I have JIRA Server running behind my firewall on my dev machine and need to expose it to my co-workers so they can log-in without being on a VPN or having to use JIRA On Demand since we need other tools that aren't On Demand like Bamboo and Crucible. I have read that you can use Apache as a reverse proxy to forward requests to JIRA on Tomcat, but is this all you need to safely expose JIRA to the outside world? Seems exposing Apache on port 80 has its own list of security implicaitons. Therefore, seems there should be some sort of guide or blog on how to expose JIRA safely because I thought it was generally a bad idea to expose anything on Port 80, even if Apache is being used as a proxy.
As an aside, I work for a company whose developers are all distributed and work at home. We don't have a central office and would need to have access to JIRA hosted on one a machine at someone's residence but exposed to the internet. Otherwise, JIRA Server and other Server products seem to only be fit for those companies where everyone can be on the same LAN or VPN or have personnel that really know what they are doing.