Hi!
We are running a suite of Playwright tests from a Bitbucket pipeline, and for our test environments use IP whitelisting to block unauthorised access. Thus we have implemented the provided list of static Bitbucket IPs which are listed in the documentation here: https://support.atlassian.com/bitbucket-cloud/docs/what-are-the-bitbucket-cloud-ip-addresses-i-should-use-to-configure-my-corporate-firewall/
Yet we still saw the pipeline was timing out all its requests to our environment, so upon investigation we were able to see the public IPs from some of the steps were:
- 44.203.28.179
- 35.173.195.91
- 44.201.215.133
- etc.
Which, if I read the documentation correctly are all IPs which are not listed as expected IP addresses for pipelines, thus they are not whitelisted on our load balancer.
Some extra info for debugging this:
- We are using the base machine type for our pipelines (so 1x)
- We also checked the more extensive IP range list here https://ip-ranges.amazonaws.com/ip-ranges.json
- For internal debugging at Atlassian, the ID of one of our steps that logged one of these IPs is db69e636-5044-460b-9730-ab7ef9fc154a
The current workaround was to put an allow all in place on our load balancer which is OK for a short while, but in the long run we need this security measure back in place.
Thanks in advance for (sanity) checking this!
UPDATE:
Turns out I was too quick and in the list provided at https://ip-ranges.amazonaws.com/ip-ranges.json I was able to find the matching CIDRs. Yet then another problem arises: there are 8086 IPv4 ranges provided in this document and we would ideally limit the amount of IPs to whitelist. Is there a way to either:
- Set an IP affinity for a specific pipeline? This so we can limit the amount of ranges we can expect traffic to come from
- Set a regional affinity for the pipelines so we both limit the ranges to whitelist AND have the tests run closer to our actual environment.