docs(triage-engine): webhook receivers and Jira two-way sync - #16060
Open
blakeaowens wants to merge 13 commits into
Open
blakeaowens wants to merge 13 commits into
blakeaowens wants to merge 13 commits into
Conversation
New Webhook Receivers page, node reference entries for the webhook trigger, the Finding lookup and the two ticket-sync nodes, webhook paths in Building Rules, receiver and gateway settings in Configuration, and push notes and two-way sync on the Jira connector pages. The classic Jira migration notes no longer say reverse sync and push notes do not carry over. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…onal-webhook-receiver
Maffooch
approved these changes
Sep 23, 2026
devGregA
approved these changes
Sep 23, 2026
…onal-webhook-receiver
… default Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
[sc-15550] |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…onal-webhook-receiver
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… key Documents DD_WEBHOOK_GATEWAY_SECRET_KEY beside the admin token, says that dojo-compose-cli and the Helm chart generate both per installation, and describes the startup warnings an installation still on the Docker Compose defaults gets. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…onal-webhook-receiver
…ync troubleshooting Address the review of the webhook receiver and Jira two-way sync docs: - Gateway secrets are derived per install from DD_SECRET_KEY (the Helm chart derives them from dojo.secretKey); drop the claim that dojo-compose-cli generates them, and document rotating the secret key. - DefectDojo defaults to direct mode; the compose bundles and the chart turn the gateway on explicitly, and ECS runs direct mode. - Document the dedicated database role and schema, the SQL an administrator runs without CREATEROLE or CREATE, the connection budget, rate limits, and the single body-size setting. - Correct deduplication per mode, receipt statuses, dead-letter replay, receiver deletion, permissions, and which notes are pushed to Jira. - Status lists are Jira status category keys; classic resolutions come from the classic instance matching the issue's site. - New releases/pro/webhook-gateway.md upgrade page, linked from the changelog; a two-way sync section in the Jira troubleshooting page. - Node Reference count, Webhook Receivers ordered before the reference pages, American spelling, and Atlassian's granular scopes for comments. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…granted once Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The release moved from 3.3.300 to 3.4.0 (due 2026-10-05).
…onal-webhook-receiver Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Documents Triage Engine webhook receivers and two-way sync for the Jira Downstream Connector (DefectDojo Pro).
automation/triage_engine/webhook_receivers.md, ordered right after Building Rules. It covers how a delivery is handled, turning on two-way sync from a Jira connection (one receiver per connection), what Jira changes do to linked Findings, the status category lists, pushing notes to Jira as comments (every public note, from any path; private and rule-created notes never leave), building a rule for a custom webhook, authentication, receipts and replay, how retries are deduplicated in each mode, the webhook gateway and dead letters, the Inbound Webhooks flag, and permissions.releases/pro/webhook-gateway.md, linked from the changelog. What an upgrading Docker Compose or Kubernetes operator gets (the gateway image for amd64 and arm64, a -fips variant, the new nginx files, the secrets volume), the schema and dedicated database role with the SQL a database administrator runs when DefectDojo's user cannot create them, derived secrets, the connection budget and rate limits, how to verify the upgrade, running without the gateway, and rollback. ECS runs direct mode.webhook.*and the newctx.*paths.The Triage Engine page weights shift by one so Webhook Receivers sits before the reference pages; the translated pages get the same weights. Otherwise English only: the translated pages are regenerated on the usual schedule (docs/TRANSLATIONS.md).
Test results
Docs only. Every label and setting named here was checked against the Pro source. Internal links and anchors in the changed pages were checked; the local Hugo is older than the site needs, so the site was not built locally.
🤖 Generated with Claude Code