Questa pagina descrive i webhook di Secure Source Manager. Per configurare un webhook, segui le istruzioni riportate in Configurare i webhook.
I webhook sono richieste HTTP attivate da un evento in un repository Secure Source Manager e poi inviate a un URL specificato dall'utente.
Impostazioni webhook
I webhook possono essere configurati solo nell'interfaccia web di Secure Source Manager. I seguenti campi sono configurabili:
- ID hook
- Nome leggibile per il webhook. Gli ID hook devono rispettare la convenzione di denominazione delle risorse. Devono includere solo lettere minuscole, numeri o trattini, devono iniziare con una lettera e non possono essere modificati dopo la creazione del webhook.
- URL target
- URL di destinazione del webhook. Una destinazione webhook è un URL aperto e pubblico.
- Stringa di query sensibile
Le stringhe di query sensibili vengono aggiunte alla fine dell'URL di destinazione nel seguente modo:
TARGET_URL?SENSITIVE_QUERY_STRING.La maggior parte dei servizi fornisce un token o un segreto per garantire che le richieste in entrata provengano da un servizio autorizzato. Per verificare la richiesta, puoi archiviare il token o il secret richiesto nella stringa di query sensibile.
Le stringhe di query sensibili sono statiche, di lunga durata e devono essere create, ruotate e convalidate manualmente. Utilizza stringhe di query sensibili per il targeting di strumenti che prevedono un segreto condiviso, una chiave API o un token nei parametri di query dell'URL. Puoi anche utilizzare stringhe di query sensibili nei casi in cui la destinazione webhook non supporta l'autenticazione basata su token di intestazione
auth.- Abilitare l'autenticazione del account di servizio
Seleziona questa opzione per autenticare il webhook utilizzando un account di servizio. Quando l'autorizzazione del account di servizio è abilitata, Secure Source Manager crea un token ID OpenID Connect (OIDC) firmato da Google per ilaccount di servizioce account del repository e lo invia come token di autenticazione nella richiesta webhook.
L'autorizzazione del service account è di breve durata e non richiede la gestione manuale dei token. Ti consigliamo di utilizzare l'autorizzazione dell'account di servizio quando i tuoi webhook hanno come target servizi o endpoint che convalidano i token ID OIDC di Google utilizzando IAM anziché segreti condivisi. Esempi di questi servizi includono servizi Cloud Run privati o funzioni Cloud Run Functions.
- Trigger attivato
Evento per attivare la richiesta webhook. Le opzioni sono Push (attivato da un push al repository), Stato della richiesta di pull modificato (attivato quando una richiesta di pull viene aperta, chiusa, riaperta o modificata) e Commento alla richiesta di pull (attivato quando un commento viene aggiunto, modificato o eliminato in una richiesta di pull).
- Filtro dei riferimenti Git per gli eventi push
Un filtro per specificare le filiali da includere nei report per gli eventi push specificati come pattern glob. Per la sintassi, consulta la documentazione relativa al glob.
- Attivo
Se selezionato, il webhook invia richieste in caso di eventi di attivazione. Se non è selezionata, non vengono inviate richieste.
Testare i webhook
Dopo aver configurato il webhook, puoi testarlo utilizzando il pulsante Test di consegna nella scheda dei webhook.
Esempi di informazioni sull'evento
I seguenti esempi mostrano le informazioni sugli eventi inviate da Secure Source Manager all'URL di destinazione per diversi eventi webhook.
