How to Configure actions/checkout for GitHub Enterprise Server
To configure actions/checkout for GitHub Enterprise Server, set the github-server-url input to your GHES instance URL (e.g., https://ghes.mycompany.com) and provide a Personal Access Token or SSH key that is valid for your enterprise environment.
The actions/checkout repository provides the official GitHub Action for cloning repositories during workflow runs. While it defaults to GitHub.com, the action fully supports self-hosted GitHub Enterprise Server (GHES) instances through a specific input parameter. This guide explains how to override the default host URL and authenticate against your enterprise environment using the actual source code implementation.
Understanding the github-server-url Input
Input Declaration in action.yml
The github-server-url input is declared in action.yml at lines 98-101, where it defaults to the URL of the runner's host environment. According to the source code, this input accepts any valid GHES URL such as https://ghes.mycompany.com, allowing the action to target your private instance instead of the public GitHub.com endpoint.
Implementation in input-helper.ts
In src/input-helper.ts at line 162, the workflow reads the github-server-url value and stores it within the Input configuration object that drives the checkout process. This value ensures that all Git operations—including git clone and git fetch—use your enterprise base URL rather than the default https://github.com.
Configuring Authentication for GHES
When targeting GHES, you must provide credentials that are valid for your enterprise instance, as the default github.token only works for GitHub.com.
Personal Access Token (PAT)
Use a PAT generated from your GHES instance with appropriate repository permissions. Pass this token to the token input in your workflow configuration. The src/git-auth-helper.ts file handles the authentication header setup for these credentials.
SSH Key Authentication
Alternatively, configure SSH authentication by providing a private key via the ssh-key input and specifying known hosts using ssh-known-hosts. The src/git-auth-helper.ts file configures the Git client to use these SSH credentials when connecting to your GHES instance.
Practical Configuration Examples
Basic Checkout from GHES
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout from GHES
uses: actions/checkout@v7
with:
github-server-url: https://ghes.mycompany.com
repository: my-org/my-repo
token: ${{ secrets.GHES_PAT }}
Shallow Fetch with Specific Branch
- uses: actions/checkout@v7
with:
github-server-url: https://ghes.mycompany.com
repository: my-org/my-repo
ref: feature/awesome-feature
fetch-depth: 1
token: ${{ secrets.GHES_PAT }}
SSH Authentication
- uses: actions/checkout@v7
with:
github-server-url: https://ghes.mycompany.com
repository: my-org/my-repo
ssh-key: ${{ secrets.GHES_SSH_KEY }}
ssh-known-hosts: |
mycompany.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQD...
ssh-strict: true
Sparse Checkout on GHES
- uses: actions/checkout@v7
with:
github-server-url: https://ghes.mycompany.com
repository: my-org/my-repo
sparse-checkout: |
src/
docs/
sparse-checkout-cone-mode: false
Key Source Files and Implementation Details
The checkout flow for GHES relies on several core files in the actions/checkout repository:
action.yml: Declares all inputs includinggithub-server-urlat lines 98-101src/input-helper.ts: Reads workflow inputs at line 162 and builds the configuration objectsrc/git-source-provider.ts: Constructs clone URLs based on thegithub-server-urlvaluesrc/git-auth-helper.ts: Handles token and SSH authentication setup for the Git clientsrc/main.ts: Orchestrates the overall checkout execution
Summary
- Set
github-server-urlto your GHES instance URL (e.g.,https://ghes.mycompany.com) to redirect all Git operations from GitHub.com to your enterprise server - Provide a GHES-compatible Personal Access Token or SSH key since the default
github.tokenonly authenticates against GitHub.com - All other inputs (
fetch-depth,sparse-checkout,submodules,ref) behave identically to GitHub.com configurations once the server URL is set - The action reads the server URL in
src/input-helper.tsand applies it to URL construction insrc/git-source-provider.ts
Frequently Asked Questions
Can I use the default GITHUB_TOKEN for GHES authentication?
No. The default github.token provided by GitHub Actions only authenticates against GitHub.com. For GitHub Enterprise Server, you must create a Personal Access Token (PAT) on your GHES instance with appropriate repository scopes and pass it via the token input, as implemented in src/git-auth-helper.ts.
Does the github-server-url input support HTTP or only HTTPS?
While the examples typically show HTTPS URLs like https://ghes.mycompany.com, the implementation in src/git-source-provider.ts constructs URLs based on the provided string. You should use HTTPS for secure connections, though the underlying Git commands would technically accept HTTP if your enterprise instance configuration supports it.
How do I configure actions/checkout for GHES when using self-hosted runners?
Self-hosted runners automatically detect the GitHub Enterprise Server URL from the GITHUB_SERVER_URL environment variable. However, you can still explicitly set github-server-url in your workflow to override this behavior or ensure consistency across different runner environments, as processed by src/input-helper.ts.
Will sparse checkout and shallow fetch work the same way on GHES?
Yes. Once you configure github-server-url, all standard features like sparse-checkout, fetch-depth, and submodules function identically to GitHub.com because the action simply redirects the Git operations to your enterprise URL while maintaining the same feature logic in src/git-source-provider.ts.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →