Deployment patterns to use the same confluence instance on intranet and internet

Hello,

My organization uses Confluence internally. It has the following setup:

  • Users login using crowd connected to Microsoft AD
  • Anonymous access can see almost everything

Now we would like to expose parts of this instance on the internet (includes putting the confluence instance in a DMZ). If a user accesses our confluence site from the internet we would like the following setup:

  • Anonymous access restricted to specific spaces - for public documentation etc.
  • Users can login using crowd connected to Microsoft AD and
    • can see everything if employee
    • can see specified spaces if partner (not employee)

Is it possible to mix these policys on the same confluence instance based on IP adress?

Thanks in advance,

Johan

2 answers

1 accepted

This widget could not be displayed.

This was put on hold by my organization.

After thinking about this for a while I would buy a second confluence instance and export/import spaces because of security concerns. That way I am assured that only public information is available on the internet.

This widget could not be displayed.

The part with anonymous users might be a problem

I would use a webserver in front of the confluence tomcat doing a sso with ntlm or kerberos, so your internal users are automatically logged in (with a special authenticator you have to write).

Use a second webserver for the web traffic.

The only problem, you have two servers but only one baseurl.

Maybe you can use the same domain and map it internally to a different ip?

If you get this working, the only thing you have to deal with is permission management.

You don't need internal anonymous access and can work with qualified user names.

Or do you need the anonymous access due to licensing?

Suggest an answer

Log in or Sign up to answer
Atlassian Summit 2018

Meet the community IRL

Atlassian Summit is an excellent opportunity for in-person support, training, and networking.

Learn more
Community showcase
Published Tuesday in Confluence

Add-on evaluation with confluence templates

Atlassian market place contains number of Apps/Addons which improves the capability of out of the box Atlassian products. It is good to follow a plugin evaluation process before install add-ons. So t...

107 views 12 6
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you