My bamboo server is wrapped up inside our internal network. I could expose it, but before I do so are webhooks required for bamboo-specs to work? Is there some way that the conventional polling method bamboo usually uses could not be employed?
Apart from Bitbucket Server, the other repository types Bitbucket Cloud, Git, Github and Subversion need webhooks for bamboo specs to work.
Bamboo 6.5 Release Notes
Setting up webhooks
See also https://jira.atlassian.com/browse/BAM-19837
One of the blockers we're facing is that even with exposing our Bamboo server to external network and obviously securing it properly, webhooks still don't work because they require that Anonymous access is enabled on the Bamboo server - which we have obviously disabled for security reasons.
See https://jira.atlassian.com/browse/BAM-19874
Do you know if anonymous users need access to the plan itself, or just enabled globally (and then ensure every plan and project excludes them)?
You do not need a permission to trigger a scan. All you need to do is to use the appropriate REST API to trigger specs scanning.
For Eg: You can use a curl URL like below to trigger a scan as the destination for the webhook so that Bamboo knows about new commits:
curl -X POST -H "Content-Type: application/json" http://BambooHostURL:8085/rest/api/latest/repository/scan?repositoryId=123456
Hope that clarifies.
... but that obviously only works if Anonymous access is enabled. If it's disabled then you will get an error:
curl : The remote server returned an error: (401) Unauthorized.
It looks like you're new here. Sign in or register to get started.