Reviewers check who; branch rules check what. An environment accepts any ref, only protected branches, or only branches and tags matching File.fnmatch patterns, the choice made by custom_branch_policies: true in 3.11.4:
gh api -X POST repos/{owner}/{repo}/environments/production/deployment-branch-policies \
-f name=main -f type=branch --jq '{name, type}'
gh api -X POST repos/{owner}/{repo}/environments/production/deployment-branch-policies \
-f name='v*' -f type=tag --jq '{name, type}'Output
{"name":"main","type":"branch"}
{"name":"v*","type":"tag"}To test the rule, the same commit was pushed as a branch, try/deploy-from-branch, and deployed from there with gh 29 workflow run deploy.yml --ref try/deploy-from-branch:
gh run view 36135153506Output
X try/deploy-from-branch Deploy · 36135153506 ... X Branch "try/deploy-from-branch" is not allowed to deploy to production due to environment protection rules. ...
staging, with no branch rule, deployed; production failed without running a step, so its secret never reached a runner. The rule trusts main, so it is only as strong as the "Protect main" ruleset (Rulesets).