Deployment patterns to use the same confluence instance on intranet and internet

Hello,

My organization uses Confluence internally. It has the following setup:

  • Users login using crowd connected to Microsoft AD
  • Anonymous access can see almost everything

Now we would like to expose parts of this instance on the internet (includes putting the confluence instance in a DMZ). If a user accesses our confluence site from the internet we would like the following setup:

  • Anonymous access restricted to specific spaces - for public documentation etc.
  • Users can login using crowd connected to Microsoft AD and
    • can see everything if employee
    • can see specified spaces if partner (not employee)

Is it possible to mix these policys on the same confluence instance based on IP adress?

Thanks in advance,

Johan

2 answers

1 accepted

This was put on hold by my organization.

After thinking about this for a while I would buy a second confluence instance and export/import spaces because of security concerns. That way I am assured that only public information is available on the internet.

The part with anonymous users might be a problem

I would use a webserver in front of the confluence tomcat doing a sso with ntlm or kerberos, so your internal users are automatically logged in (with a special authenticator you have to write).

Use a second webserver for the web traffic.

The only problem, you have two servers but only one baseurl.

Maybe you can use the same domain and map it internally to a different ip?

If you get this working, the only thing you have to deal with is permission management.

You don't need internal anonymous access and can work with qualified user names.

Or do you need the anonymous access due to licensing?

Suggest an answer

Log in or Sign up to answer
How to earn badges on the Atlassian Community

How to earn badges on the Atlassian Community

Badges are a great way to show off community activity, whether you’re a newbie or a Champion.

Learn more
Community showcase
Asked yesterday in Confluence

What are the resources that you use to learn more about Atlassian Products?

I am gathering information about resources available for Atlassian product knowledge transferring for a presentation in our local Atlassian User Group. I want to group them in four categories From ...

98 views 4 4
View question

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you