We are trying to add a tag from within our pipeline as noted here:
https://support.atlassian.com/bitbucket-cloud/docs/push-back-to-your-repository/
However, the challenge is that we require all commits to be signed. As far as I can tell, there is no valid signature in the default pipeline. My approach has been to import GPG keys via repository variables to be used for reconfiguring git.
Thus far I can't get the GPG keys to import successfully although this script runs elsewhere without issues. Any ideas as to how we can sign a commit / push a signed tag from within a pipeline? Example shell script below
#restore private
echo "$pub_key" > public.gpg
echo "$pri_key" > private.key
gpg --import public.gpg
gpg --import private.key
echo "Keys imported sucessfuly"
rm -rf public.gpg
rm -rf private.key
echo "Key files removed sucessfully"
git config --global user.signingkey $key_serial
git config --global commit.gpgsign true
git config --global tag.gpgSign true