Bitbucket Pipelines has experienced significant growth recently. In response, Atlassian is enhancing its cloud infrastructure to maintain high performance and reliability. A key part of this enhancement is an update to the network edge for Bitbucket Pipelines, including the introduction of new IP addresses that Pipeline traffic can originate from. This blog post explains why these new IP addresses were introduced, what it means for your team, and the steps you should take to stay secure and connected.
Bitbucket Pipelines Growth and Network Enhancements
As more developers and teams adopt Bitbucket Pipelines for continuous integration and deployment, Atlassian continues to scale its backend systems. Why the change? In short, Atlassian is expanding its network edge to handle increased usage and provide faster, more reliable service worldwide. This expansion often involves adding new points of presence to improve connectivity for users in different geographies. With these additions come new IP addresses that Bitbucket Pipelines uses. By rolling out additional IP addresses, Atlassian can distribute traffic load more effectively and reduce latency for a better user experience. In essence, the growth of Bitbucket Pipelines usage has driven Atlassian to broaden its infrastructure, and updating the IP address pool is a natural result of that growth.

Key Facts About the New IP Addresses
-
Atlassian has added new outgoing IP addresses for Bitbucket Pipelines as part of its infrastructure upgrade. These addresses will be used when pipeline build containers communicate with external services.
-
No downtime or user action is required for most customers. Bitbucket Pipelines will automatically start using the new IPs in the background. Your DNS and Atlassian’s systems seamlessly handle the change, so pipeline builds continue as usual for the majority of teams.
-
Who is affected? Primarily teams and organizations that restrict network traffic based on IP addresses. If your company’s security policies or firewall rules only allow known IP ranges to access certain resources, you will be impacted by this change.
-
The new IP addresses are fully owned and managed by Atlassian. This means they are just as secure and trustworthy as the previous addresses. They’ve been introduced to support additional capacity and global reach, aligning with Atlassian’s commitment to performance and reliability.
-
Atlassian provides an up-to-date list of all Bitbucket Pipelines IP ranges. You can find the updated IP address allowlist on Atlassian’s support page, which reflects the newly added addresses. It’s a good idea to bookmark that page for any future changes.
Minimal Impact for Most Teams
The good news is that these IP address updates should have minimal or no impact on many teams. If your workflows and tools do not enforce strict outbound or inbound network rules, Bitbucket Pipelines will continue to work as it always has without any intervention. Your builds, deployments, and integrations won’t notice a thing; Atlassian’s upgrade is designed to be transparent. This change does not affect how you use Pipelines on a daily basis, and it doesn’t alter any Bitbucket Pipelines features or user interfaces. In fact, Atlassian timed these enhancements to avoid disruption, and they did not announce any downtime.
However, for organizations with stricter network security, ignoring this update could lead to pipeline connectivity issues. For example, if you maintain a firewall that only allows traffic to specific IPs, a Bitbucket Pipeline build might fail to download dependencies or reach an external service if it’s coming from a new IP your firewall doesn’t recognize. Similarly, if you have web services that only accept incoming requests from Atlassian’s known IP ranges, those services might block pipeline traffic originating from the new addresses. In short, while Atlassian’s infrastructure change is behind-the-scenes, you should evaluate if your team needs to adjust any settings to accommodate it.

Action Required: Update Your Firewall Policies
If your team uses firewalls, security groups, or any outbound access rules tied to IP addresses, you will need to take action to ensure Bitbucket Pipelines continues to work smoothly. Here are the steps to follow:
-
Identify restricted connections: First, determine if your organization has any firewalls or network policies that restrict outbound internet access or inbound service access based on IP addresses. This could include cloud security groups, on-premises firewalls, or VPN rules that only allow specific IP ranges.
-
Obtain Atlassian’s updated IP list: Visit Atlassian’s official documentation for allowed IP addresses (the page listing “IP addresses and domains to allowlist in your corporate firewall”). Retrieve the latest list of Bitbucket Pipelines IP ranges, which now includes the new addresses introduced in this update.
-
Update your allowlist: Modify your firewall or security group settings to include the new IP addresses from Atlassian’s list. Ensure that any service expected to communicate with Bitbucket Pipelines is configured to trust connections from these new addresses. It’s often best to update by adding the new ranges rather than replacing the old ones, since Atlassian added addresses without immediately removing all old ones (unless they explicitly deprecated some older IPs in prior announcements).
-
Verify pipeline connectivity: After updating your network rules, run a few Bitbucket Pipeline builds that interact with your protected resources. Confirm that they succeed and that no connections are being blocked. If you encounter any issues, double-check that all relevant new IP ranges were included correctly and that the rules were deployed to all necessary environments.
-
Stay informed: Going forward, keep an eye on Atlassian’s announcements or Atlas Bench’s updates for any further changes. Atlassian occasionally updates its cloud infrastructure. Proactively adjusting your configurations whenever these changes occur will save you from last-minute scrambles if a pipeline suddenly can’t reach a resource.
By following the above steps, teams with strict network settings can adapt to Atlassian’s changes quickly and ensure their CI/CD pipelines continue to run without interruption. It’s always a good practice to review such security rules periodically to accommodate evolving cloud infrastructure.