Deploy GitHub Actions Migration Agents to your GitHub Enterprise environment.
- Create
.github-privaterepository (Internal visibility) - Clone and configure this repository
- Push to
.github-private - Configure secrets and variables for automation
- Create the
COPILOT_MCP_GITHUB_PERSONAL_ACCESS_TOKENCopilot Agents secret in each target organization (manual) - Enable agents in Enterprise settings
- GitHub Enterprise Cloud with Copilot Business/Enterprise
- Enterprise Owner permissions
- Organization Admin permissions
- Git client
-
Create repository in your organization:
- Name:
.github-private(exact name required) - Visibility: Internal (required for agent access to knowledgebase)
- Do not initialize with README
- Name:
-
Note the repository URL for later steps
Why Internal? Agents use GitHub MCP to access knowledgebase files. Internal visibility enables this while keeping content private to your enterprise.
git clone https://github.com/github/actions-migrations-via-copilot.git
cd actions-migrations-via-copilotReplace {MY_ORGANIZATION} with your organization slug:
# macOS/Linux
find agents -name "*.md" -type f -exec sed -i '' 's/{MY_ORGANIZATION}/YOUR-ORG-SLUG/g' {} +
# Verify
grep -r "{MY_ORGANIZATION}" agents/Should return no results.
git remote add enterprise https://github.com/YOUR-ORG-SLUG/.github-private.git
git push enterprise mainVerify at https://github.com/YOUR-ORG-SLUG/.github-private
-
Create app at
https://github.com/organizations/YOUR-ORG-SLUG/settings/apps:- Name:
CI/CD Migration Automation - Webhook: Inactive
- Repository permissions: Contents (R/W), Issues (R/W), Pull requests (R/W), Workflows (R/W)
- Organization permissions: Custom properties (Read), Members (Read)
- Where to install: "This enterprise"
- Name:
-
Generate private key and save the
.pemfile -
Install app in your organizations (select "All repositories")
-
Note the App ID from the app settings page
Generate a Classic PAT with:
- Scopes:
repo,admin:org - SSO authorization: Enable for all organizations
- Expiration: Per your organization policy
Navigate to https://github.com/YOUR-ORG-SLUG/.github-private/settings/secrets/actions
| Secret Name | Value |
|---|---|
GH_APP_PEM |
Contents of .pem file (include BEGIN/END lines) |
ISSUE_SUBMIT_TOKEN |
PAT value |
Edit .github/settings/config.yaml:
gh_app_id: '123456' # Your GitHub App ID
gh_migration_type:
default_value: 'Jenkins'
description: 'The type of migration for this repository'
other_values:
- 'Jenkins'
- 'Azure DevOps'
- 'CircleCI'
- 'GitLab'
- 'Travis CI'
- 'Bamboo'
- 'Bitbucket'
- 'DroneCI'
organizations:
- 'YOUR-ORG-SLUG'
batch_size: 100Commit and push:
git add .github/settings/config.yaml
git commit -m "Configure automation settings"
git push enterprise mainRun the Settings workflow to create variables from config:
- Go to
https://github.com/YOUR-ORG-SLUG/.github-private/actions - Click "Configuration Settings" workflow
- Click "Run workflow" → Select
main→ "Run workflow" - Verify success (green checkmark)
- Check variables at
https://github.com/YOUR-ORG-SLUG/.github-private/settings/variables/actions
Expected variables: GH_APP_ID, GH_MIGRATION_TYPE_DEFAULT, ORGANIZATIONS, BATCH_SIZE
The migration agents use the GitHub MCP server, which requires a Personal Access Token exposed as the COPILOT_MCP_GITHUB_PERSONAL_ACCESS_TOKEN secret. This must be created as a Copilot Agents secret at the organization level. There is no API for this, so it must be configured manually for each organization listed in .github/settings/config.yaml.
First, create a dedicated PAT for MCP knowledgebase access:
- Generate a fine-grained PAT (recommended) scoped only to the
.github-privaterepository:- Resource owner: Your organization
- Repository access: Only select repositories →
.github-private - Repository permissions: Contents (Read-only), Metadata (Read-only)
- Expiration: Per your organization policy
- SSO authorization: Enable for the organization
- If your organization requires classic PATs, generate one with the minimum scope
repoand authorize SSO for the organization. Prefer the fine-grained option above.
Why a dedicated token? Scoping this PAT to
.github-privatewith read-only access limits the blast radius if it is ever exposed. Do not reuseISSUE_SUBMIT_TOKEN, which has broader privileges needed for the automation workflows.
Then, for each organization:
- Navigate to
https://github.com/organizations/YOUR-ORG-SLUG/settings/secrets/agents - Click New organization secret
- Configure the secret:
- Name:
COPILOT_MCP_GITHUB_PERSONAL_ACCESS_TOKEN - Value: The dedicated PAT created above
- Name:
- Click Add secret
Note: Repeat this step for every organization in the
organizationslist ofconfig.yaml. The secret must be available to Copilot coding agent runs in repositories belonging to those organizations.
-
Navigate to Enterprise AI controls:
- Click profile photo → Your enterprises → [Your Enterprise]
- Click AI controls
-
Enable custom agents:
- Find "Custom agents" section
- Select your organization from dropdown
- Verify agents appear:
- Jenkins Migrator
- Azure DevOps Migrator
- CircleCI Migrator
- GitLab Migrator
- Travis CI Migrator
- Bamboo Migrator
- Bitbucket Migrator
- Drone CI Migrator
- Reusable Workflow Builder
-
Wait 5-10 minutes for agent registration to propagate
- Navigate to github.com/copilot/agents
- Verify your migration agents appear
- Open a test repository with CI/CD configuration
- Invoke an agent through Copilot Chat
- Verify agent can access knowledgebase
When adding new agents (see extending.md):
- Add agent file to
agents/directory - Create knowledgebase files in
knowledge/ - Update organization references
- Commit and push to
.github-private
# After adding new agent
git add agents/ knowledge/
git commit -m "Add <platform> migration agent"
git push enterprise mainChanges are live immediately.
Update mappings and patterns as Actions evolves:
# Edit files in knowledge/
nano knowledge/actions-mapping/jenkins.md
# Commit and push
git add knowledge/
git commit -m "Update action mappings"
git push enterprise mainAgents automatically use latest knowledgebase content.
- Review Copilot usage reports in Enterprise settings
- Collect feedback from migration teams
- Update knowledgebase based on real-world patterns
- Refine agents based on common issues
| Issue | Solution |
|---|---|
| Agents not appearing | Verify .github-private exists, wait 10 minutes, check Enterprise AI settings |
| Cannot access knowledgebase | Ensure repository visibility is Internal, verify org slug in agent files |
Organization slug still shows {MY_ORGANIZATION} |
Re-run sed command or manually edit agent files |
| Validation errors in migrations | Review migration report, update knowledgebase mappings |
- Keep
.github-privateInternal visibility (never Public) - Review repository access regularly
- Monitor agent usage in audit logs
- Validate GitHub Secrets configuration in migrated workflows
- Use environment protection rules for sensitive workflows
- Operations Guide - Learn how to use migration agents
- Extending Guide - Add support for new CI/CD platforms
- Train teams on agent invocation
- Establish migration workflows
- Monitor and iterate based on feedback