Repository navigation
Fix preview environment cleanup token and naming - #202
Conversation
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 27 minutes and 4 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughUpdated the preview workflow to fix invalid environment name interpolation, simplified YAML formatting, added explicit cleanup job permissions, and changed the cleanup step to always run using Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🔎 Preview deployed: https://kody-pr-202.kentcdodds.workers.dev Worker: Mocks:
|
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/preview.yml:
- Around line 444-446: The workflow currently grants only "permissions:
contents: read" and "deployments: write" which cannot delete repository
environments; locate the permissions block and the job/step that calls the
DELETE /repos/{owner}/{repo}/environments/{environment_name} endpoint and either
(A) remove the environment-deletion step entirely, or (B) change the step to use
a personal access token or GitHub App with proper Environments: write scope
(e.g., reference a secret like secrets.GITHUB_PAT) instead of GITHUB_TOKEN;
update any step that references the environment deletion so it uses the
alternate token and ensure the permissions block remains compatible with that
approach.
- Around line 57-58: The preview environment naming and permissions are
incorrect: change the deploy job's environment name expression (currently
"preview-${{ github.event.pull_request.number || inputs.pr_number ||
github.run_id }}") to a deterministic branch identifier such as using
"inputs.preview_name || github.ref_name" so branch-triggered workflow_dispatch
doesn't create orphaned "preview-${{ github.run_id }}" environments, and update
the cleanup job to both request the correct permission scope by adding
"environments: write" to its permissions and ensure the cleanup logic uses the
exact same naming expression (or the inputs.preview_name || github.ref_name
expression) when calling DELETE
/repos/{owner}/{repo}/environments/{environment_name} so deletion succeeds.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: bc9e020a-ec36-4c04-aace-cb3133abeaaa
📒 Files selected for processing (1)
.github/workflows/preview.yml
| name: preview-${{ github.event.pull_request.number || inputs.pr_number || | ||
| github.run_id }} |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
# First, locate and examine the preview.yml workflow file
fd -t f "preview.yml" .github/Repository: kentcdodds/kody
Length of output: 88
🏁 Script executed:
# Read the workflow file to examine the lines mentioned
wc -l .github/workflows/preview.ymlRepository: kentcdodds/kody
Length of output: 92
🏁 Script executed:
# Check lines 57-58 (deploy environment naming) and surrounding context
sed -n '50,70p' .github/workflows/preview.ymlRepository: kentcdodds/kody
Length of output: 712
🏁 Script executed:
# Check lines 599-603 (cleanup deletion logic)
sed -n '590,610p' .github/workflows/preview.ymlRepository: kentcdodds/kody
Length of output: 782
🏁 Script executed:
# Check the cleanup script to understand the condition
sed -n '440,460p' .github/workflows/preview.ymlRepository: kentcdodds/kody
Length of output: 651
🏁 Script executed:
# Get the full cleanup script context (lines 550-620)
sed -n '550,620p' .github/workflows/preview.ymlRepository: kentcdodds/kody
Length of output: 2617
🏁 Script executed:
# Also check what inputs are available and how target is used
sed -n '1,100p' .github/workflows/preview.ymlRepository: kentcdodds/kody
Length of output: 2726
🌐 Web query:
GitHub REST API DELETE /repos/environments permission scope required
💡 Result:
The required permission scope for the GitHub REST API DELETE /repos/{owner}/{repo}/environments/{environment_name} endpoint is the "repo" scope for OAuth app tokens and personal access tokens (classic). This applies particularly when using the endpoint with private repositories, but the documentation states it explicitly for this DELETE operation.
