I would like to restrict who can add git-tags to the bitbucket cloud repository, so that only certain users can start tag triggered pipelines. Ideally, I would like to set a permission so that only a specified list of users can tag with specific formats, only annotated tags are allowed, any other tag attempts are rejected.
I've looked at branch pattern permissions for `refs/tags/**` and server-side hooks, neither of which seem to be supported by Bitbucket Cloud.
E.g.
General user can add annotated tag `hello-world`.
General user can not add lightweight tag `hello-world`, tag is rejected.
General user can not add annotated tag `pipeline-trigger-<number>`, tag is rejected.
Admin user can add annotated tag `pipeline-trigger-<number>` which triggers a specific pipeline.
Admin user can add annotated tag `hello-world`.
Admin user can not add lightweight tag `hello-world`, tag is rejected.