Skip to main content

Enhance Public Worker Capabilities for IP-Restricted VCS Access

Prospect requests an enhancement to Spacelift's Public Worker capabilities to enable seamless access to IP-whitelisted Source Code Management systems like Bitbucket Cloud. The desired outcome is for a Public Worker to be able to successfully clone/fetch code from a VCS repository that requires IP whitelisting.

The most viable technical approach would be to allow users to configure how the code checkout step is performed, specifically enabling it to go through a designated proxy server.This could potentially be facilitated by:

  • Enhancements around the Preparing phase: Allowing secure injection of environment variables or providing dedicated hook points specifically designed for network/proxy configuration before the Git clone operation occurs.

  • A dedicated setting within the VCS integration configuration in Spacelift for specifying proxy details and securely managing credentials for repositories requiring proxied access.

Workaround
Problem
Status: ❌ Rejected1 comment

Log in to comment and vote

Comments1

  • Black Breeze

    •

    May 8, 2025

    This is a request we’ve seen before, especially with Bitbucket Cloud’s IP allowlisting. Our public workers are intentionally shared and ephemeral, which means we can’t offer predictable IPs or fixed network egress. That model is great for ease and scale, but it doesn’t align with strict IP-based security.

    Proxying the clone step might sound like a workaround, but since public workers are shared, routing through a user-defined proxy doesn’t create real isolation—and could introduce misleading expectations around security.

    When outbound network control is required, private workers are the right tool. They provide dedicated execution, predictable egress, and full control. We know they come with a higher cost, but that reflects the security and flexibility they unlock. Happy to talk through ways to scope their use if cost is a concern.