存在待部署任务时,无法通过CLI/REST API批准GitHub部署
问题场景与故障排查
核心问题
同一环境下部分仓库可自动部署,部分需手动审批,采用并行作业模式实现自动审批。可通过gh api或curl获取环境ID、作业ID及待审批任务,但执行POST批准请求时返回422错误,提示「无待处理部署请求」。已配置github.token及对应权限,尝试过带仓库权限的PAT均无效,但第三方Action配合PAT可成功审批,怀疑自身代码存在问题,准备尝试细粒度令牌。
相关代码片段
工作流配置
jobs: job-before-staging: # 审批前的前置任务,用于锚定后续两个并行任务 # 该环境有部署保护规则,需手动审批 deploy-staging: needs: job-before-staging env: STAGING if: runStaging == true # ... 部署步骤 # 未声明环境 staging-auto-approval: needs: job-before-staging if: runStaging == true && requireStagingApproval == false steps: - name: auto-approve-deploy run: <批准任务的API>
有效查询待部署任务命令
gh api --verbose repos/$REPO/actions/runs/$RUNID/pending_deployments
失败的批准命令及返回结果
批准命令
gh api --verbose \ repos/$REPO/actions/runs/$RUNID/pending_deployments \ --method POST \ -F "environment_ids[]=$ENVID" \ -f "state=approved" \ -f "comment=Auto-Approved by GitHub Actions"
返回结果
{ "comment": "Auto-Approved by GitHub Actions", "environment_ids": [ 11130481765 ], "state": "approved" } ... { "message": "Validation Failed", "errors": "No pending deployment requests to approve or reject", "documentation_url": "https://docs.github.com/rest/actions/workflow-runs#review-pending-deployments-for-a-workflow-run", "status": "422" } * Request took 469.770458ms gh: No pending deployment requests to approve or reject (Validation Failed)
权限配置
env: GH_TOKEN: ${{ github.token }} permissions: checks: write deployments: write actions: write
可行修复方向
校验请求参数准确性
确认$ENVID是查询到的待审批环境的真实ID,避免使用缓存或硬编码的旧ID;同时确保$RUNID为当前工作流运行的正确ID,防止跨运行提交审批。调整作业执行时机
并行作业可能出现审批请求先于部署请求进入待审批状态的情况,可在staging-auto-approval中增加等待逻辑,循环检测待审批任务后再执行批准:while true; do PENDING_COUNT=$(gh api repos/$REPO/actions/runs/$RUNID/pending_deployments | jq '. | length') if [ "$PENDING_COUNT" -gt 0 ]; then break fi echo "等待待审批任务生成..." sleep 10 done # 执行批准命令 gh api --verbose \ repos/$REPO/actions/runs/$RUNID/pending_deployments \ --method POST \ -F "environment_ids[]=$ENVID" \ -f "state=approved" \ -f "comment=Auto-Approved by GitHub Actions"优化令牌权限
替换github.token为细粒度PAT,授予仓库级的「Deployments(读写)」「Actions(读写)」权限,遵循最小权限原则,避免权限范围不足或过度。调整API请求格式
尝试改用JSON格式提交请求,替代表单参数:gh api --verbose repos/$REPO/actions/runs/$RUNID/pending_deployments \ --method POST \ --input - <<EOF { "environment_ids": [$ENVID], "state": "approved", "comment": "Auto-Approved by GitHub Actions" } EOF
内容的提问来源于stack exchange,提问作者Max Cascone
相关产品推荐
相关产品推荐

