Hi Atlassian,
We are a server licensed customer of several of your products for our internal development operations.
We are planning to move our internal development infrastructure into the cloud. As part of that we are investigating hosting of JIRA, BitBucket and Confluence in Amazon AWS. Do you have any issues with us hosting a licensed JIRA/BitBucket/Confluence server in a cloud?
Also, as a matter of policy, to protect our data, we are planning to run a vulnerability test on all tools deployed in our cloud environment. Are there any issues with running a vulnerability test within our environment against our servers running a licensed version of your software?
Basil
I'm not an Atlassian, but I can answer.
You can run Server versions of the Atlassian stack anywhere you want
Two caveats on that:
You should not find any issues running your vulnerability tests against a licenced Atlassian application. If, however, you have any nagging doubt, then your commercial licence comes with "developer" licences. You can use those instead, without compromising your production licences in any way.
Thanks Nic,
I believe we have the OS container worked out, but I a concerned if somehow we would be violating Atlassians Acceptable Use terms in the legal agreements by running a vulnerability scan against their software, licensed appropriately, in our servers on a cloud.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Basil,
There's no problem, atlassian promotes the reporting of security issues with a number of programs.
you can check https://www.atlassian.com/trust/security
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I'm guessing you are reading https://www.atlassian.com/legal/acceptable-use-policy ?
You're absolutely right that running your security scans against their software on their serves breaches the AUP.
But... that applies to their servers, not yours. You can do what you want with your servers, even if they're running Atlassian software. In fact, Atlassian would support you doing it - if security testing is something you want to do against your servers, you absolutely should do it. I am aware of a number of sites hosting Atlassian software who run some pretty heavy and hardcore security checks on their own stuff regularly and very frequently (and I'm not going to pretend Atlassian always passes every test).
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Basil,
i think that hosting jira on aws follows the same licensing scheme than the server version.
regarding the vulnerability test, can you specify which tool are you using? I have no experience in that field but by knowing the tool maybe someone can help
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Its a third party recommended by Amazon, but let's say for the sake of this discussion its a stock vulnerability testing suite for network and web applications recommended by security standards organizations. Tools like Nessus, OpenVAS, Rapid7, etc.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.