Hi,
I am operating in an environment with strict firewall and outside network access (read none).
The current JIRA and hence other Atlassian plugin architecture is causing significant dramas in that
essentially they require direct outgoing access to the Internet to upgrade and enhance the products. This conflicts with security protocols in place (i.e. no Internet access from production machines). I have attempted manual updates, but this is both time consuming and highly error prone. We need another solution.
The key issue here is that with Jira et al. requiring directly Internet access it bypasses, virus checking / packet inspection and many other security measures of what is downloaded. Further, plugins and other components come from a range of changing URI's making creating URI whitelists impractical.
I have trying to think of a solution that allows my customer to keep their software up to date whilst
sitting within their security policies.
My thinking is that we need a cache of the various updates / plugins where we can do all the
security stuff - prior's to loading the plugins into the secure applications.
Now it turns out that we already have such a thing - it is our Maven / Nexus repo.
This already connects to Atlassian's maven repo to update code during our plugin development cycles.
My question is, what would it take to make it possible to upgrade the Atlassian products and plugins via our Nexus repo or some other means, rather than having to lift up our firewalls to upgrade Atlassian Products directly (which looks doubtful at this stage).
Help greatly appreciated.
Kind Regards,
Philip Haynes