External Repository Sites
Up to BigFix 11.0.6, managing custom content across multiple root servers and environments presents significant challenges:
- Custom content is packaged and published separately.
- Repository history is not the site version source of truth.
- Cross-environment tracing of author and commit is difficult.
Starting with BigFix 11.0.7, integrating BigFix directly with external source control systems (Git) allows BigFix to treat repositories as "External Sites" and gather content directly at the source.
This enhancement aligns BigFix with standard DevOps practices, providing:
- Unified Source of Truth: Centralized versioning and clear cross-environment history tracking.
- DevOps Integration: Full compatibility with modern CI/CD and automation pipelines.
- Enhanced Governance: Improved visibility into content evolution while maintaining strict content confidentiality.
In BigFix 11.0.7, the BigFix Server treats the Git repository as the source of truth for
a new site type called External Repository Site:
- A new External Site type recognized by a repository-specific gather URL.
- Repository URL and branch define the source identity.

The content flow is as follows:
- Initial synchronization uses a shallow clone; later cycles reuse the local repository and perform incremental fetches.
- The generated site behaves like traditionally published external content: signed listing first, then file hash validation.
- A manual Gather operation triggers an immediate repository check; normal scheduling uses the configured polling period.
- Repository SSH access and known_hosts verification protect synchronization.
SSH Access: Required Root Server Preparation
The repository access is read-only and uses credential files controlled by the Root Server service account.
Before the first import:
- Register id_rsa.pub with the Git service account permitted to read the repository.
- Populate known_hosts with the repository host public keys.
- Ensure the BES Server service account can read the private key.
Repository Site Import
Deployment-signed Repository Site:
- Permanent deployment Repository Site Registrar signs the mastheads.
- Trust is local to the issuing deployment.
- Registrar is created once, stored, reused, and explicitly rotated or revoked.
- Only BigFix 11.0.7 and later endpoints are supported.
Create Deployment Repository Site through Console
Using the BigFix Console, Master Operators can choose the menu Tools > Create External Repository Site... as described in Create Repository Site.