Hi Data Center Community 👋
Last year we introduced OAuth 2.0 and Cloud Connectors — a simpler, more secure way to connect Atlassian Data Center to Cloud — and more recently extended that support to the previous LTS versions of Jira and Confluence.
Today we’re excited to share the next step: Secure Tunnels are now built directly into the Cloud Connectors setup flow. If your Data Center instance sits behind a firewall, connecting it to Cloud just became dramatically simpler — no manual credential copying, and no server restart on supported versions.
If your Data Center instance is behind a firewall, Cloud can’t reach it directly. Until now, connecting a firewalled instance to Cloud features like Rovo meant setting up an application tunnel separately from the connector itself — a fragmented, multi-step process that involved:
Leaving the connector setup flow to configure a tunnel
Manually copying credentials between Cloud and your Data Center instance
Making direct server configuration changes — often requiring a restart of your Data Center instance
Manually rotating tunnel keys to stay secure
Every one of those steps was an opportunity for error, downtime, or a credential to leak. We wanted connecting a behind-the-firewall instance to be as easy as connecting one that isn’t.
Secure Tunnel setup is now part of the Cloud Connector wizard itself. When you set up a Rovo and Team Graph connector for a Data Center instance that needs a tunnel, everything happens inline — in one flow, in one place.
Integrated tunnel setup — create a secure, encrypted tunnel without ever leaving the Cloud Connector setup flow.
Automatic detection and reuse — if a suitable tunnel already exists, the wizard detects it and reuses it instead of asking you to create a new one.
Automated credential management — no more copying client IDs, secrets, or tokens by hand. Credentials are generated and exchanged for you.
Zero-restart setup — is supported on the same versions that ‘Automated credential management’ and ‘Integrated tunnel setup’ are on supported Data Center versions, setting up a tunnel no longer requires restarting your instance.
Automatic key rotation — tunnel credentials are rotated automatically to keep your connection secure over time.
Live health visibility — see the health status of your tunnels right in the Atlassian Admin Hub, with clear indicators if a connection is interrupted.
Go to Atlassian Administration → Connected Sources.
Create Rovo connector for your Jira and Confluence (for example, to connect Jira or Confluence Data Center to Rovo).
If your instance needs a tunnel, the wizard auto-detects an existing tunnel or offers to create one inline — no separate setup, no credential copying.
Approve the connection in your Data Center instance. No restart required.
Start using Cloud-powered features like Rovo and Teamwork Graph.
Stronger security — automated credential handling and key rotation remove the manual steps where secrets could be mishandled or leaked.
Less downtime — no need to restart your Data Center instance to stand up a tunnel.
Better visibility — tunnel health and dependent connections are surfaced in the Admin Hub, so you can spot and resolve issues quickly.
Ready for hybrid and migration — keep Data Center and Cloud connected securely while you run in hybrid mode or migrate in stages.
Integrated Secure Tunnel setup is available for Rovo and Teamwork Graph connectors on Data Center instances running supported versions. Manual tunnel setup is still available for older Data Center versions or for standalone tunnel management.
This functionality is available — Jira 11.3.11+ and Confluence 10.2.16+ onwards.
Have you tried the new integrated tunnel setup? We’d love to hear how it’s working for you — share your experience, use cases, or questions in the comments below. 💬
Abhishek Desai
2 comments