使用Terraform创建GitHub仓库失败:组织强制提交签署引发422错误
问题描述
使用Terraform创建模板化GitHub仓库时,terraform plan执行成功,但terraform apply失败,报错信息如下:
Error: PATCH https://api.github.com/repos/{my-org}/{repo-name}: 422 Commit signoff is enforced by the organization and cannot be disabled []
已在组织层面开启提交签署强制设置,且Terraform配置中已将web_commit_signoff_required设为true,仍出现该错误。对应的Terraform配置代码如下:
# Create the GitHub repository, itself resource "github_repository" "this" { # The default configuration of the repository name = var.name description = var.description topics = var.topics visibility = var.visibility has_issues = false has_discussions = false has_projects = false has_wiki = false auto_init = true # Setup the merge settings for the repository allow_merge_commit = true allow_squash_merge = true allow_rebase_merge = true allow_auto_merge = false delete_branch_on_merge = true # Turn on vulnerability alerts for the repository web_commit_signoff_required = true vulnerability_alerts = true } # Declare the variables that should be associated with this repository resource "github_actions_variable" "this" { for_each = var.variables repository = github_repository.this.name variable_name = each.key value = each.value } # Declare the action permissions for this repository resource "github_actions_repository_permissions" "this" { repository = github_repository.this.name enabled = true allowed_actions = "all" } # Create a GitHub branch called main resource "github_branch" "main" { repository = github_repository.this.name branch = "main" } # Set the main branch to this repository's default branch resource "github_branch_default" "default" { repository = github_repository.this.name branch = github_branch.main.branch } # Setup a branch protection rule on the repo to ensure that the main branch is protected resource "github_branch_protection" "main" { repository_id = github_repository.this.node_id # Setup the base requirements for the branch protection rule pattern = "main" enforce_admins = false require_signed_commits = true required_linear_history = false allows_deletions = false allows_force_pushes = false require_conversation_resolution = true # Ensure that status checks are required required_status_checks { strict = true } # Ensure that pull request reviews are required, but that admins can still bypass required_pull_request_reviews { restrict_dismissals = true require_code_owner_reviews = true require_last_push_approval = true required_approving_review_count = 2 pull_request_bypassers = [local.admins_team] } # Ensure that pushes are restricted to admins restrict_pushes { blocks_creations = true push_allowances = [local.admins_team] } # Ensure that force-pushes are restricted to admins force_push_bypassers = [local.admins_team] }
原因分析
- 自动初始化的冲突:当设置
auto_init = true时,GitHub会在仓库创建时自动生成初始提交和main分支,但这个操作发生在Terraform设置web_commit_signoff_required = true之前。由于组织强制要求提交签署,未签署的初始提交直接触发规则校验失败。 - API请求顺序问题:Terraform创建
github_repository资源时,可能先以默认值web_commit_signoff_required = false发起创建请求,之后再通过PATCH请求更新为true。而组织规则不允许该字段从true(组织强制)被临时设置为false,导致422校验错误。 - 冗余设置的冲突:组织层面已强制开启提交签署,仓库级别的
web_commit_signoff_required会被组织规则覆盖,显式设置该字段反而会触发不必要的API更新请求,引发冲突。
解决方法
方法1:关闭自动初始化,手动提交签署的初始代码
将github_repository资源中的auto_init设为false,避免GitHub自动生成未签署的初始提交,后续手动提交一个已签署的初始文件到仓库:
resource "github_repository" "this" { # ... 其他配置保持不变 auto_init = false # ... 其他配置保持不变 }
方法2:移除仓库级别的签署设置
由于组织规则已强制开启提交签署,仓库级别的web_commit_signoff_required设置会被覆盖,直接从github_repository资源中移除该字段,避免触发冲突的API请求:
resource "github_repository" "this" { # ... 其他配置保持不变 # 移除 web_commit_signoff_required = true 这一行 vulnerability_alerts = true }
内容的提问来源于stack exchange,提问作者Woody1193
相关产品推荐
相关产品推荐

