Hi Atlassian Support,
I’m reaching out to understand whether there is a supported way to use Docker images hosted in Bitbucket Packages as base images within Bitbucket Pipelines without relying on personal API tokens.
Current situation:
- Bitbucket Packages provides native authentication for pushing Docker images, which works well.
- However, this native authentication does not appear to support pulling images within Bitbucket Pipelines.
- As a result, to use a Bitbucket-hosted image as a base image in a pipeline, we must use a personal API token.
Problem:
- Personal API tokens have an expiry, which introduces instability into our CI pipelines when tokens expire.
- Managing token rotation across a large number of repositories (hundreds) creates significant operational overhead and maintenance burden.
- This also introduces avoidable risk of unexpected pipeline failures.
What we’re looking for:
- Is there a way to use Bitbucket Packages Docker images in Pipelines using native authentication (similar to push), workspace-level credentials, or service accounts?
- Alternatively, are there recommended best practices to avoid using expiring personal API tokens for this use case?
If this is not currently supported, we would appreciate any guidance on:
- Roadmap plans for improving authentication between Bitbucket Pipelines and Bitbucket Packages
- Suggested architectural workarounds (e.g., workspace tokens, OIDC, or other mechanisms)
This capability would significantly improve reliability and reduce maintenance effort for teams managing multiple repositories.
Thanks in advance for your help.
Kind regards