You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform创建GitHub仓库失败:组织强制提交签署引发422错误

问题描述

使用Terraform创建模板化GitHub仓库时,terraform plan执行成功,但terraform apply失败,报错信息如下:

Error: PATCH https://api.github.com/repos/{my-org}/{repo-name}: 422 Commit signoff is enforced by the organization and cannot be disabled []

已在组织层面开启提交签署强制设置,且Terraform配置中已将web_commit_signoff_required设为true,仍出现该错误。对应的Terraform配置代码如下:

# Create the GitHub repository, itself
resource "github_repository" "this" {

  # The default configuration of the repository
  name            = var.name
  description     = var.description
  topics          = var.topics
  visibility      = var.visibility
  has_issues      = false
  has_discussions = false
  has_projects    = false
  has_wiki        = false
  auto_init       = true

  # Setup the merge settings for the repository
  allow_merge_commit     = true
  allow_squash_merge     = true
  allow_rebase_merge     = true
  allow_auto_merge       = false
  delete_branch_on_merge = true

  # Turn on vulnerability alerts for the repository
  web_commit_signoff_required = true
  vulnerability_alerts        = true
}

# Declare the variables that should be associated with this repository
resource "github_actions_variable" "this" {
  for_each = var.variables

  repository    = github_repository.this.name
  variable_name = each.key
  value         = each.value
}

# Declare the action permissions for this repository
resource "github_actions_repository_permissions" "this" {
  repository = github_repository.this.name

  enabled         = true
  allowed_actions = "all"
}
# Create a GitHub branch called main
resource "github_branch" "main" {
  repository = github_repository.this.name
  branch     = "main"
}

# Set the main branch to this repository's default branch
resource "github_branch_default" "default" {
  repository = github_repository.this.name
  branch     = github_branch.main.branch
}

# Setup a branch protection rule on the repo to ensure that the main branch is protected
resource "github_branch_protection" "main" {
  repository_id = github_repository.this.node_id

  # Setup the base requirements for the branch protection rule
  pattern                         = "main"
  enforce_admins                  = false
  require_signed_commits          = true
  required_linear_history         = false
  allows_deletions                = false
  allows_force_pushes             = false
  require_conversation_resolution = true

  # Ensure that status checks are required
  required_status_checks {
    strict = true
  }

  # Ensure that pull request reviews are required, but that admins can still bypass
  required_pull_request_reviews {
    restrict_dismissals             = true
    require_code_owner_reviews      = true
    require_last_push_approval      = true
    required_approving_review_count = 2
    pull_request_bypassers          = [local.admins_team]
  }

  # Ensure that pushes are restricted to admins
  restrict_pushes {
    blocks_creations = true
    push_allowances  = [local.admins_team]
  }

  # Ensure that force-pushes are restricted to admins
  force_push_bypassers = [local.admins_team]
}
原因分析
  1. 自动初始化的冲突:当设置auto_init = true时,GitHub会在仓库创建时自动生成初始提交和main分支,但这个操作发生在Terraform设置web_commit_signoff_required = true之前。由于组织强制要求提交签署,未签署的初始提交直接触发规则校验失败。
  2. API请求顺序问题:Terraform创建github_repository资源时,可能先以默认值web_commit_signoff_required = false发起创建请求,之后再通过PATCH请求更新为true。而组织规则不允许该字段从true(组织强制)被临时设置为false,导致422校验错误。
  3. 冗余设置的冲突:组织层面已强制开启提交签署,仓库级别的web_commit_signoff_required会被组织规则覆盖,显式设置该字段反而会触发不必要的API更新请求,引发冲突。
解决方法

方法1:关闭自动初始化,手动提交签署的初始代码

将github_repository资源中的auto_init设为false,避免GitHub自动生成未签署的初始提交,后续手动提交一个已签署的初始文件到仓库:

resource "github_repository" "this" {
  # ... 其他配置保持不变
  auto_init = false
  # ... 其他配置保持不变
}

方法2:移除仓库级别的签署设置

由于组织规则已强制开启提交签署,仓库级别的web_commit_signoff_required设置会被覆盖,直接从github_repository资源中移除该字段,避免触发冲突的API请求:

resource "github_repository" "this" {
  # ... 其他配置保持不变
  # 移除 web_commit_signoff_required = true 这一行
  vulnerability_alerts = true
}

内容的提问来源于stack exchange,提问作者Woody1193

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 01:53:18