Error: GitHub rate limit exceeded for api.github.com plugin release metadata
Fixes pulumi import hitting GitHub API rate limits when fetching release metadata. For engineers whose Pulumi plugin downloads 403 in CI or fresh builds, with the token fix and wait guidance.
Error: GitHub rate limit exceeded for https://api.github.com/repos/pulumi/pulumi-converter-terraform/releases/latest
TL;DR
You hit GitHub's unauthenticated API rate limit while Pulumi fetched plugin release info. Set GITHUB_TOKEN for a much higher limit, or wait the duration in the message and retry.
The error
GitHub rate limit exceeded for https://api.github.com/repos/pulumi/pulumi-converter-terraform/releases/latest, try again in 7m51.830125s. You can set GITHUB_TOKEN to make an authenticated request with a higher rate limit.Fix it
- Read the
try again in [duration]value. That is the exact wait.
- Success check: you know whether waiting is practical.
- For an immediate fix:
export GITHUB_TOKEN [your value] token]and re-run the Pulumi command.
- Success check: the API call authenticates and the rate-limit error disappears.
- In CI, set
GITHUB_TOKEN(orsecrets.GITHUB_TOKEN) as a standard step before anything that downloads Pulumi plugins.
- Success check: repeated runs stop 403ing on plugin metadata fetches.
- If you just finished a build-heavy session, the limit may clear on its own within the hour. Retry before changing anything else.
- Success check: the same command works with no changes after the window.
When to use this
You hit this on any Pulumi command that downloads a plugin or converter from GitHub releases, especially on shared CI runners or right after build activity.
When NOT to use this
Do not use this for 404s on plugin downloads (wrong plugin name or version) or for registry auth errors. This is specifically the 60-requests/hour unauthenticated limit.
Compatibility
Pulumi CLI 3.x. GitHub API rate limits are external to Pulumi.
Variants
rate limit exceeded: 403 HTTP error fetching plugin from https://api.github.com/...- The same message naming other repos (
pulumi/pulumi-aws, provider repos) instead of the converter repo
Root cause
Pulumi resolves "latest" plugin versions via the GitHub releases API. Unauthenticated callers get 60 requests/hour per IP, which shared environments exhaust quickly.
Edge cases
- A token with no special scopes is enough; it only needs to identify you for the higher limit.
- Caching plugins locally (
pulumi plugin installonce, reuse) avoids the API call entirely on repeat runs.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.