Skip to main content

    Bitbucket Data Center stays. The question is what posture you run it in.

    Atlassian kept Bitbucket Data Center when other Data Center products moved, because source-code workloads have requirements Cloud does not serve for regulated buyers. iTmethods runs it inside your authorization boundary as a single-tenant dedicated instance.

    Delivered as a single-tenant dedicated instance, in your own AWS or Azure cloud account or in infrastructure iTmethods operates. Both are available today. Google Cloud is planned for 2027. Air-gapped and sovereign are in development.

    The decision you are being forced to make

    Atlassian set the dates. You still choose the posture.

    Atlassian's published Data Center lifecycle forces a near-term decision for every Atlassian customer. Bitbucket Data Center is the one product in the family without a read-only end date — which makes the decision about posture rather than about survival. All four dates below are Atlassian's own.

    DateWhat happensWhat it means
    30 March 2026 New Data Center license cutoff Atlassian stops selling new Data Center licenses to new customers. After this date, if you do not already hold a Bitbucket Data Center license, you cannot buy one as a new customer.
    Mid-2026 Hybrid license launches A hybrid Bitbucket Data Center and Cloud license at no extra cost. Existing Data Center customers can run both side by side.
    30 March 2028 Expansion window closes Existing customers can keep expanding their license footprint until this date. After it, expansions close too.
    28 March 2029 Other Data Center products go read-only Jira, Confluence and Jira Service Management Data Center go read-only. Bitbucket Data Center does not. Atlassian continues to support and develop it, on the basis that source-code workloads have security and compliance requirements Cloud cannot serve for regulated enterprises.

    Dates as published by Atlassian. Confirm them against Atlassian's own lifecycle documentation before you plan against them — they are that vendor's to change, not ours.

    Deployment

    Two shapes. One operating posture.

    The governed posture does not change when the shape does. Multi-node Data Center clustering is wired to your load balancer and storage either way.

    ShapeWhat it isStatus
    Single-tenant dedicated instance, in our environment Provisioned for one customer and serving that customer only, in infrastructure iTmethods operates, with Data Center clustering wired to the load balancer and storage primitives. For organizations that want a managed envelope without standing up the Data Center operational competency in-house. Available today
    Single-tenant dedicated instance, in your own cloud account The same instance, provisioned in your own AWS or Azure account. The account is yours and the billing relationship with the cloud provider is yours. Google Cloud is planned for 2027. Available today
    Air-gapped and sovereign Air-gapped deployment and sovereign deployment. Two shapes, in development together. In development
    Neither of the two in development is available, neither is being sold, and we are not offering a date. There is no multi-tenant or shared option at any tier. iTmethods makes no compliance, certification or accreditation claim under any framework. Regulatory alignment →
    The hardening sheet

    What Reign Ops applies on day one.

    Twelve named controls, each policy-as-code rather than manual configuration. Five are below. The full deliverable, with framework mapping, topology diagrams and sample policy excerpts, is the hardening sheet.

    Identity boundary bound to your provider.

    SAML or OIDC at the platform edge, single sign-on only, on the protocol you already run.

    Allow-listing at both edges.

    At the platform edge and at the runner edge, so the execution surface is bounded as tightly as the console is.

    Pipelines runners isolated per environment.

    Short-lived tokens, no long-lived registration secrets, and no shared execution surface between environments.

    Audit log streamed to your SIEM.

    Bitbucket audit logs go to the system your security team already watches rather than staying in a console.

    AI coding tools governed at the call layer.

    Atlassian Intelligence and the rest of the fleet route through Reign Gateway. The section below is what that means in practice.

    And seven more.
    Code scanningBranch protectionApproved-model registryData classificationEgress controlsBackup and disaster recovery

    Plus a periodic hardening review with your team.

    The complete control set, with framework mapping and sample policy excerpts. Bitbucket DC on Reign Ops hardening sheet →

    The AI coding tools

    Productivity multipliers, and the newest way code leaves.

    Atlassian Intelligence, Copilot, Cursor, Claude Code and the rest of the coding-agent fleet read and write your source code at machine pace. Reign Gateway governs them at the call layer, which is the one place a policy can apply to all of them at once, whoever built them.

