fix(github): fail fast on a dead GH_TOKEN instead of hanging the mirror #50
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/workflows!50
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/github-distribute-fail-fast"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Both GitHub-track jobs in
webgrip/ploegrun 170 (v0.2.0-rc.20) died from one invalidGH_TOKEN, and only one of them said so.Distribute image (GHCR)docker login ghcr.io->denied: denied, exit 1Mirror & Release (GitHub)runningfor 20+ minutes, holding a runner slot with the caller's flattened job stuck onblockedWhy the messages are so bad
GHCR's token endpoint returns
{"code":"DENIED","message":"denied"}for a non-empty token it does not accept, versus the longer"requested access to the resource is denied"for an empty password — sodenied: deniedreads like a package-permission problem rather than a dead secret. Probed directly against ghcr.io to confirm.The mirror is worse: github.com 401s the push, git falls back to the credential subsystem, finds no helper, and blocks on a terminal prompt that never arrives. Nothing times out.
Changes
GH_TOKENagainstapi.github.com/userbefore doing any work, and echo the token's scopes. Verified against a junk token: named failure in ~1s instead of the opaque one.write:packages— fine-grained PATs can never carry it, which is the likeliest shape of the bad secret.GIT_TERMINAL_PROMPT=0, emptycredential.helper/core.askPass, and a 5mtimeoutbackstop, so no auth or egress failure can park a runner again.This makes the failure legible; it does not make the jobs pass.
webgrip/ploeg'sGHCR_TOKENstill needs rotating to a classic PAT withrepo+write:packages.ryangr0 referenced this pull request2026-08-25 05:40:57 +00:00