All skills
apollographql avatar

/rover

@9ccc6ed official
by Apollo GraphQLapollographql/skills115 stars
13

Guide for using Apollo Rover CLI to manage GraphQL schemas and federation. Use this skill when: (1) publishing or fetching subgraph/graph schemas, (2) composing supergraph schemas locally or via GraphOS, (3) running local supergraph development with rover dev, (4) validating schemas with check and lint commands, (5) configuring Rover authentication and environment, (6) exploring or searching a graph's schema for agent-driven discovery (rover schema describe / rover schema search).

Use this Skill: https://skilld.dev/gh/apollographql/skills/rover

This session only. Nothing lands on disk.

referencesdev.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Rover Dev Command

Run a local supergraph for development with automatic schema composition and hot reloading.

Basic Usage

# Start with supergraph config
rover dev --supergraph-config supergraph.yaml

# Start on specific port
rover dev --supergraph-config supergraph.yaml --router-port 4000

Default behavior:

  • Router runs on http://localhost:4000
  • GraphQL endpoint: http://localhost:4000
  • Health check: http://localhost:4000/health

Configuration File

Create supergraph.yaml for local development:

federation_version: =2.9.0

subgraphs:
  products:
    routing_url: http://localhost:4001/graphql
    schema:
      file: ./products/schema.graphql

  reviews:
    routing_url: http://localhost:4002/graphql
    schema:
      subgraph_url: http://localhost:4002/graphql

  users:
    routing_url: http://localhost:4003/graphql
    schema:
      file: ./users/schema.graphql

Hot Reloading

File-based Schema

When using schema.file, Rover watches for file changes:

subgraphs:
  products:
    schema:
      file: ./products/schema.graphql  # Watched for changes

Save the file and Rover automatically recomposes.

Introspection-based Schema

When using schema.subgraph_url, Rover polls for changes:

subgraphs:
  reviews:
    schema:
      subgraph_url: http://localhost:4002/graphql  # Polled for changes

Using with GraphOS Variant

Start with a GraphOS variant as baseline and override locally:

rover dev --graph-ref my-graph@staging --supergraph-config local-overrides.yaml

local-overrides.yaml:

federation_version: =2.9.0

subgraphs:
  # Override products with local version
  products:
    routing_url: http://localhost:4001/graphql
    schema:
      file: ./products/schema.graphql
  # Other subgraphs come from GraphOS variant

Router Configuration

Custom Router Config

rover dev \
  --supergraph-config supergraph.yaml \
  --router-config router.yaml

router.yaml:

supergraph:
  listen: 127.0.0.1:4000

headers:
  all:
    request:
      - propagate:
          matching: "^x-.*"

cors:
  origins:
    - http://localhost:3000
  allow_headers:
    - Content-Type
    - Authorization

telemetry:
  apollo:
    endpoint: https://usage.api.apollographql.com/api/ingress/traces

Common Router Options

# Sandbox enabled (default in dev)
sandbox:
  enabled: true

# Introspection enabled (default in dev)
introspection: true

# Query plans in response
include_subgraph_errors:
  all: true

MCP Server Integration

Enable MCP server alongside Router:

rover dev --supergraph-config supergraph.yaml --mcp

MCP options:

# Specify MCP port
rover dev --supergraph-config supergraph.yaml --mcp --mcp-port 5001

# MCP output format
rover dev --supergraph-config supergraph.yaml --mcp --mcp-format json

Use cases:

  • AI agent integration during development
  • Testing MCP-based tools
  • Local agentic workflow development

Multiple Subgraph Development

Single Machine Setup

# Terminal 1: Products subgraph
cd products && npm run dev  # Runs on 4001

# Terminal 2: Reviews subgraph
cd reviews && npm run dev   # Runs on 4002

# Terminal 3: Rover dev
rover dev --supergraph-config supergraph.yaml

Adding a New Subgraph

  1. Add to supergraph.yaml:
subgraphs:
  # existing...

  new-service:
    routing_url: http://localhost:4004/graphql
    schema:
      file: ./new-service/schema.graphql
  1. Rover automatically detects changes and recomposes.

