Skip to content

Quickstart

Drop the snippet below into your bitbucket-pipelines.yml. It uses OIDC so no AWS access keys ever land in your pipeline. The IAM trust policy that pairs with it lives in the OIDC setup guide.

image: atlassian/default-image:4

pipelines:
  branches:
    main:
      - step:
          name: Deploy to EKS
          deployment: production
          oidc: true                                     # Bitbucket sets BITBUCKET_STEP_OIDC_TOKEN
          script:
            - pipe: docker://ghcr.io/yves-vogl/aws-eks-helm-deploy:2
              variables:
                OIDC_AUDIENCE: $OIDC_AUDIENCE            # ari:cloud:bitbucket::workspace/<UUID>
                ROLE_ARN: $DEPLOY_ROLE_ARN
                AWS_REGION: eu-central-1
                CLUSTER_NAME: my-eks-cluster
                CHART: repo://bitnami/nginx
                REPO_URL: https://charts.bitnami.com/bitnami
                CHART_VERSION: 18.2.0
                RELEASE_NAME: nginx
                NAMESPACE: production
                WAIT: "true"
                TIMEOUT: 10m

Image pinning

Pin the pipe to :2 (rolling major) or to a specific version like :2.0.0. :latest is also published but pinning to a major is the recommended pattern — you get patch + minor updates automatically while a major-version bump always requires an explicit migration step.

Need static AWS keys for now?

If OIDC isn't an option yet, the examples/basic/ snippet has the same shape with AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY instead. When you're ready to migrate, follow the Migrating from static keys walkthrough.

More copy-paste-ready snippets

Scenario Path
Static keys + local chart examples/basic/
OIDC + Helm repo chart examples/oidc-only/
OIDC + OCI chart from GHCR examples/oci-chart/
Multi-env with ACTION=diff PR comments examples/multi-env/
v1 → v2 line-by-line migration diff examples/migration-v1-to-v2/

All five bitbucket-pipelines.yml files in examples/ are schema-validated in CI via check-jsonschema --builtin-schema vendor.bitbucket-pipelines.

Variables

The full, autogenerated reference is at reference/variables. For an at-a-glance summary of the most common variables — auth, cluster + chart, action + behaviour — see the README.

Verifying releases

Every release is signed (Cosign keyless) and ships SPDX + CycloneDX SBOMs. The exact cosign verify and cosign verify-attestation commands live in the README "Verifying releases" section.