How to Configure actions/checkout for GitHub Enterprise Server

To configure actions/checkout for GitHub Enterprise Server, set the github-server-url input to your GHES instance URL (e.g., https://ghes.mycompany.com) and provide a Personal Access Token or SSH key that is valid for your enterprise environment.

The actions/checkout repository provides the official GitHub Action for cloning repositories during workflow runs. While it defaults to GitHub.com, the action fully supports self-hosted GitHub Enterprise Server (GHES) instances through a specific input parameter. This guide explains how to override the default host URL and authenticate against your enterprise environment using the actual source code implementation.

Understanding the github-server-url Input

Input Declaration in action.yml

The github-server-url input is declared in action.yml at lines 98-101, where it defaults to the URL of the runner's host environment. According to the source code, this input accepts any valid GHES URL such as https://ghes.mycompany.com, allowing the action to target your private instance instead of the public GitHub.com endpoint.

Implementation in input-helper.ts

In src/input-helper.ts at line 162, the workflow reads the github-server-url value and stores it within the Input configuration object that drives the checkout process. This value ensures that all Git operations—including git clone and git fetch—use your enterprise base URL rather than the default https://github.com.

Configuring Authentication for GHES

When targeting GHES, you must provide credentials that are valid for your enterprise instance, as the default github.token only works for GitHub.com.

Personal Access Token (PAT)

Use a PAT generated from your GHES instance with appropriate repository permissions. Pass this token to the token input in your workflow configuration. The src/git-auth-helper.ts file handles the authentication header setup for these credentials.

SSH Key Authentication

Alternatively, configure SSH authentication by providing a private key via the ssh-key input and specifying known hosts using ssh-known-hosts. The src/git-auth-helper.ts file configures the Git client to use these SSH credentials when connecting to your GHES instance.

Practical Configuration Examples

Basic Checkout from GHES

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout from GHES
        uses: actions/checkout@v7
        with:
          github-server-url: https://ghes.mycompany.com
          repository: my-org/my-repo
          token: ${{ secrets.GHES_PAT }}

Shallow Fetch with Specific Branch

- uses: actions/checkout@v7
  with:
    github-server-url: https://ghes.mycompany.com
    repository: my-org/my-repo
    ref: feature/awesome-feature
    fetch-depth: 1
    token: ${{ secrets.GHES_PAT }}

SSH Authentication

- uses: actions/checkout@v7
  with:
    github-server-url: https://ghes.mycompany.com
    repository: my-org/my-repo
    ssh-key: ${{ secrets.GHES_SSH_KEY }}
    ssh-known-hosts: |
      mycompany.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQD...
    ssh-strict: true

Sparse Checkout on GHES

- uses: actions/checkout@v7
  with:
    github-server-url: https://ghes.mycompany.com
    repository: my-org/my-repo
    sparse-checkout: |
      src/
      docs/
    sparse-checkout-cone-mode: false

Key Source Files and Implementation Details

The checkout flow for GHES relies on several core files in the actions/checkout repository:

Summary

  • Set github-server-url to your GHES instance URL (e.g., https://ghes.mycompany.com) to redirect all Git operations from GitHub.com to your enterprise server
  • Provide a GHES-compatible Personal Access Token or SSH key since the default github.token only authenticates against GitHub.com
  • All other inputs (fetch-depth, sparse-checkout, submodules, ref) behave identically to GitHub.com configurations once the server URL is set
  • The action reads the server URL in src/input-helper.ts and applies it to URL construction in src/git-source-provider.ts

Frequently Asked Questions

Can I use the default GITHUB_TOKEN for GHES authentication?

No. The default github.token provided by GitHub Actions only authenticates against GitHub.com. For GitHub Enterprise Server, you must create a Personal Access Token (PAT) on your GHES instance with appropriate repository scopes and pass it via the token input, as implemented in src/git-auth-helper.ts.

Does the github-server-url input support HTTP or only HTTPS?

While the examples typically show HTTPS URLs like https://ghes.mycompany.com, the implementation in src/git-source-provider.ts constructs URLs based on the provided string. You should use HTTPS for secure connections, though the underlying Git commands would technically accept HTTP if your enterprise instance configuration supports it.

How do I configure actions/checkout for GHES when using self-hosted runners?

Self-hosted runners automatically detect the GitHub Enterprise Server URL from the GITHUB_SERVER_URL environment variable. However, you can still explicitly set github-server-url in your workflow to override this behavior or ensure consistency across different runner environments, as processed by src/input-helper.ts.

Will sparse checkout and shallow fetch work the same way on GHES?

Yes. Once you configure github-server-url, all standard features like sparse-checkout, fetch-depth, and submodules function identically to GitHub.com because the action simply redirects the Git operations to your enterprise URL while maintaining the same feature logic in src/git-source-provider.ts.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →