Confluence Data Center
Protect access to self-managed Confluence Data Center workspaces as an upstream web application.
Overview
Confluence Data Center is the self-managed Confluence product for clustered or single-node enterprise deployments. It exposes a web interface and API. Collaborative editing can add Synchrony and WebSocket proxy requirements.
Confluence Data Center can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Confluence Data Center. Confluence Data Center remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Set the Confluence canonical base URL and connector proxy settings for the Pomerium origin. Configure Synchrony and collaborative-editing proxy paths when the deployment uses them.
Example
A private Confluence Data Center deployment uses Pomerium as its user-facing route. Employees authenticate through Pomerium. Confluence still controls spaces, pages, and administration permissions.
Considerations
- Atlassian Server support ended on February 15, 2024. Use this route for Confluence Data Center.
- Atlassian states that Data Center reaches end of life on March 28, 2029. Review the product lifecycle before a new deployment.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
Sources and official resources
- Confluence Data CenterOfficial website
- Confluence proxy and HTTPS configurationOfficial documentation
- Atlassian Server end of supportPrimary source
- Atlassian Data Center end of lifePrimary source
- Pomerium HTTP and WebSocket routingPomerium documentation
- Pomerium route timeoutsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
