We are using Bitbucket Cloud with Pipelines. I am trying to implement a controlled access to the git repo from the Pipelines process. As such we have created a 'bot' user which has git repo write permissions across multiple branches. Following the guidance in serveral questions/articles such as:
.. I have created an ssh key for the repo and provided the public key to the bot user. When running the pipeline everything works as expected, which is great, however I do not understand how the pipeline script actually associates the bot user with the BITBUCKET_GIT_SSH_ORIGIN variable.
The relevant excerpt from my bitbucket-pipelines.yml looks like this:
custom:
release-and-publish:
- step:
name: Build and test
caches:
- gradle
script:
- bash ./gradlew clean build
- step:
name: Git merge to master
script:
- git config remote.origin.fetch "+refs/heads/*:refs/remotes/origin/*"
- git fetch
- git checkout master
- git merge ${BITBUCKET_BRANCH}
- git remote set-url origin ${BITBUCKET_GIT_SSH_ORIGIN}
- git push
.. which results in the bot account 'BB' successfully performing the tasks.

My question is, how is the bot account associated with the ssh origin variable BITBUCKET_GIT_SSH_ORIGIN? The bot user account is the only account with write permission within the repo with access to the repo public key. My hypothesis is that the pipeline tries to look up repo write users with the appropriate public key.
If that is the case, a further question would then be, what would happen if I provided the repo public key to another user with repo write access, how would the pipeline then determine who is the resultant account which performs the git actions?