You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Action中使用gh创建仓库遇权限错误求助

问题

作为组织管理员,在GitHub Action中通过GitHub CLI(gh)创建仓库时遇到报错:GraphQL: Resource not accessible by integration (createRepository)。已在action.yaml中设置permissions: write-all并使用${{ secrets.GITHUB_TOKEN }},需要解决权限配置问题。

相关配置及错误信息如下:

action.yaml配置

name: Create Repo
on: 
  push:
    branches: [ master ]

env:
  GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  TEMPLATE_REPO: template # this is the template directory

jobs:
  build:
    name: Create Repo
    runs-on: ubuntu-latest
    permissions: write-all
    steps:
    - name: Check out repository
      uses: actions/checkout@v3

    - name: Repo Create
      run: |
        git -C ${{ env.TEMPLATE_REPO }} init
        gh repo create repo-test --private --source=${{ env.TEMPLATE_REPO }}

错误信息

Initialized empty Git repository in /home/runner/work/repo-central/repo-central/template/.git/
GraphQL: Resource not accessible by integration (createRepository)
Error: Process completed with exit code 1.
解决方案
  • 核心问题:默认的GITHUB_TOKEN权限仅限触发Action的当前仓库,没有跨仓库/创建组织仓库的权限,哪怕你是组织管理员也无效。
  • 解决步骤:
    1. 生成Personal Access Token(PAT):在GitHub个人设置中新建PAT,勾选repo权限(若为组织仓库,确保该PAT拥有组织的仓库创建权限)。
    2. 添加PAT到Secrets:将生成的PAT添加到仓库或组织的Secrets中,命名为ORG_GH_TOKEN(可自定义,避免与默认GITHUB_TOKEN重名)。
    3. 修改action.yaml配置:
      • 把env中的GH_TOKEN替换为${{ secrets.ORG_GH_TOKEN }}。
      • 保留permissions: write-all(或更精准设置repositories: write,write-all已足够覆盖需求)。

修改后的关键配置片段:

env:
  GH_TOKEN: ${{ secrets.ORG_GH_TOKEN }}
jobs:
  build:
    runs-on: ubuntu-latest
    permissions: write-all
    # 其余步骤保持不变

内容的提问来源于stack exchange,提问作者Rio

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 05:33:12