# chainctl guardener github migrate create

URL: https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/platform/chainctl/chainctl-docs/chainctl_guardener_github_migrate_create.md
Last Modified: October 7, 2026
Tags: chainctl, Reference, Product

 chainctl guardener github migrate create Enqueue the repository&rsquo;s configured Actions and image migrations.
Synopsis Enqueue the repository&rsquo;s configured Actions and image migrations.
Each feature requires migrate.enabled: true in its effective configuration: .chainguard/actions.yaml for Actions and .chainguard/images.yaml for images. The enabled migrations open or update separate pull requests. The command returns one operation tracking both results; by default it waits and prints each result, including any failures. Pass &ndash;wait=false to return immediately with the operation name, which you can pass to &ldquo;migrate get&rdquo; later.
REPOSITORY may be a full URL (https://github.com/owner/repo) or the &ldquo;owner/repo&rdquo; shorthand; only github.com is supported today.
Actions migration requires guardener.actions.migrate, and image migration requires guardener.images.migrate on the group, which must own the repository&rsquo;s GitHub App installation. Permissions are checked independently for each feature: an unauthorized feature reports a failure while authorized migrations continue. At least one migration permission is required to create or read an operation. A feature disabled in the deployment or repository configuration completes as a successful no-op without failing the operation.
chainctl guardener github migrate create REPOSITORY [flags] Options --parent string Name or UIDP of the Chainguard group that owns the installation. Prompts interactively if omitted. --timeout duration How long to wait for the migration when --wait is set. (default 10m0s) --wait Wait for the migration operation to complete before returning. (default true) Options inherited from parent commands --api string The url of the Chainguard platform API. (default &#34;https://console-api.enforce.dev&#34;) --audience string The Chainguard token audience to request. (default &#34;https://console-api.enforce.dev&#34;) --config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly. --console string The url of the Chainguard platform Console. (default &#34;https://console.chainguard.dev&#34;) --force-color Force color output even when stdout is not a TTY. -h, --help Help for chainctl --issuer string The url of the Chainguard STS endpoint. (default &#34;https://issuer.enforce.dev&#34;) --log-level string Set the log level (debug, info) (default &#34;ERROR&#34;) -o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide] -v, --v int Set the log verbosity level. SEE ALSO chainctl guardener github migrate	- Migrate the Actions and images enabled by a repository&rsquo;s configuration. 