Payload evento push
Il contenuto di un payload di eventi push è simile al seguente:
Intestazione
Request URL: https://example.com?{sensitive_query_string_placeholder}
Request method: POST
Content-Type: application/json
X-SecureSourceManager-Delivery: 6546af81-25c6-46d9-aa41-70c00dc67752
X-SecureSourceManager-Event: push
X-SecureSourceManager-Signature:
Corpo
{
"secret": "",
"ref": "refs/heads/main",
"before": "f22fe95d6097bc18ba2ace7c5808ef53c0211a2e",
"after": "85c7e78e6dfb63bcad4a0bb0953c0b3554ed0e93",
"compare_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo/compare/f22fe95d6097bc18ba2ace7c5808ef53c0211a2e...85c7e78e6dfb63bcad4a0bb0953c0b3554ed0e93",
"commits": [
{
"id": "85c7e78e6dfb63bcad4a0bb0953c0b3554ed0e93",
"message": "Push Event'\n",
"url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo/commit/85c7e78e6dfb63bcad4a0bb0953c0b3554ed0e93",
"author": {
"name": "user",
"email": "user@example.com",
"username": "user@example.com"
},
"committer": {
"name": "user",
"email": "user@example.com",
"username": "user@example.com"
},
"verification": null,
"timestamp": "2024-07-03T18:27:38Z",
"added": [],
"removed": [],
"modified": [
"README.md"
]
}
],
"head_commit": null,
"repository": {
"id": 4,
"owner": {"id":2,"login":"my-project","full_name":"","email":"email-address@example.com","avatar_url":"b2653dbf52c7e078e04b8b20020eaadeafe0337787cc0e19b976efc8d594aefb","language":"","is_admin":false,"last_login":"1970-01-01T00:00:00Z","created":"2023-06-02T14:18:40Z","restricted":false,"username":"my-project"},
"name": "my-repo",
"full_name": "my-project/my-repo",
"description": "",
"empty": false,
"private": false,
"fork": false,
"template": false,
"parent": null,
"mirror": false,
"size": 4,
"html_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"ssh_url": "git@my-instance-123456789-ssh.us-central1.sourcemanager.dev:my-project/my-repo.git",
"clone_url": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git",
"original_url": "",
"website": "",
"stars_count": 0,
"forks_count": 0,
"watchers_count": 1,
"open_issues_count": 0,
"open_pr_counter": 1,
"release_counter": 1,
"default_branch": "main",
"archived": false,
"created_at": "2023-06-06T20:34:36Z",
"updated_at": "2024-04-04T18:19:14Z",
"permissions": {
"admin": true,
"push": true,
"pull": true
},
"has_issues": true,
"internal_tracker": {
"enable_time_tracker": false,
"allow_only_contributors_to_track_time": true,
"enable_issue_dependencies": true
},
"has_wiki": true,
"has_pull_requests": true,
"has_projects": true,
"ignore_whitespace_conflicts": false,
"allow_merge_commits": true,
"allow_rebase": true,
"allow_rebase_explicit": true,
"allow_squash_merge": true,
"avatar_url": "",
"internal": false,
"mirror_interval": "",
"uris": {
"api": "https://my-instance-123456789-api.us-central1.sourcemanager.dev/v1/projects/my-project/locations/us-central1/repositories/my-repo",
"html": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"git_https": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git"
}
},
"pusher": {"id":4,"login":"user@example.com","full_name":"user","email":"user@example.com","avatar_url":"https://this-is-avatar.com","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T20:53:58Z","restricted":false,"username":"user@example.com"},
"sender": {"id":4,"login":"user@example.com","full_name":"user","email":"user@example.com","avatar_url":"https://this-is-avatar.com","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T20:53:58Z","restricted":false,"username":"user@example.com"}
}
Recupera il payload dell'evento
Il contenuto di un payload di evento pull è simile al seguente.
