Overview
AWX supports webhook integration for:- GitHub - GitHub.com and GitHub Enterprise
- GitLab - GitLab.com and self-hosted GitLab
- Bitbucket Data Center - Self-hosted Bitbucket
Webhook Components
Webhook Key
Each Job Template and Workflow Job Template can have an associated webhook key:- Secret token used to validate incoming webhook requests
- Automatically generated when webhook service is enabled
- Can be rotated for security
Webhook Service
Specifies which external service sends the webhook:githubgitlabbitbucket_dc
Webhook Credential
Optional credential for authenticating back to the external service:- Used to post status updates
- Enables AWX to update commit statuses
Configuration
Step 1: Enable Webhooks on Template
Configure a Job Template or Workflow Job Template for webhook support:Set Webhook Service
github, gitlab, or bitbucket_dcConfigure Credential (Optional)
Save Template
Step 2: Retrieve Webhook Key
Get the webhook key for configuring the external service:Step 3: Configure External Service
Set up the webhook in your repository:GitHub
Navigate to Repository Settings
Configure Webhook URL
Set Content Type
application/jsonAdd Secret
Choose Events
GitLab
Navigate to Repository Settings
Configure Webhook URL
Add Secret Token
Select Triggers
Disable SSL Verification (if needed)
Bitbucket Data Center
Navigate to Repository Settings
Configure Webhook URL
Set Secret
Choose Events
Webhook Behavior
Request Processing
When a webhook is received:Signature Verification
Duplicate Detection
Event Extraction
Job Creation
Job Launch
Signature Verification
Each webhook service uses different signature methods: GitHub:- Header:
X-Hub-Signature - Algorithm: HMAC SHA-1
- Format:
sha1=<signature>
- Header:
X-Gitlab-Token - Algorithm: Direct token comparison (no HMAC)
- Format: Plain text token
- Header:
X-Hub-Signature - Algorithm: HMAC SHA-256 or SHA-1
- Format:
sha256=<signature>orsha1=<signature> - Ping requests are not signed
Webhook Variables
Webhook events provide extra variables to your playbooks:awx_, tower_, and ansible_ for compatibility. Use awx_* variables in new playbooks.Using Webhook Variables
Event Types and References
GitHub Events
Supported event types and their reference keys:GitLab Events
Supported event types and their reference keys:Bitbucket Data Center Events
Supported event types and their reference keys:Security
Webhook Key Rotation
Rotate the webhook key if compromised:Permissions
Webhook key management requires:- Get webhook key: Admin role on the template
- Rotate webhook key: Admin role on the template
- Use
AllowAnypermission (no authentication required) - Security provided by signature verification
- Invalid signatures are rejected with
403 Forbidden
Best Practices
Use HTTPS
Rotate Keys
Limit Events
Monitor Logs
Status Updates
When a webhook credential is configured, AWX can post status updates back to the repository.GitHub Status Updates
GitLab Status Updates
Bitbucket Status Updates
Troubleshooting
Webhook Not Triggering Jobs
Verify Webhook URL
Check Webhook Key
Review External Service Logs
Examine AWX Logs
Signature Verification Failures
Duplicate Webhook Detection
If webhooks are being ignored:- AWX tracks webhook GUIDs to prevent duplicate processing
- Redelivering the same webhook from the external service will be ignored
- This is normal behavior to prevent duplicate job runs
- Create a new event to trigger a new job
Jobs Not Using Correct Ref
Ensure your Job Template is configured correctly:- Project must support SCM branch override
- Job Template must have “Prompt on launch” enabled for SCM branch
- Use
{{ awx_webhook_event_ref }}to checkout the correct ref
Use Cases
Continuous Deployment
Configure Webhook on Main Branch
Create Deployment Job Template
Automatic Deployments
Pull Request Testing
Multi-Environment Deployments
Use different templates for different branches:mainbranch → Production deploymentstagingbranch → Staging deploymentdevelopbranch → Development deployment