All skills
apollographql avatar

/rover

@9ccc6ed official
by Apollo GraphQLapollographql/skills115 stars
13

Guide for using Apollo Rover CLI to manage GraphQL schemas and federation. Use this skill when: (1) publishing or fetching subgraph/graph schemas, (2) composing supergraph schemas locally or via GraphOS, (3) running local supergraph development with rover dev, (4) validating schemas with check and lint commands, (5) configuring Rover authentication and environment, (6) exploring or searching a graph's schema for agent-driven discovery (rover schema describe / rover schema search).

Use this Skill: https://skilld.dev/gh/apollographql/skills/rover

This session only. Nothing lands on disk.

referencessupergraphs.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Rover Supergraph Commands

Commands for composing and fetching federated supergraph schemas.

supergraph fetch

Download the composed supergraph schema from GraphOS.

# Basic fetch
rover supergraph fetch my-graph@production

# Output to file
rover supergraph fetch my-graph@production > supergraph.graphql

# JSON output (includes build info)
rover supergraph fetch my-graph@production --format json

Options:

Option Description
--format <FORMAT> Output format: plain (default) or json

Output: The full supergraph SDL including:

  • All subgraph types merged
  • Federation metadata (_service, _entities)
  • Join directives for Router

supergraph compose

Compose a supergraph schema locally from subgraph schemas.

# Basic composition
rover supergraph compose --config supergraph.yaml

# Output to file
rover supergraph compose --config supergraph.yaml > supergraph.graphql

# Specify output file
rover supergraph compose --config supergraph.yaml --output supergraph.graphql

Options:

Option Description
--config <PATH> Path to supergraph config file (required)
--output <PATH> Write output to file
--format <FORMAT> Output format: plain (default) or json

Supergraph Configuration File

The supergraph.yaml file defines subgraphs for local composition.

Basic Structure

federation_version: =2.9.0

subgraphs:
  products:
    routing_url: http://localhost:4001/graphql
    schema:
      file: ./subgraphs/products/schema.graphql

  reviews:
    routing_url: http://localhost:4002/graphql
    schema:
      file: ./subgraphs/reviews/schema.graphql

  users:
    routing_url: http://localhost:4003/graphql
    schema:
      subgraph_url: http://localhost:4003/graphql

Schema Sources

From File
subgraphs:
  products:
    routing_url: http://localhost:4001/graphql
    schema:
      file: ./products.graphql
From Introspection
subgraphs:
  products:
    routing_url: http://localhost:4001/graphql
    schema:
      subgraph_url: http://localhost:4001/graphql
From Introspection with Headers
subgraphs:
  products:
    routing_url: http://localhost:4001/graphql
    schema:
      subgraph_url: http://localhost:4001/graphql
      introspection_headers:
        Authorization: Bearer ${AUTH_TOKEN}
        X-Custom-Header: value
From GraphOS
subgraphs:
  products:
    routing_url: http://localhost:4001/graphql
    schema:
      graphref: my-graph@production
      subgraph: products

Federation Version

# Exact version (recommended for reproducibility)
federation_version: =2.9.0

# Minimum version
federation_version: 2.9.0

# Latest 2.x
federation_version: 2

Supported versions:

  • 2.9.x - Latest with @cost directive
  • 2.8.x - Stable with @context
  • 2.7.x - @authenticated, @requiresScopes
  • 1.x - Legacy (not recommended)

Complete Example

federation_version: =2.9.0

subgraphs:
  # From local files (development)
  products:
    routing_url: http://localhost:4001/graphql
    schema:
      file: ./services/products/schema.graphql

  # From running service (hot reload)
  inventory:
    routing_url: http://localhost:4002/graphql
    schema:
      subgraph_url: http://localhost:4002/graphql

  # From GraphOS (production baseline)
  users:
    routing_url: http://localhost:4003/graphql
    schema:
      graphref: my-graph@production
      subgraph: users

  # With authentication
  orders:
    routing_url: http://localhost:4004/graphql
    schema:
      subgraph_url: http://localhost:4004/graphql
      introspection_headers:
        Authorization: Bearer ${ORDERS_TOKEN}

Composition Errors

Common Errors

Entity Key Mismatch:

Error: Entity "Product" has different keys in different subgraphs

Fix: Ensure @key directives match across subgraphs.

Invalid Reference:

Error: Cannot extend type "Product" - not found in any subgraph

Fix: Define the base type in one subgraph before extending.

Field Conflict:

Error: Field "Product.name" has different types in different subgraphs

Fix: Ensure field types match or use @override.

Debugging Composition

# Verbose output
rover supergraph compose --config supergraph.yaml 2>&1 | head -100

# JSON output includes detailed errors
rover supergraph compose --config supergraph.yaml --format json

Using with Router

Local Development

# 1. Compose supergraph
rover supergraph compose --config supergraph.yaml > supergraph.graphql

# 2. Run Router with composed schema
router --supergraph supergraph.graphql

With rover dev (Recommended)

# Automatic composition and Router
rover dev --supergraph-config supergraph.yaml

Environment Variables

Use environment variables in config:

subgraphs:
  products:
    routing_url: ${PRODUCTS_URL}
    schema:
      subgraph_url: ${PRODUCTS_URL}
      introspection_headers:
        Authorization: Bearer ${PRODUCTS_TOKEN}
PRODUCTS_URL=http://localhost:4001/graphql \
PRODUCTS_TOKEN=secret \
  rover supergraph compose --config supergraph.yaml

CI/CD Integration

Validate Composition

# Fail if composition errors
rover supergraph compose --config supergraph.yaml > /dev/null
echo "Composition successful"

Compare with Production

# Fetch production supergraph
rover supergraph fetch my-graph@production > production.graphql

# Compose local
rover supergraph compose --config supergraph.yaml > local.graphql

# Diff schemas
diff production.graphql local.graphql

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk HIGH
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive guide for the Apollo Rover CLI. It contains installation instructions that involve downloading and executing remote scripts from Apollo's official domain. While these are remote code execution patterns, they are standard for this recognized vendor. The skill is susceptible to indirect prompt injection because it processes external GraphQL schema data without explicit boundary markers or sanitization.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    6/6 files flagged

  • ZeroLeaks5mo

    1 finding · Score: 82/100

Signed by skilld at 9ccc6ed. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
What it can do
Runs commands
compatibility
Node.js v18+, Linux/macOS/Windows
metadata
{
  "author": "apollographql",
  "version": "1.1.2"
}
All 1 allowed tools
Bash(rover:*) Bash(npm:*) Bash(npx:*) Read Write Edit Glob Grep
  • CLI
  • graphql
  • apollo
  • rover
  • federation
  • schema
  • supergraph
  • graphos
  • subgraph

README badge

README badge for apollographql/skills/rover

Manages GraphQL schemas and federation via the Apollo Rover CLI, including publishing subgraphs, composing supergraphs, and validating schemas with check and lint commands. Designed for local schema exploration via piped commands (rover schema describe/search) and GraphOS integration workflows, with built-in support for federated and monograph architectures.

Generated from the current SKILL.md.

Does Rover work with both federated and non-federated GraphQL graphs?
Yes. Use `rover subgraph` commands for federated graphs and `rover graph` commands for monographs (non-federated graphs). Both workflows are supported.
How do I explore a large GraphQL schema without loading the entire SDL into context?
Pipe `rover graph fetch` into `rover schema describe` or `rover schema search` — these commands read the schema via stdin and return only a compact overview or search results, keeping context manageable.
What's the difference between `rover graph fetch` and `rover supergraph fetch`?
`rover graph fetch` returns the API schema (what you can query), while `rover supergraph fetch` returns the composed supergraph SDL with federation internals like `join__` and `link__`. Use the former for schema exploration and the latter for composition/router work.
Can Rover execute GraphQL queries, or does it only manage schemas?
Rover only manages and inspects schemas. To run a generated query, you must send it to the graph's endpoint separately using curl or another HTTP client.
Does this skill require a GraphOS account, or can I use Rover offline?
Most Rover commands (publish, fetch, check) require authentication with a GraphOS API key. Local composition with `rover supergraph compose` and schema exploration of local files work offline.

Generated from the current SKILL.md. These answers refresh after source changes.