerrVault shows a wizard with snippets to connect a cluster, a shell or a CI pipeline. None of its tabs worked as written.

The Kubernetes manifest was refused by kubectl apply. It now fills organization on the FerrVaultConnection and project on the FerrVaultSecret, both required by the operator's CRDs, and drops the environment field, which the CRD does not have: the token already decides the environment.

The CLI tab pointed at an install script that returned a 404. It now builds the CLI from source, pinned to the lockfile in the repository:

cargo install --locked --git https://github.com/FerrLabs/FerrVault ferrvault-cli

The GitHub Actions tab used action inputs that do not exist. The workflow it shows now installs the CLI the same way and runs your command through ferrvault exec, with FERRVAULT_URL and FERRVAULT_TOKEN in its environment. Prebuilt binaries are not published yet, so cargo is the only install path for now; the CLI docs use the same command.