Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Locking down pipeliens

Sergey Stoma
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 4, 2018

Is there a way to lock down modification of bitbucket-pipelines.yml file?

For example, if we want to run the CI and push changes to servers only on merge to master or develop branch, we could target those specific branches in the pipeline.

But nothing really prevents a develop from creating a branch, modifying the pipeline definition to target their own branch, pushing that new branch - and yay (!) we are running some rogue code on test or prod...

 

1 answer

1 accepted

0 votes
Answer accepted
Sergey Stoma
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 4, 2018

Answering my own question since it doesn't look like it is possible to delete a question :-\

 

There is an outstanding request:

https://bitbucket.org/site/master/issues/13676/ability-to-restrict-who-can-run-deployment

Ana Retamal
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 5, 2018

Thanks for sharing that, Sergey! I'm sure that will help some other users :D

Have a good day,

Ana 

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events