Integrations
Connect CI/CD providers and the tools Prodgator works with, from Organization > Integrations.
Org admins connect providers and tools under Organization > Integrations. Connected CI/CD providers send runs and deployments; tools receive notifications and issues.
CI/CD providers
GitHub
Install the Prodgator GitHub App on an organization or account.
GitLab
Connect a GitLab group.
Bitbucket
Connect a Bitbucket workspace.
Azure DevOps
Connect an Azure DevOps organization.
Jenkins (beta)
Send build events from a Jenkins server.
AWS CodePipeline and CodeBuild
Bring in AWS pipelines with an EventBridge rule.
Other CI
CircleCI, Buildkite, Jenkins and other CI systems have no connection to install. A pipeline reports to Prodgator with the command line and signs in with an API key or an OIDC token. Org admins set up the OIDC side in the Other CI card of Organization > Integrations. Everything these pipelines send is self-reported; see Any CI.
Trust an OIDC issuer
In the Other CI card, choose Add OIDC trust. Start from a preset (CircleCI, Buildkite, Jenkins with the OIDC provider plugin, or self-managed GitLab) and replace the parts in angle brackets with your own values. A preset maps only the claims that match what sends from that CI system; see Any CI.
- Issuer: the https URL in the claim of your CI system's tokens.
- Audience: , filled in by the presets. Pipelines ask for this audience when they mint a token. An issuer and audience pair can belong to only one organization, and an audience on a Prodgator host must name your own organization id.
- Bound claims: at least one claim a token must carry, with an exact value or a pattern, such as for Buildkite. A token must match every row. This is what keeps another customer of a shared issuer out. On a shared issuer (Buildkite, gitlab.com, GitHub Actions, Google, HCP Terraform) one claim that names your tenant must have an exact value; see Other CI.
- Claim map: optional. Which claim gives the repository, branch, commit, run id, attempt and actor.
- Longest token age: 3600 seconds by default, at most 86,400.
- Signing keys: optional. Only for an issuer Prodgator cannot reach, such as a Jenkins server on a private network.
Use Test on a trust to check that Prodgator can load the issuer's signing keys. You can have up to 10 trusts, and deleting one stops its tokens right away. Both setting up a trust and creating a CI key are open to Org admins on every plan.