Hi,
I'm wondering if there is a generic architecture suggestion for the atlassian stack. Although I don't know how useful it would be, I think we're already going a bit "off book".
We started with JIRA on a public network, then added Fisheye in a DMZ, talking to our repositories on an "internal" network.
Now, we've got Confluence (internal network) and want to connect it to Jira.
To talk, Confluence/JIRA seem to need a direct connection, so we can't use a DMZ.
Along with Confluence, I also decided to go for Crowd, which I'm guessing is going to need direct access from JIRA too.
Is it common to install all this on an "internet" facing network? Crowd in particular seems highly risky. Or is there a way to proxy connections through a DMZ gateway somehow?
(Of course, I can firewall the applications, but if there is a zero-day exploit in JIRA and I've allowed it to get to 443 on Confluence, a lot of Atlassian apps use the same Java components, so likely, we've just allowed one 0-day attack direct access from the internet to our internal LAN. I'm not sure how much value the DMZ with Fisheye is giving us either...)