Intestazione
Request URL: https://example.com?{sensitive_query_string_placeholder}
Request method: POST
Content-Type: application/json
X-SecureSourceManager-Delivery: d7bb9273-17cf-431d-835c-b334c9702eee
X-SecureSourceManager-Event: pull_request
X-SecureSourceManager-Signature:
Corpo
{
"secret": "",
"action": "opened",
"number": 4,
"pull_request": {
"id": 18,
"url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo/pulls/4",
"number": 4,
"user": {"id":4,"login":"user@example.com","full_name":"user","email":"user@example.com","avatar_url":"https://page-address.com","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T20:53:58Z","restricted":false,"username":"user@example.com"},
"title": "Open a Pull Request'",
"body": "",
"labels": [],
"milestone": null,
"assignee": null,
"assignees": null,
"state": "open",
"is_locked": false,
"comments": 0,
"html_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/cloud-git-test-pso-instance/test2/pulls/4",
"diff_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo/pulls/4.diff",
"patch_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo/pulls/4.patch",
"mergeable": false,
"merged": false,
"merged_at": null,
"merge_commit_sha": null,
"merged_by": null,
"base": {
"label": "main",
"ref": "main",
"sha": "85c7e78e6dfb63bcad4a0bb0953c0b3554ed0e93",
"repo_id": 4,
"repo": {
"id": 4,
"owner": {"id":2,"login":"my-project","full_name":"","email":"email-address@example.com","avatar_url":"b2653dbf52c7e078e04b8b20020eaadeafe0337787cc0e19b976efc8d594aefb","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T14:18:40Z","restricted":false,"username":"my-project"},
"name": "my-repo",
"full_name": "my-project/my-repo",
"description": "",
"empty": false,
"private": false,
"fork": false,
"template": false,
"parent": null,
"mirror": false,
"size": 4,
"html_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"ssh_url": "git@my-instance-123456789-ssh.us-central1.sourcemanager.dev:my-project/my-repo.git",
"clone_url": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git",
"original_url": "",
"website": "",
"stars_count": 0,
"forks_count": 0,
"watchers_count": 1,
"open_issues_count": 0,
"open_pr_counter": 0,
"release_counter": 1,
"default_branch": "main",
"archived": false,
"created_at": "2023-06-06T20:34:36Z",
"updated_at": "2024-07-03T18:27:42Z",
"permissions": {
"admin": false,
"push": false,
"pull": false
},
"has_issues": true,
"internal_tracker": {
"enable_time_tracker": false,
"allow_only_contributors_to_track_time": true,
"enable_issue_dependencies": true
},
"has_wiki": true,
"has_pull_requests": true,
"has_projects": true,
"ignore_whitespace_conflicts": false,
"allow_merge_commits": true,
"allow_rebase": true,
"allow_rebase_explicit": true,
"allow_squash_merge": true,
"avatar_url": "",
"internal": false,
"mirror_interval": "",
"uris": {
"api": "https://my-instance-123456789-api.us-central1.sourcemanager.dev/v1/projects/my-project/locations/us-central1/repositories/my-repo",
"html": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"git_https": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git"
}
}
},
"head": {
"label": "dev",
"ref": "dev",
"sha": "06aa2c971d8e06e5271ce04248ef1920341ce208",
"repo_id": 4,
"repo": {
"id": 4,
"owner": {"id":2,"login":"my-project","full_name":"","email":"email-address@example.com","avatar_url":"b2653dbf52c7e078e04b8b20020eaadeafe0337787cc0e19b976efc8d594aefb","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T14:18:40Z","restricted":false,"username":"my-project"},
"name": "my-repo",
"full_name": "my-project/my-repo",
"description": "",
"empty": false,
"private": false,
"fork": false,
"template": false,
"parent": null,
"mirror": false,
"size": 4,
"html_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"ssh_url": "git@my-instance-123456789-ssh.us-central1.sourcemanager.dev:my-project/my-repo.git",
