We already have JIRA, Stash, and Confluence installed and have been using them for some time. Each currently has a "Delegated LDAP" directory that authenticates via Active Directory. They all automatically create the user and adds them to the appropriate jira-users, stash-users, confluence-users group respectively at first log on. Not all users use all three apps but there is considerable overlap between the sets of users in each. We also have a number of additional groups that associate users with geographic locations (countries), product teams, etc. Groups that are used across all products are named the same in each app, and unique group names are used if they are only applicable to users of the particular app.
We are installing Crowd and my understanding is that it is better to use a single directory in Crowd (ours will be Delegated LDAP) so that we do not have duplicate users across three individual directories. We want to migrate to Crowd with hopefully no impact on the user community. I cannot find any document that discusses this scenario so I have questions:
- Is the single directory approach the preferred method?
- Can I migrate the users from all three apps into a single Crowd Delegated LDAP directory? Any problems I should watch out for? Special tricks?
- Will the groups also be migrated? Keeping the existing group memberships is essential since not every user has an account on all three apps so we need to maintain the memberships for the license counts.
- Once we convert to Crowd and each app is using the common Crowd directory instead of its own Delegated LDAP directory, do we need to keep the groups defined in the apps as well as in Crowd, or should they be defined in the apps instead of in Crowd, or can we put some in one place and some in others depending on whether they are used across all three apps or unique to a specific app. In other words the workings of groups and directories and related best practices are not clear to us, especially with multiple apps sharing the same directory. For example in JIRA we currently have a JIRA Internal directory and a Delegated LDAP directory. When we create a group in JIRA, there are two rows created in the cwd_group table, one for each of the directories (so the group "exists" in both directories). After the conversion, if we create a group in JIRA (assuming we still can), will it exist in the internal directory and the Crowd directory and will we see it in the UI in both JIRA and Crowd? A more detailed discussion of the theory and logic behind how this works would be most helpful.
I know this is a big ask, but my searches haven't turned up much in the way of information or guidance for multiple app migration and I really don't want to break our existing tools.