GitHub Actions "Missing environment 'production'"
A job that names environment: production expects an environment defined in the repository. If it is misspelled or never created, the deploy cannot resolve its protection rules, secrets, or URL.
What this error means
The deploy job fails or the environment-scoped secrets are empty because the named environment does not match any configured environment.
Error: Missing environment 'production'
The environment referenced in the job does not exist in this repository.Diagnose it: print the context before you change anything
Most workflow-expression bugs are not syntax errors, they are an expression reading something that is empty. GitHub resolves a missing property to an empty string instead of failing the run, so a wrong reference looks like a logic bug rather than a mistake. Dump the contexts first and you will usually see the answer immediately.
- name: Dump contexts
run: |
echo '--- github ---' ; echo '${{ toJSON(github) }}'
echo '--- needs ---' ; echo '${{ toJSON(needs) }}'
echo '--- steps ---' ; echo '${{ toJSON(steps) }}'
echo '--- matrix ---' ; echo '${{ toJSON(matrix) }}'
echo '--- inputs ---' ; echo '${{ toJSON(inputs) }}'Check the context is allowed where you used it
Contexts are not available everywhere. The same expression can be valid in a step if and invalid in a job if, which is why an expression that works in one workflow fails when moved.
| Where you wrote it | Contexts available there |
|---|---|
run-name | github, inputs, vars |
concurrency | github, inputs, vars |
Top-level env | github, secrets, inputs, vars |
jobs.<id>.if | github, needs, vars, inputs |
jobs.<id>.steps.if | github, needs, strategy, matrix, job, runner, env, vars, steps, inputs |
jobs.<id>.outputs | Full access, including secrets |
Reusable workflow outputs | github, jobs, vars, inputs |
Common causes
Environment never created
No environment named production exists under Settings > Environments, so the reference has nothing to bind to.
Name mismatch or casing
The job uses a slightly different name (prod, Production) than the configured environment.
How to fix it
Create or correct the environment name
- Create the environment under Settings > Environments with the exact name used in the job.
- Or change the job to reference the existing environment name (names are case-sensitive in matching).
- Add protection rules and environment secrets there if the deploy needs them.
jobs:
deploy:
runs-on: ubuntu-latest
environment:
name: production
url: ${{ steps.deploy.outputs.page_url }}Catch it before it reaches CI
Every failure in this cluster is statically detectable. actionlint parses workflow expressions, checks context availability against the same rules above, and validates needs references, so these bugs never need to cost you a run.
# one-off
docker run --rm -v "$(pwd):/repo" --workdir /repo rhysd/actionlint:latest -color
# as a job, before anything expensive runs
- uses: actions/checkout@v4
- run: |
bash <(curl -s https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash)
./actionlint -colorHow to prevent it
- Define every referenced environment in repository settings before merging the workflow.
- Keep environment names consistent across workflows to avoid drift.