I have a bitbucket-pipelines.yml file, with pipelines defined that trigger on either commits to the main branch or when a pull-request (PR) is created or updated. The pipelines are deploying terraform infrastructure as code using GitOps practices. The branching strategy is to have a main branch, which is our source of truth, from which developers take a branch which is then merged back into main via a PR.
The idea is that the PR needs to be reviewed by our infrastructure team before being merged but any developer is free to open branches, make code changes and create pull requests for review.
The PR pipeline runs linters, static analysis, validation and planning steps. The main branch pipeline applies (deploys) the resources.
The problem is that any developer who can open a PR can modify the PR triggered pipeline and effectively execute arbitrary code e.g. terraform apply or destroy commands. This is because the modified PR pipeline runs before it has been reviewed by a reviewer.
Can I prevent the PR pipeline running in this way? Ideally I only want it to use the bitbucket-pipelines.yml file from the main branch, the PR target, and not bypass the review process.
Thanks.