Domains we connect to
Forge apps declare every domain they can reach, and that declaration is enforced by the platform rather than by us. Nothing can quietly connect somewhere undeclared.
The categories below are what those domains are for. Your own approved egress domains are added to this list by you, and by nobody else.
#When this matters
Firewall and proxy configuration.
Security questionnaires asking for an egress list.
Understanding what a browser does when it renders a page with diagrams.
#The detail
Thing | What happens |
|---|---|
Atlassian | Confluence itself, for storage, permissions and page content. |
Capable services | The rendering service and app backend. |
Your own approved domains | Only those an administrator has added. |
Nothing else | Undeclared domains are blocked by the Forge platform. |
#A few things that catch people out
The enforcement is Atlassian's, not ours. That is what makes the declaration meaningful.
A self-hosted renderer means adding your own renderer's domain to the approved list.
The exact current list is shown on the Marketplace listing, and on the permissions screen when you install or update the app. For your own domains, see Administration.
#Related
Ask us the awkward questions. They have answers.
