Summary
I am trying to get an application link between my origination Bamboo Instance and our Atlassian JIRA-Cloud account. The application link from JIRA-Clopud to bamboo is broken and gives error 403. Without more information from JIRA-Cloud I cannot figure out the cause of the problem. Any idea how to fix this?
Details
We are running bamboo behind nginx following these steps.
The link form bamboo to JIRA-cloud looks good, but I am having trouble with the reverse. Initially it looks good, JIRA-Cloud looks like it is thinking and nginx shows good responces (nginx log below)
192.168.xxx.xxx - - [10/Jun/2019:08:49:13 -0400] "OPTIONS /bamboo/plugins/servlet/oauth/consumer-info?_=000000000000 HTTP/1.1" 200 0 "https://xxxxxxx.atlassian.net/plugins/servlet/applinks/listApplicationLinks" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
192.168.xxx.xxx - - [10/Jun/2019:08:49:13 -0400] "GET /bamboo/plugins/servlet/oauth/consumer-info?_=00000000 HTTP/1.1" 200 643 "https://xxxxxxx.atlassian.net/plugins/servlet/applinks/listApplicationLinks" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
Then this suddenly stop with no further information from nginx. I get the following from JIRA-Cloud:
Unexpected response
We received an unexpected response from XXXXXX Bamboo. If the remote application is behind a proxy, check that the application is operational. Troubleshoot this for other possible causes.
403: Forbidden
To see the full response content look at your application logs.
Looking up the error you get the following
HTTP 403: Forbidden- This usually indicates an authentication failure. However application links report authentication failures differently from a 403, so this suggests a problem with the proxy configuration instead.
| - The remote application is behind a misconfigured proxy. Check the local application logs for the
<response body>. - If the application has been configured with an outbound proxy, the remote application URL can be added to the nonProxyHosts to allow the application link to bypass it.
- nonProxyHosts may be configured incorrectly and non-functional. See:
|
The application logs just show what the nginx logs show, good HTTP requests. There is one error but it looks like an intentional one for backwards compatibility,
2019-06-10 11:45:45,995 WARN [AtlassianEvent::0-BAM::EVENTS:pool-1-thread-4] [DefaultRemoteCapabilitiesService] Exception trying to get Applink for manifest with ID 06d0e21c-a66a-308c-a57c-29650c0df38f
2019-06-10 11:45:45,995 INFO [http-nio-8100-exec-11] [AppLinksManifestDownloader] Authenticator placeholder.to.ensure.backwards.compatibility specified by remote application 06d0e21c-a66a-308c-a57c-29650c0df38f is not installed locally, and will not be used.
2019-06-10 11:45:45,996 INFO [http-nio-8100-exec-11] [AppLinksManifestDownloader] Authenticator placeholder.to.ensure.backwards.compatibility specified by remote application 06d0e21c-a66a-308c-a57c-29650c0df38f is not installed locally, and will not be used.
2019-06-10 11:45:55,767 INFO [http-nio-8100-exec-17] [AccessLogFilter] liam PUT https://XXX/bamboo/rest/applinks/3.0/applicationlink 376109kb
2019-06-10 11:45:56,051 INFO [http-nio-8100-exec-18] [AccessLogFilter] liam GET https://XXX/bamboo/rest/applinks/3.0/applicationlink/06d0e21c-a66a-308c-a57c-29650c0df38f?_=1560181543582 371127kb
2019-06-10 11:45:56,076 INFO [http-nio-8100-exec-19] [AccessLogFilter] liam PUT https://XXX/bamboo/rest/applinks/3.0/applicationlink/06d0e21c-a66a-308c-a57c-29650c0df38f/authentication/provider 370226kb
2019-06-10 11:45:56,081 INFO [http-nio-8100-exec-21] [AccessLogFilter] liam PUT https://XXX/bamboo/rest/applinks-oauth/1.0/applicationlink/06d0e21c-a66a-308c-a57c-29650c0df38f/authentication/consumer?autoConfigure=true 369629kb
2019-06-10 11:45:56,123 INFO [http-nio-8100-exec-20] [AccessLogFilter] liam PUT https://XXX/bamboo/rest/applinks/3.0/applicationlink/06d0e21c-a66a-308c-a57c-29650c0df38f/authentication/provider 367846kb
As far as `nonProxyHosts` , nginx should be rewriting the requests to account for this.
At this point I am pretty much at a dead end besides blindly adjusting http.proxy settings.
Update
Setting nonProxyHost in catalina.properties did not fix the problem:
http.nonProxyHosts=*.atlassian.com|*.atlassian.net|localhost|*.bitbucket.org
Also I found this page and to answer each point:
- You must have administrator permissions on both the Cloud application (JIRA) and the stand-alone Bamboo.
I Do
- Bamboo should be accessible via either port 8085, 80 or 443.
It is being served from an alt port, is this really the cause of the 403?
- If SSL is used, you need to have a valid certificate, a self-signed certificate can NOT be used.
it does