Bug information
Steps to reproduce (required)
Run the scheduled .github/workflows/test.yaml workflow with a sample failure. Its Create GitHub issue on failure step runs gh issue create using GH_TOKEN: ${{ github.token }}.
Representative failure: https://github.com/radius-project/samples/actions/runs/34119803387 on v0.60.
Observed behavior (required)
The reporting step fails with:
GraphQL: Resource not accessible by integration (createIssue)
The workflow declares permissions: {} globally and the test job grants only contents: read; the reporting step attempts to create an issue without a declared issues: write permission. Investigate effective token permissions and repository policy to confirm the complete cause.
Desired behavior (required)
Scheduled sample-test failures automatically create a GitHub issue with the expected sample-specific title, workflow-run link, and test-failure label.
Provide narrowly scoped issue-write access to scheduled failure reporting without unnecessarily broadening privileges for pull-request test jobs. Verify the reporting path with a controlled failure and assess which maintained branches share the defect.
Workaround (optional)
Inspect failed workflow runs and file failures manually.
System information
rad Version (required)
Radius v0.60.2 was reported in the September 7 volumes job. This failure concerns the workflow's GitHub token permissions rather than Radius initialization.
Operating system (required)
GitHub Actions ubuntu-24.04 runner.
Additional context
Follow-up to #2661, which addresses the separate v0.60 default-environment initialization failure. Keep the permission fix independent so deployment recovery is not blocked by reporting changes. The PR release-version selection correction is included in the #2661 implementation plan and does not need a separate issue.
Bug information
Steps to reproduce (required)
Run the scheduled
.github/workflows/test.yamlworkflow with a sample failure. ItsCreate GitHub issue on failurestep runsgh issue createusingGH_TOKEN: ${{ github.token }}.Representative failure: https://github.com/radius-project/samples/actions/runs/34119803387 on
v0.60.Observed behavior (required)
The reporting step fails with:
The workflow declares
permissions: {}globally and the test job grants onlycontents: read; the reporting step attempts to create an issue without a declaredissues: writepermission. Investigate effective token permissions and repository policy to confirm the complete cause.Desired behavior (required)
Scheduled sample-test failures automatically create a GitHub issue with the expected sample-specific title, workflow-run link, and
test-failurelabel.Provide narrowly scoped issue-write access to scheduled failure reporting without unnecessarily broadening privileges for pull-request test jobs. Verify the reporting path with a controlled failure and assess which maintained branches share the defect.
Workaround (optional)
Inspect failed workflow runs and file failures manually.
System information
rad Version (required)
Radius v0.60.2 was reported in the September 7 volumes job. This failure concerns the workflow's GitHub token permissions rather than Radius initialization.
Operating system (required)
GitHub Actions
ubuntu-24.04runner.Additional context
Follow-up to #2661, which addresses the separate v0.60 default-environment initialization failure. Keep the permission fix independent so deployment recovery is not blocked by reporting changes. The PR release-version selection correction is included in the #2661 implementation plan and does not need a separate issue.