Citations:
- 1: https://docs.github.com/rest/deployments/environments
- 2: https://docs.github.com/en/rest/deployments/environments
- 3: https://help.github.com/en/rest/deployments/environments
🌐 Web query:
GitHub Actions GITHUB_TOKEN permissions deployments write delete environment
💡 Result:
The GITHUB_TOKEN in GitHub Actions workflows has configurable permissions via the 'permissions' key at workflow or job level. By default, it has read access to most scopes (contents: read, actions: read, etc.), but write permissions must be explicitly granted, such as deployments: write for creating/updating deployments and environments: write for managing environment configurations. For deployments: - GITHUB_TOKEN can create deployments when a job references an environment (automatic via GitHub Actions). - To explicitly grant: permissions: { deployments: write } For environments: - GITHUB_TOKEN supports read access by default. - For write/delete (e.g., API calls to create/update/delete environments), explicitly grant: permissions: { environments: write } - Note: Some advanced environment management may require a GitHub App token or PAT with repo/administration scope, as GITHUB_TOKEN (GitHub App installation token) lacks certain repository administration permissions like full environment CRUD via API. Example workflow snippet: jobs: deploy: permissions: deployments: write environments: write environment: production steps: - name: Deploy run: echo "Deploying..." Sources confirm GITHUB_TOKEN needs explicit write permissions for these scopes, and limitations exist for delete/create environments via standard GITHUB_TOKEN (requires alternatives for full control).
Citations:
- 1: https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs/
- 2: https://docs.github.com/actions/deployment/targeting-different-environments/using-environments-for-deployment
- 3: https://docs.github.com/en/actions/configuring-and-managing-workflows/authenticating-with-the-github_token
- 4: https://docs.github.com/en/actions/concepts/security/github_token
- 5: https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs
- 6: https://docs.github.com/en/rest/deployments/environments?apiVersion=2026-03-10
- 7: https://stackoverflow.com/questions/77214899/permission-needed-to-create-an-environment-from-a-github-actions-workflow
- 8: https://github.com/marketplace/actions/delete-deployment-environment
Fix orphaned branch preview environments and add missing environment deletion permissions.
When workflow_dispatch is triggered with target=branch (the default), the deploy job creates preview-${github.run_id}, but the cleanup job intentionally skips GitHub environment deletion with the message "branch-targeted cleanups use a different naming scheme." This leaves an orphaned environment for each manual branch deployment.
Additionally, the cleanup job declares only deployments: write permission, but calling DELETE /repos/{owner}/{repo}/environments/{environment_name} requires either environments: write or the broader repo scope. The GITHUB_TOKEN used here lacks full environment management permissions for deletion via the REST API.
To fix this:
- Add
environments: writepermission to the cleanup job (minimum requirement for environment deletion) - Update the deploy environment name to use a deterministic identifier for branch deployments (e.g.,
inputs.preview_name || github.ref_name), or explicitly implement branch-targeted deletion logic using the same naming expression in the cleanup script
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/preview.yml around lines 57 - 58, The preview environment
naming and permissions are incorrect: change the deploy job's environment name
expression (currently "preview-${{ github.event.pull_request.number ||
inputs.pr_number || github.run_id }}") to a deterministic branch identifier such
as using "inputs.preview_name || github.ref_name" so branch-triggered
workflow_dispatch doesn't create orphaned "preview-${{ github.run_id }}"
environments, and update the cleanup job to both request the correct permission
scope by adding "environments: write" to its permissions and ensure the cleanup
logic uses the exact same naming expression (or the inputs.preview_name ||
github.ref_name expression) when calling DELETE
/repos/{owner}/{repo}/environments/{environment_name} so deletion succeeds.
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Bugbot Autofix prepared a fix for the issue found in the latest run.
- ✅ Fixed: Cleanup step still references removed secret, never runs
- Switched the cleanup step to always run with the built-in token by removing the secret guard and using
${{ github.token }}for the GitHub API call.
- Switched the cleanup step to always run with the built-in token by removing the secret guard and using
You can send follow-ups to the cloud agent here.
Reviewed by Cursor Bugbot for commit 010ee24. Configure here.
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>

Summary
github.run_iddeployments: writepermissionVerification
24606236180403 Resource not accessible by integrationforDELETE /repos/{owner}/{repo}/environments/{environment_name}when usinggithub.token, withx-accepted-github-permissions: administration=writenpx prettier --check ".github/workflows/preview.yml"Reviewer findings assessed
github.token; I kept the dedicated secret token for environment deletion.Artifact:
Summary by CodeRabbit
Bug Fixes
Chores