Are you in the loop? Keep up with the latest by making sure you're subscribed to Community Announcements. Just click Watch and select Articles.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Prisma Cloud (twistcli) container scanning from BitBucket Pipeline - is this possible?

We are migrating from Jenkins CI to BBC pipeline and are blocked by this. Prisma provide a tool (twistcli) which we install in our image, however it tries to run Docker using the --security-opt argument and this is blocked by BBC.

Since Prisma is a relatively common tool I'm hoping someone else has already got around this?

 

 

 

1 answer

0 votes
Mark C
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
Feb 22, 2023

Hi @patrick feerick,

Thank you for reaching out to the community.

The Docker command with the --security-opt is indeed not allowed when you run it on Pipelines cloud infrastructure. - Here's the full list of restricted commands

Alternatively, you can explore Bitbucket Cloud Pipelines runners which will allow you to have more control as it runs on your self-hosted machine.

Hope it helps and do let me know if you have further questions.

Regards,
Mark C

Thank @Mark C  I guess that is an option, although the need for server management does not at first glance make it look too attractive. AFAIK bbc-pipeline equivalents (on Azure, Github) seem to be supporting Prisma. You would have thought they were as similarly constrained vs Docker.

Paddy

anubhav_sharma
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
Sep 26, 2023

Hi @patrick feerick I am also trying to implement twistcli in CI pipeline.

Could you please help me how you have enabled it?

Hi Anubhav,

We gave up on attempting to run twistcli in BBC because of the above restrictions. I haven't attempted since then but doubt those restrictions have gone away.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Site Admin
TAGS
AUG Leaders

Atlassian Community Events