Options Reference

Option Description Default
--supergraph-config <PATH> Path to supergraph config Required
--graph-ref <REF> GraphOS variant for baseline None
--router-port <PORT> Router listen port 4000
--router-config <PATH> Custom Router config None
--mcp Enable MCP server false
--mcp-port <PORT> MCP server port 5001
--log <LEVEL> Log level info

Troubleshooting

Port Already in Use

# Check what's using port 4000
lsof -i :4000

# Use different port
rover dev --supergraph-config supergraph.yaml --router-port 4001

Subgraph Not Reachable

Error: Could not connect to subgraph "products" at http://localhost:4001/graphql
  • Ensure subgraph server is running
  • Check correct port in config
  • Verify subgraph URL responds to introspection

Composition Fails

# Check composition separately
rover supergraph compose --config supergraph.yaml

# Look for specific errors in output

Schema Not Updating

For file-based schemas:

  • Ensure file path is correct
  • Check file permissions
  • Try saving file again

For introspection:

  • Ensure server has introspection enabled
  • Check for authentication requirements

Environment Variables

# Required for GraphOS features
export APOLLO_KEY=your-api-key
export APOLLO_GRAPH_REF=my-graph@staging

# Run with environment
APOLLO_KEY=$APOLLO_KEY rover dev \
  --graph-ref $APOLLO_GRAPH_REF \
  --supergraph-config local.yaml

Development Workflow

Typical Session

# 1. Start subgraph servers
npm run dev:subgraphs  # Custom script to start all

# 2. Start Rover dev
rover dev --supergraph-config supergraph.yaml

# 3. Open http://localhost:4000 for Sandbox
# 4. Make schema changes - auto-reloads
# 5. Ctrl+C to stop

With Docker Compose

# docker-compose.yaml
services:
  products:
    build: ./products
    ports:
      - "4001:4001"

  reviews:
    build: ./reviews
    ports:
      - "4002:4002"
# Start services
docker-compose up -d

# Start Rover dev
rover dev --supergraph-config supergraph.yaml

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk HIGH
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive guide for the Apollo Rover CLI. It contains installation instructions that involve downloading and executing remote scripts from Apollo's official domain. While these are remote code execution patterns, they are standard for this recognized vendor. The skill is susceptible to indirect prompt injection because it processes external GraphQL schema data without explicit boundary markers or sanitization.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    6/6 files flagged

  • ZeroLeaks5mo

    1 finding · Score: 82/100

Signed by skilld at 9ccc6ed. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
What it can do
Runs commands
compatibility
Node.js v18+, Linux/macOS/Windows
metadata
{
  "author": "apollographql",
  "version": "1.1.2"
}
All 1 allowed tools
Bash(rover:*) Bash(npm:*) Bash(npx:*) Read Write Edit Glob Grep
  • CLI
  • graphql
  • apollo
  • rover
  • federation
  • schema
  • supergraph
  • graphos
  • subgraph

README badge

README badge for apollographql/skills/rover

Manages GraphQL schemas and federation via the Apollo Rover CLI, including publishing subgraphs, composing supergraphs, and validating schemas with check and lint commands. Designed for local schema exploration via piped commands (rover schema describe/search) and GraphOS integration workflows, with built-in support for federated and monograph architectures.

Generated from the current SKILL.md.

Does Rover work with both federated and non-federated GraphQL graphs?
Yes. Use `rover subgraph` commands for federated graphs and `rover graph` commands for monographs (non-federated graphs). Both workflows are supported.
How do I explore a large GraphQL schema without loading the entire SDL into context?
Pipe `rover graph fetch` into `rover schema describe` or `rover schema search` — these commands read the schema via stdin and return only a compact overview or search results, keeping context manageable.
What's the difference between `rover graph fetch` and `rover supergraph fetch`?
`rover graph fetch` returns the API schema (what you can query), while `rover supergraph fetch` returns the composed supergraph SDL with federation internals like `join__` and `link__`. Use the former for schema exploration and the latter for composition/router work.
Can Rover execute GraphQL queries, or does it only manage schemas?
Rover only manages and inspects schemas. To run a generated query, you must send it to the graph's endpoint separately using curl or another HTTP client.
Does this skill require a GraphOS account, or can I use Rover offline?
Most Rover commands (publish, fetch, check) require authentication with a GraphOS API key. Local composition with `rover supergraph compose` and schema exploration of local files work offline.

Generated from the current SKILL.md. These answers refresh after source changes.