GitHub Action中使用gh创建仓库遇权限错误求助
问题
作为组织管理员,在GitHub Action中通过GitHub CLI(gh)创建仓库时遇到报错:GraphQL: Resource not accessible by integration (createRepository)。已在action.yaml中设置permissions: write-all并使用${{ secrets.GITHUB_TOKEN }},需要解决权限配置问题。
相关配置及错误信息如下:
action.yaml配置
name: Create Repo on: push: branches: [ master ] env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} TEMPLATE_REPO: template # this is the template directory jobs: build: name: Create Repo runs-on: ubuntu-latest permissions: write-all steps: - name: Check out repository uses: actions/checkout@v3 - name: Repo Create run: | git -C ${{ env.TEMPLATE_REPO }} init gh repo create repo-test --private --source=${{ env.TEMPLATE_REPO }}
错误信息
Initialized empty Git repository in /home/runner/work/repo-central/repo-central/template/.git/ GraphQL: Resource not accessible by integration (createRepository) Error: Process completed with exit code 1.
解决方案
- 核心问题:默认的
GITHUB_TOKEN权限仅限触发Action的当前仓库,没有跨仓库/创建组织仓库的权限,哪怕你是组织管理员也无效。 - 解决步骤:
- 生成Personal Access Token(PAT):在GitHub个人设置中新建PAT,勾选
repo权限(若为组织仓库,确保该PAT拥有组织的仓库创建权限)。 - 添加PAT到Secrets:将生成的PAT添加到仓库或组织的Secrets中,命名为
ORG_GH_TOKEN(可自定义,避免与默认GITHUB_TOKEN重名)。 - 修改action.yaml配置:
- 把
env中的GH_TOKEN替换为${{ secrets.ORG_GH_TOKEN }}。 - 保留
permissions: write-all(或更精准设置repositories: write,write-all已足够覆盖需求)。
- 把
- 生成Personal Access Token(PAT):在GitHub个人设置中新建PAT,勾选
修改后的关键配置片段:
env: GH_TOKEN: ${{ secrets.ORG_GH_TOKEN }} jobs: build: runs-on: ubuntu-latest permissions: write-all # 其余步骤保持不变
内容的提问来源于stack exchange,提问作者Rio
相关产品推荐
相关产品推荐

