Deployment Restrictions

Deployment Branch and Tag Restrictions

Reviewers check who; branch rules check what. An environment accepts any ref, only protected branches, or only branches and tags matching File.fnmatch patterns, the choice made by custom_branch_policies: true in 3.11.4:

Allowing production deployments from main and from v* tags onlyShell
gh api -X POST repos/{owner}/{repo}/environments/production/deployment-branch-policies \
  -f name=main -f type=branch --jq '{name, type}'
gh api -X POST repos/{owner}/{repo}/environments/production/deployment-branch-policies \
  -f name='v*' -f type=tag --jq '{name, type}'
Output
{"name":"main","type":"branch"}
{"name":"v*","type":"tag"}

To test the rule, the same commit was pushed as a branch, try/deploy-from-branch, and deployed from there with gh 29 workflow run deploy.yml --ref try/deploy-from-branch:

The run started from a branch that production does not acceptShell
gh run view 36135153506
Output
X try/deploy-from-branch Deploy · 36135153506
...
X Branch "try/deploy-from-branch" is not allowed to deploy to production due to environment
  protection rules.
...

staging, with no branch rule, deployed; production failed without running a step, so its secret never reached a runner. The rule trusts main, so it is only as strong as the "Protect main" ruleset (Rulesets).