"clone_url": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git",
"original_url": "",
"website": "",
"stars_count": 0,
"forks_count": 0,
"watchers_count": 1,
"open_issues_count": 0,
"open_pr_counter": 0,
"release_counter": 1,
"default_branch": "main",
"archived": false,
"created_at": "2023-06-06T20:34:36Z",
"updated_at": "2024-07-03T18:27:42Z",
"permissions": {
"admin": false,
"push": false,
"pull": false
},
"has_issues": true,
"internal_tracker": {
"enable_time_tracker": false,
"allow_only_contributors_to_track_time": true,
"enable_issue_dependencies": true
},
"has_wiki": true,
"has_pull_requests": true,
"has_projects": true,
"ignore_whitespace_conflicts": false,
"allow_merge_commits": true,
"allow_rebase": true,
"allow_rebase_explicit": true,
"allow_squash_merge": true,
"avatar_url": "",
"internal": false,
"mirror_interval": "",
"uris": {
"api": "https://my-instance-123456789-api.us-central1.sourcemanager.dev/v1/projects/my-project/locations/us-central1/repositories/my-repo",
"html": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"git_https": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git"
}
}
},
"merge_base": "af065efa8d3d7549154c560da5cb3ec236ad3002",
"due_date": null,
"created_at": "2024-07-03T18:40:21Z",
"updated_at": "2024-07-03T18:40:21Z",
"closed_at": null
},
"repository": {
"id": 4,
"owner": {"id":2,"login":"my-project","full_name":"","email":"email-address@example.com","avatar_url":"b2653dbf52c7e078e04b8b20020eaadeafe0337787cc0e19b976efc8d594aefb","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T14:18:40Z","restricted":false,"username":"my-project"},
"name": "my-repo",
"full_name": "my-project/my-repo",
"description": "",
"empty": false,
"private": false,
"fork": false,
"template": false,
"parent": null,
"mirror": false,
"size": 4,
"html_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"ssh_url": "git@my-instance-123456789-ssh.us-central1.sourcemanager.dev:my-project/my-repo.git",
"clone_url": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git",
"original_url": "",
"website": "",
"stars_count": 0,
"forks_count": 0,
"watchers_count": 1,
"open_issues_count": 0,
"open_pr_counter": 1,
"release_counter": 1,
"default_branch": "main",
"archived": false,
"created_at": "2023-06-06T20:34:36Z",
"updated_at": "2024-07-03T18:27:42Z",
"permissions": {
"admin": false,
"push": false,
"pull": true
},
"has_issues": true,
"internal_tracker": {
"enable_time_tracker": false,
"allow_only_contributors_to_track_time": true,
"enable_issue_dependencies": true
},
"has_wiki": true,
"has_pull_requests": true,
"has_projects": true,
"ignore_whitespace_conflicts": false,
"allow_merge_commits": true,
"allow_rebase": true,
"allow_rebase_explicit": true,
"allow_squash_merge": true,
"avatar_url": "",
"internal": false,
"mirror_interval": "",
"uris": {
"api": "https://my-instance-123456789-api.us-central1.sourcemanager.dev/v1/projects/my-project/locations/us-central1/repositories/my-repo",
"html": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"git_https": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git"
}
},
"sender": {"id":4,"login":"user@example.com","full_name":"user","email":"user@example.com","avatar_url":"https://this-is-avatar.com","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T20:53:58Z","restricted":false,"username":"user@example.com"},
"review": null
}
Payload evento di commento alla richiesta di pull
I contenuti di un payload dell'evento di commento della richiesta di pull sono simili ai seguenti:
Intestazione
Request URL: https://example.com?{sensitive_query_string_placeholder}
Request method: POST
Content-Type: application/json
X-SecureSourceManager-Delivery: d7bb9273-17cf-431d-835c-b334c9702eee
X-SecureSourceManager-Event: pull_request_comment
X-SecureSourceManager-Signature:
Corpo
{
"secret": "",
"action": "created",
"issue": {
"id": 18,
