Common errors
Identify the failed operation before retrying.
On this page
Find the failed handoff
Keep the error code, time, draft ID and revision or repository name when asking support. Never share setup links, cookies, tokens or enrollment approval URLs. See Ceremonies for each operation’s completion evidence.
Mermaid source
flowchart LR
R["Open review for saved validated revision"] --> E["Review prepared bytes; fresh passkey signs and publishes"]
E -->|confirmed| C["Read signed result and exact immutable release tuple"]
E -->|refused or uncertain| F["Stop and inspect authoritative state"]Repository not ready for enrollment
Choose the intended workspace. In Pushgate Settings, choose Check delivery and inspect both repository enrollment setup and delivery results. A delivery success alone does not prove enrollment registration. If registration is unavailable, disabled, or repeatedly fails, give support the error code and repository. Rotating the agent setup link does not repair registration. Do not authorize an empty or different scope.
Policy preparation
| Code | Next action |
|---|---|
description_required | Write a description of what the policy requires in the draft editor, then save. The release signs this text. An imported file does not supply one. |
description_too_long | Shorten the draft description to at most 512 UTF-8 bytes, then save and validate. Non-ASCII characters can occupy multiple bytes. |
invalid_policy | For an older generated draft, choose Refresh platform trust, then save and validate. Otherwise inspect validation errors and correct the source before opening review. |
policy_trust_unresolved / policy_trust_invalid | For a generated policy, choose Refresh platform trust. For custom trust, correct all referenced evidence and timestamp certificates. Save and validate again. |
invalid_params | Check the release name and tag, each at most 128 supported characters, and the description byte limit. |
summary_too_long | Split the policy into smaller policies: each complete review supports at most 64 summary lines. |
policy_review_refused | An unclassified preparation refusal needs support investigation using the draft ID, revision and time. Repeated unchanged requests are not a repair. |
review_outcome_unknown / publication_tracking_unavailable | Reload for read-only recovery. If the outcome remains unknown, contact support for reconciliation. Do not delete tracking state or create repeated signing requests. |
draft_changed / draft_not_validated | Reload the current draft, save your intended revision and validate before requesting review. |
Push and delivery
A policy denial requires the missing or corrected evidence for the exact commit. Follow the machine-readable challenge; retry only when its prerequisites are satisfied. A queued or admitted push is not yet delivered. Check the exact ref and commit with cilock pushgate status --wait. An unavailable decision or missing provenance cannot be repaired with break-glass.