We currently have two Bamboo instances in our company. One is used for all pre-prod (dev/test/stage) builds and deployments, the other is used strictly for production builds and deployments. The two Bamboo instances have different user access levels (developers in one instance, operations in the other instance), reside on different servers in different domains on the network, run under different user accounts on the server, and have different sets of build agents (local and remote).
I am evaluating the feasibility of moving everything to one Bamboo instance. Having them split in two creates several problems, and, from what I can tell, does not provide many benefits (the person who decided to do it this way in the first place is no longer available for questioning). Here is what I've discovered so far:
Problems:
- Plan cloning cannot occur all the way up the stack. Any plan created in one instance has to be manually re-created in the other instance. This causes problems when initially setting up plans, but also when making changes to the pre-prod plans that then have to be mimicked in the prod plans. Even the tiniest, slightest change in the pre-prod builds can, if forgotten, destroy confidence in the integrity of the production build plan.
- If we use the new Deployment Projects feature, the dashboard is not as helpful because one environment only shows pre-prod deployments/status, and the other environment only shows production deployments/status. This defeats the purpose of the Deployment Projects, in our opinion.
- Any resources needed on the build server to support a software build (Visual Studio, Java, additional libraries, etc.) have to be present and maintained on both build servers.
- We only have one instance integrating with JIRA, and not sure if we should/can integrate the other instance with JIRA (does the one-to-many connection cause problems, etc.).
- We have to pay for licenses/maintenance/support on two instances instead of just one.
Benefits:
- Security. Because the production builds all occur on a separate server in different domain under a different user account, we are able to harden that environment much more thoroughly and protect it from unwanted (or unauthorized) changes.
I have the resources available to me to make the build server very robust and powerful, so performance considerations are not a concern. I'm just trying to gather any other ideas as to why I might need to keep these instances separate. If it's just a security concern, I think I can convince management to combine them. Between utilizing the granular permissions capabilities and user training, I think we could avoid most security problems that they're worried about (and besides, if there are rogue deployments to Prod occurring, that's not something that should be fixed by technology, that's something that should be fixed by management).
All thoughts/questions/feedback/ideas are welcome. I anticipate your responses.