We have a repository which hosts the code for our documentation server. Whenever one of our projects is updated, we run a pipeline to generate the documentation based on the latest code, push it to the documentation repository, and deploy it to the server from there.
The solution we are currently using relies on git to pull and push code from one repository to another. However, this requires SSH authentication, which in turn requires some hacky abuse of user SSH:
- Take the SSH key of the pushing repository
- Add it to a user
- Make sure that user has read/write permissions for the repository you want to push to
We would like to do this in a way that does not require a specific user, but the alternatives I can think of have their own downsides:
1. Push with git, but handle SSH authentication 'by hand'
Store the SSH keys in workspace variables and copy them to the required places during the pipeline.
Cons:
- Finicky to set up
- Pipeline might break if the build image is changed, e.g. files in unexpected locations etc.
2. Use the Bitbucket REST API to move the files
Set up an API token in a workspace variable and use a script to loop over files you want to push/pull
Cons:
- Files cannot be pulled at all - only their content
- Files must be added individually to the API request (might be 1000s of files)
- Difficult to determine what files have changed
Overall, it seems silly to use the API for handling tasks that git does so well. But there does not seem to be a good mechanism to authenticate between Bitbucket repositories.
What is the recommended way to move code between repositories?
Thanks,
Chris