"url": "https://my-instance-123456789-api.us-central1.sourcemanager.dev/v1/projects/my-project/locations/us-central1/repositories/my-repo/issues/4",
"html_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo/pulls/4",
"number": 4,
"user": {"id":4,"login":"user@example.com","full_name":"user","email":"user@example.com","avatar_url":"https://page-address.com","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T20:53:58Z","restricted":false,"username":"user@example.com"},
"original_author": "",
"original_author_id": 0,
"title": "Open a Pull Request'",
"body": "This is the description of the pull request.",
"ref": "",
"labels": [],
"milestone": null,
"assignee": null,
"assignees": null,
"state": "open",
"is_locked": false,
"comments": 1,
"created_at": "2024-07-03T18:40:21Z",
"updated_at": "2024-07-03T18:40:21Z",
"closed_at": null,
"due_date": null,
"pull_request": {
"merged": false,
"merged_at": null
},
"repository": {
"id": 4,
"name": "my-repo",
"owner": "my-project",
"full_name": "my-project/my-repo"
},
"etag": "PSIsycnIx2xBaS1CtNRhB0qY-NCtxuHIeYlo8H12E1Q"
},
"comment": {
"id": 1,
"html_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo/pulls/4#issuecomment-1",
"pull_request_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo/pulls/4",
"issue_url": "",
"user": {"id":4,"login":"user@example.com","full_name":"user","email":"user@example.com","avatar_url":"https://page-address.com","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T20:53:58Z","restricted":false,"username":"user@example.com"},
"original_author": "",
"original_author_id": 0,
"body": "this is a comment",
"created_at": "2024-07-03T18:40:21Z",
"updated_at": "2024-07-03T18:40:21Z"
},
"repository": {
"id": 4,
"owner": {"id":2,"login":"my-project","full_name":"","email":"email-address@example.com","avatar_url":"b2653dbf52c7e078e04b8b20020eaadeafe0337787cc0e19b976efc8d594aefb","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T14:18:40Z","restricted":false,"username":"my-project"},
"name": "my-repo",
"full_name": "my-project/my-repo",
"description": "",
"empty": false,
"private": false,
"fork": false,
"template": false,
"parent": null,
"mirror": false,
"size": 4,
"html_url": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"ssh_url": "git@my-instance-123456789-ssh.us-central1.sourcemanager.dev:my-project/my-repo.git",
"clone_url": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git",
"original_url": "",
"website": "",
"stars_count": 0,
"forks_count": 0,
"watchers_count": 1,
"open_issues_count": 0,
"open_pr_counter": 1,
"release_counter": 1,
"default_branch": "main",
"archived": false,
"created_at": "2023-06-06T20:34:36Z",
"updated_at": "2024-07-03T18:27:42Z",
"permissions": {
"admin": false,
"push": false,
"pull": true
},
"has_issues": true,
"internal_tracker": {
"enable_time_tracker": false,
"allow_only_contributors_to_track_time": true,
"enable_issue_dependencies": true
},
"has_wiki": true,
"has_pull_requests": true,
"has_projects": true,
"ignore_whitespace_conflicts": false,
"allow_merge_commits": true,
"allow_rebase": true,
"allow_rebase_explicit": true,
"allow_squash_merge": true,
"avatar_url": "",
"internal": false,
"mirror_interval": "",
"uris": {
"api": "https://my-instance-123456789-api.us-central1.sourcemanager.dev/v1/projects/my-project/locations/us-central1/repositories/my-repo",
"html": "https://my-instance-123456789.us-central1.sourcemanager.dev/my-project/my-repo",
"git_https": "https://my-instance-123456789-git.us-central1.sourcemanager.dev/my-project/my-repo.git"
}
},
"sender": {"id":4,"login":"user@example.com","full_name":"user","email":"user@example.com","avatar_url":"https://this-is-avatar.com","language":"","is_admin":false,"last_login":"0001-01-01T00:00:00Z","created":"2023-06-02T20:53:58Z","restricted":false,"username":"user@example.com"},
"is_pull": true
}
Passaggi successivi
- Utilizza i webhook per connetterti a Jenkins.
- Configura i webhook.