Skip to content

docs(triage-engine): webhook receivers and Jira two-way sync - #16060

Open
blakeaowens wants to merge 13 commits into
bugfixfrom
docs/jira-bidirectional-webhook-receiver
Open

blakeaowens wants to merge 13 commits into
bugfixfrom
docs/jira-bidirectional-webhook-receiver

Conversation

@blakeaowens

@blakeaowens blakeaowens commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Description

Documents Triage Engine webhook receivers and two-way sync for the Jira Downstream Connector (DefectDojo Pro).

  • New page: automation/triage_engine/webhook_receivers.md, ordered right after Building Rules. It covers how a delivery is handled, turning on two-way sync from a Jira connection (one receiver per connection), what Jira changes do to linked Findings, the status category lists, pushing notes to Jira as comments (every public note, from any path; private and rule-created notes never leave), building a rule for a custom webhook, authentication, receipts and replay, how retries are deduplicated in each mode, the webhook gateway and dead letters, the Inbound Webhooks flag, and permissions.
  • New upgrade page: releases/pro/webhook-gateway.md, linked from the changelog. What an upgrading Docker Compose or Kubernetes operator gets (the gateway image for amd64 and arm64, a -fips variant, the new nginx files, the secrets volume), the schema and dedicated database role with the SQL a database administrator runs when DefectDojo's user cannot create them, derived secrets, the connection budget and rate limits, how to verify the upgrade, running without the gateway, and rollback. ECS runs direct mode.
  • Configuration: the receiver limits, the gateway settings with DefectDojo's direct-mode default, secrets derived from DD_SECRET_KEY (explicit variables win), the procedure for changing the secret key, the database role and schema, the connection budget and rate limits.
  • Node Reference: entries for On an Inbound Webhook, Find Findings by a Value, Apply the Ticket's Status, and Add a Ticket Comment as a Note, including per-site scoping of classic Jira issues. The If / Filter entry no longer claims to be the only node with two outputs.
  • Building Rules: a "Referring to webhook data" section for webhook.* and the new ctx.* paths.
  • About: the node count is 47, and "Where to go next" links Webhook Receivers.
  • Jira connector reference: the inbound status category and resolution lists ("Coming Back From Jira"), Push Notes as Comments with Atlassian's granular scopes for adding a comment, and a Two-way Sync section.
  • Jira troubleshooting: a two-way sync section: receipts, rejected deliveries, Dispatch Failed, the run trace, the gateway states (including Not Started), the Gateway tab and dead letters, a 404 for a wrong token, signature failures after a secret change, and notes not reaching Jira.
  • Jira (Legacy) guide: the classic migration notes no longer say reverse sync and Push Notes do not carry over. Push Notes now becomes Push Notes as Comments, and the classic resolution mappings carry over to the connector's status mapping.

The Triage Engine page weights shift by one so Webhook Receivers sits before the reference pages; the translated pages get the same weights. Otherwise English only: the translated pages are regenerated on the usual schedule (docs/TRANSLATIONS.md).

Test results

Docs only. Every label and setting named here was checked against the Pro source. Internal links and anchors in the changed pages were checked; the local Hugo is older than the site needs, so the site was not built locally.

🤖 Generated with Claude Code

blakeaowens and others added 2 commits September 23, 2026 02:56
New Webhook Receivers page, node reference entries for the webhook trigger,
the Finding lookup and the two ticket-sync nodes, webhook paths in Building
Rules, receiver and gateway settings in Configuration, and push notes and
two-way sync on the Jira connector pages. The classic Jira migration notes
no longer say reverse sync and push notes do not carry over.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@blakeaowens blakeaowens added this to the 3.3.300 milestone Sep 23, 2026
@github-actions github-actions Bot added the docs label Sep 23, 2026
blakeaowens and others added 2 commits September 23, 2026 22:21
@blakeaowens

Copy link
Copy Markdown
Contributor Author

[sc-15550]

blakeaowens and others added 7 commits September 24, 2026 04:24
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… key

Documents DD_WEBHOOK_GATEWAY_SECRET_KEY beside the admin token, says that
dojo-compose-cli and the Helm chart generate both per installation, and describes
the startup warnings an installation still on the Docker Compose defaults gets.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ync troubleshooting

Address the review of the webhook receiver and Jira two-way sync docs:

- Gateway secrets are derived per install from DD_SECRET_KEY (the Helm
  chart derives them from dojo.secretKey); drop the claim that
  dojo-compose-cli generates them, and document rotating the secret key.
- DefectDojo defaults to direct mode; the compose bundles and the chart
  turn the gateway on explicitly, and ECS runs direct mode.
- Document the dedicated database role and schema, the SQL an
  administrator runs without CREATEROLE or CREATE, the connection budget,
  rate limits, and the single body-size setting.
- Correct deduplication per mode, receipt statuses, dead-letter replay,
  receiver deletion, permissions, and which notes are pushed to Jira.
- Status lists are Jira status category keys; classic resolutions come
  from the classic instance matching the issue's site.
- New releases/pro/webhook-gateway.md upgrade page, linked from the
  changelog; a two-way sync section in the Jira troubleshooting page.
- Node Reference count, Webhook Receivers ordered before the reference
  pages, American spelling, and Atlassian's granular scopes for comments.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…granted once

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Maffooch Maffooch modified the milestones: 3.3.300, 3.4.0 Sep 28, 2026
blakeaowens and others added 2 commits September 28, 2026 01:00
The release moved from 3.3.300 to 3.4.0 (due 2026-10-05).
…onal-webhook-receiver

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants