It seems like Docker Hub is implemented as an OAuth app [2], where these granular options are not available and you have to grant access to all your repositories.
[1] https://developer.github.com/apps/differences-between-apps/
honest question, what's the point of using OAuth when the Authz is so coarse? Why not augment to have scopes per repo? Is it considered bad practice to have have a variable (repo name) as a scope?
> Service user (or machine/bot account) suggested
> Attaching your personal GitHub or Bitbucket account to this Docker Hub organization will allow other organization owners to create builds from your private repositories. We suggest using a service user (also referred to as a machine user or bot account).
c.f.: https://docs.docker.com/docker-cloud/builds/automated-build/...
Seems worthwhile to do this, if you're an enterprise or otherwise have sensitive private repos. But I agree that it would be better to have an easier per-repo authorization system, since many users won't bother going through the hassle of setting up a service account.
> c.f.: https://docs.docker.com/docker-cloud/builds/automated-build/....
Did they remove this language from your link? I don't see it anymore.
Also not sure what access permissions you need but deploy keys are repo level.
https://developer.github.com/v3/guides/managing-deploy-keys/...
Machine users are another option.
https://developer.github.com/v3/guides/managing-deploy-keys/...