    What the boundary adds
    Every call routed through Reign Gateway: identity-bound, content-classified, and policy-enforced before the model sees the code. For each one the record carries the identity that made it, the policy that applied, the decision taken, the model that answered and the time it happened. You author the catalog of tools the organization sanctions; the boundary enforces it.
    The part worth being precise about. This governs the coding tools your own engineers run. It is not a claim that those tools are safe, and it does not make an unapproved model approved. iTmethods makes no compliance, certification or accreditation claim under any framework. How the boundary works → · Regulatory alignment →
    Where Reign Factory fits

    The same instance, with work arriving in it.

    Reign Ops is sold and operated on its own terms, and a customer who never adopts Reign Factory loses nothing here. But this is the platform Factory hands work to.

    What Factory does against a governed Bitbucket Data Center. It works an item you assign in an isolated environment, with Reign Gateway on the model path, and opens a pull request in your Bitbucket project carrying its checks and findings. Your pipeline, your reviewers and your release process are unchanged and still decide what ships.
    What it does not do. It does not merge and it does not release. Autonomy is off by default and is turned on per population, by you, in writing. Reign Factory is being productized toward commercial availability rather than generally available today. What it is, and what it will not do →
    Shared responsibility

    What we run, what you run.

    Scoped to Bitbucket Data Center, and written down before anything is deployed, so the boundary is a document rather than a discovery.

    WhoWhat they hold
    Reign Ops, automated Operate Bitbucket Data Center inside your authorization boundary. Enforce your identity provider at the platform edge. Run Bitbucket Pipelines runners isolated per environment with short-lived tokens and no long-lived registration. Stream the audit log to your SIEM. Apply hardening as policy-as-code. Patch the substrate and the runner fleet on a cadence matched to upstream releases.
    Customer authored Your repositories and intellectual property. Code review policy, branch protection and push policy. The catalog of AI coding tools the organization sanctions. Approval of the evaluators authored during the on-ramp, and of new tool integrations and policy exceptions as they are surfaced.
    Operating partner engagement Stand up the initial hardening configuration. Author the first set of evaluators against your Bitbucket Data Center surface. Operate the remediation path on what those evaluators find. Lead the periodic posture review with your risk, security and audit functions, and train your teams to author their own evaluators.
    Before the scoping call

    The questions that arrive every time.

    Is Bitbucket Data Center going away?
    No. It is the one product in the Atlassian Data Center family without a read-only end date. Jira, Confluence and Jira Service Management Data Center go read-only in March 2029 on Atlassian’s published plan; Bitbucket Data Center continues to be supported and developed. Confirm the dates against Atlassian’s own documentation before planning against them.
    What if we already run the rest of Atlassian?
    Bitbucket Data Center runs under the same operating model as the rest of the estate we manage, so source control sits next to the tracker rather than away from it. What happens to the products that do have a read-only date is a separate conversation, and there is a page for it. The Atlassian Data Center path →
    Does Atlassian Intelligence still work?
    Yes, and it routes through Reign Gateway at the call layer along with every other coding agent your engineers use. You author the catalog of what is sanctioned; the boundary enforces it and records what each call asked for, what applied to it and what came back.
    Which deployment shapes can we have?
    A single-tenant dedicated instance, in your own AWS or Azure cloud account or in infrastructure iTmethods operates. Both are available today and both are single tenant. Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier.
    What happens to the AI coding tools our engineers already use?
    They keep working, and they route through Reign Gateway at the call layer. You author the catalog of what is sanctioned; the boundary enforces it and records what each call asked for, what applied to it and what came back. Nothing here requires your engineers to change tools.
    Can we see the controls before committing to anything?
    Yes. Five of the twelve are on this page in full, and the hardening sheet carries all twelve with framework mapping and sample policy excerpts. Nothing on this page needs a conversation before you can read it.
    AWS Advanced Tier Services Partner
    AWS Advanced Tier Services Partner and Validated Managed Service Provider. Twenty-one years operating critical infrastructure for regulated enterprises.
    Next step

    Scope your Bitbucket Data Center on Reign Ops.

    Tell us where your Bitbucket runs today, whether the rest of the Atlassian estate is moving, and what is forcing the question. We will come back with what we would operate and what we would leave alone.