Hello, we've configured a webhook in a bitbucket cloud repo to call our on-prem jenkins instance. We've exposed the webhook endpoint using a whitelist for source IPs taken from https://support.atlassian.com/organization-administration/docs/ip-addresses-and-domains-for-atlassian-cloud-products/#AtlassiancloudIPrangesanddomains-OutgoingConnections - the "subset of ranges" in the doc.
The integration is not working, the webhook requests report a "connection timed out" and "X-Squid-Error ERR_CONNECT_FAIL 110". In our firewall we see incoming connection attempts correlating in time with the failed webhook delivery from these four IPs: 104.140.188.6, 89.248.165.201, 89.246.165.104 and 39.184.152.161. We can't easily tell if they are webhook deliveries as the intital connection attempts are dropped.
As far as I can tell, these adresses aren't covered by the more extensive list at https://ip-ranges.atlassian.com/ either.
What are we missing here?
Hi @Mattias.Sjostrom
Welcome to the community.I checked those 4 IPs you've got, however, I couldn't find it on this list as well.
For this, may I kindly ask if you feel comfortable sharing your masked repository URL here where you've added the webhook for me to further check?You can mask it to something these:
https://bitbucket.org/w*******e/n**e
You can provide the first and last character of your workspace and repository name.
Otherwise, I can create a support request for you.
Thanks and looking forward to your response.
Regards,Mark C
Hi Mark,
That would work out to something like https//bitbucket.org/d******m/h****t
Thanks,
-Mattias
Thank you for providing your masked repository URL.I've checked your repository with our developers and we noticed the below error message in our internal logs:
unable to find valid certification path to requested target
For this, I'm suspecting that this is about the Webhook URL where it doesn't have a valid SSL certificate.I'm afraid we don't allow an HTTPS Webhook URL with a self-signed certificate to be used on Bitbucket Cloud.You can check out this documentation for some options.Let me know if you have further questions that I can help with.
Thank you for assisting with this. We are however not using a self-signed certificate. Our webhook URL is served with a DigiCert issued certificate for a wildcard pattern under our domain.
I can only assume this is due to our server not presenting a complete certificate chain. I'll try to adjust the configuration to rectify this.
It looks like you're new here. Sign in or register to get started.