Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

How can I prevent bitbucket-pipelines.yml to be modified by developers?

Hello,

We have set up our bitbucket-pipelines.yml file, pushed to the repo and it's working. We have read a lot about this configuration but we don't find anything about preventing developers, or just allowing some of them, to modify this file.

This is very important for us, because one developer with access to the repo can wilfully make the server crash if he modifies the source code and modify the pipelines so that Bitbucket does not run the tests and create the build properly.

I think there should exist something but we don't find it.

 

Many thanks in advance,

Victor.

2 answers

There's currently a feature request for this: BCLOUD-19457.

You can vote for it.

^ Everyone please vote for this -- this is a massive oversight that needs to be fixed

Hi @Victor Acin

 

I am afraid this isn't possible. However to prevent someone from modifying the bitbucket-pipelines.yml file, you can use Branch Permissions, assuming your build/deployment runs from master branch.

 

This will prevent anyone working on the repository to merge anything without approval.

I just want to add that with this approach you would need a Premium Membership to be able to restrict access to certain Deployments (and its variables) ton only selected branches.

But that won't prevent anyone from being able to use those variables in a malicious script in the yaml file, unless the repo admin keeps an eye on what is being modified and merged... which is the opposite of automating 🤦🏻‍♂️

I guess we need to start a feature request.

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Confluence

New page sharing experience, coming soon to Confluence Cloud

...eans the lock icon is going away, you’ll find all of the lock icon’s functionality in the new Share button.  More visibility into a page’s true access No more uncertainty around w...

31 views 0 4
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you