I have a web hook registered to call the Jenkins BitBucket Push and Pull Request Plugin running in Jenkins on AWS. The EC2 instance on which Jenkins is running is bound to an Elastic IP address (i.e., static IP). How do I secure the calls to allow legitimate calls from bitbucket cloud through but not expose Jenkins to rogue calls?
The webhook infrastructure in bitbucket does not appear to support the use of credentials and the CIDR list of where these calls could originate is daunting. Is my only choice to punt and drop back to polling bitbucket.org from Jenkins?