TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Bitbucket

Estimated reading: 3 minutes 2784 views

Set up Bitbucket for automated tests with TrustCloud

Purpose

Once you set up your compliance program, TrustCloud TrustOps works to ensure that your systems remain compliant with your adopted controls. To do so, TrustCloud runs automated tests and retrieves lists of resources against systems in your product and business stack to use for compliance evidence.

TrustCloud will retrieve this information via the Bitbucket REST API and will need an API token created by an admin user in order to authenticate and fetch this data.

Instructions to grant TrustCloud read-only access to your Bitbucket organization

  1. Log in to Bitbucket
    1. Log in to Bitbucket as a user with administrative privileges in your Bitbucket organization.
  2. Navigate to Settings
    1. From your profile avatar in the bottom left, click on your organization workspace name. Instructions to grant Kintent read only access to your Bitbucket organization
  3. Alternatively, you can click All workspaces to open an entire list from which to choose. workspaces
  4. On the opened workspace page, click “Settings” on the left sidebar to open the workspace settings. settings
  5. Obtain Workspace ID
    1. On the workspace settings page, copy and save your organization’s Workspace ID for later use. workspace ID
  6. Generate OAuth Consumer
    1. On the workspace settings page, click OAuth consumers under Apps and features on the left navigation sidebar.
      workspace settings
  7. On the OAuth consumers page, click the Add consumer button and enter the following:
    1. Name: the display name for your consumer. This must be unique within your account. This is required. Ex. TrustCloud
    2. Description: An optional description of what your consumer does.
    3. Callback URL: Set this to http://localhost/callback for the client_credentials OAuth grant type.
    4. This is a private consumer: select this checkbox. Enables the client_credentials grant type.
    5. Permissions: In the Pipelines group, enable Read; in the Runners group, enable Read, in addition to the existing read permissions Account: Read; Workspace membership: Read, Projects: Read, and the write permission Repository: Admin.
      bitbucket-6
      Note:
      The Repository: Admin permission is required for read access to branch restriction settings via the /branch-restrictions endpoint, as these are administrative repository settings. TrustCloud uses this permission only for reading branch restriction information and does not modify your repository settings or branch restrictions. The Pipelines:Read permission is required to fetch pipeline executions, pipeline configuration, and repository-level pipeline variables. The Runners:Read permission is required to list configured pipeline runners. The other permissions (Account: Read, Workspace membership: Read, Projects: Read) allow TrustCloud limited read-only access to fetch information about your repositories and Bitbucket configuration.
  8. Click the Save button. The system generates a key and a secret for you.
  9. Obtain OAuth Consumer Key and Secret
    On the OAuth consumers page, toggle the created consumer name to see the generated key and secret value for your consumer. Copy and save the key and secret values for later use. OAuth consumers
  10. Enter your Workspace ID
  11. Enter your OAuth Consumer Key
  12. Enter your OAuth Consumer Secret

Data feeds

Types of control testing that TrustCloud enables with BitBucket:

  1. Audit Logging
  2. Logging of Administrative Actions
  3. Role-based Access
  4. Multi-factor Authentication

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from BitBucket

  1. Repositories

TrustCloud uses the following sample endpoints, which pull the corresponding data into the Hybrid Data Fabric. This will provide read-only access to the following:

Read:repositories
   - ID
   - Name
   - Description
   - URL
   - Branch Restrictions

Join the conversation

You might also be interested in

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Google Cloud Platform

This document outlines the steps you can take to grant TrustCloud access to only...

Hybrid Data Fabric

The Hybrid Data Fabric is a built-in connector between your TrustCloud and an external...

Okta

Set up Okta for automated tests with TrustCloud! This document outlines the steps you...

ServiceNow

Set up ServiceNow for Ticket as Evidence with TrustCloud! This document outlines the steps...

Tenable.io

This document outlines the steps you can take to grant TrustCloud access to only...

Jira Cloud

Set up Jira Cloud for Jira Ticket as Evidence with TrustCloud! This document outlines...

AWS

This document outlines the steps you can take to grant TrustCloud access to only...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue