Bitbucket Pipelines recently announced a new feature of 4x and 8x step sizes and the migration of 1x and 2x step size machines to a new runtime[1]. I like this feature very much, though the dynamic IP ranges that need to be allow-listed are a little downer.
The documentation states that if you are using IP allow listing for your corporate firewall, need to allow > 4000 IP address ranges of AWS. Certain firewalls, e.g. AWS security could not store this amount of IP addresses easily (60 rules are the maximum here). So as one option you would need to create a security group, with 60 sub security groups and keep them up to date. I suspect this is also not possible on certain hardware appliances.
According to the documentation there is another option for the sizes 4x and 8x. You can us the "atlassian-ip-ranges" option to ensure, that request are coming from a limited pool of IP addresses.
From the documentation it is not clear, if this will be also rolled out to 1x and 2x size steps after those steps are migrated of the 1x and 2x sizes to the new run time after 17th of September or if this is exclusive for 4x and 8x steps.
1) Could you clarify on that? Will the atlassian-ip-ranges opt-in option be also available for 1x and 2x step sizes after the migration on?
2) Does the use of atlassian-ip-ranges have limitations in comparison to not using it?
Thank you very much for your time and this new feature.
[1] - https://bitbucket.org/blog/announcing-our-new-ci-cd-runtime-with-up-to-8x-faster-builds
[2] - https://support.atlassian.com/bitbucket-cloud/docs/what-are-the-bitbucket-cloud-ip-addresses-i-should-use-to-configure-my-corporate-firewall/