Create an application tunnel to your Data Center instance

Who can do this?
Role: Organization admin
Atlassian Cloud: All plans
Atlassian Government Cloud: Not available

An application tunnel connects your whole organization to a Data Center instance and can be used to forward application links from specific cloud apps.

If you are setting up a Rovo cloud connector for a behind-the-firewall Data Center instance, you usually don't need to follow this page - the cloud connector setup wizard can create a tunnel for you automatically (on Confluence 10.2.16 and Jira 11.3.10 and later versions).. Use this page if you want to manage tunnels independently of a cloud connector, or if your Data Center instance is on an older version that does not support automatic tunnel setup. See Configure cloud connectors.

Before you begin

  • Make sure you’ve prepared your Data Center instance by completing the steps described in Install application tunnels from Atlassian Marketplace and Configure required connections and upstream ports.

  • In admin.atlassian.com, you can create up to 100 tunnels, each going to a different Data Center instance. However, each self-managed instance can receive only one tunnel. You can still link multiple cloud apps to this single tunnel.

  • You’ll generate a security key for each tunnel. If you’d like to later regenerate it or set up automatic key rotation by using APIs, see Regenerate security key and Set up automatic key rotation.

  • When a tunnel is created automatically through a cloud connector, its security key is exchanged and rotated automatically. Manual key generation and rotation (described on this page) is only needed for standalone tunnels or older Data Center versions.

Create a tunnel from admin.atlassian.com

To create a tunnel from admin.atlassian.com:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Data management, then Data sources, then Application tunnels.

  3. Select Create tunnel.

  4. Go through the wizard to provide the details of your Data Center instance and generate the security key associated with your tunnel.

  5. Add the key to your Data Center instance. You can either choose to be redirected to your instance, or copy the key and give it to the admin of this instance so they can add it manually.

On Data Center instances running on Jira 11.3.10 and Confluence 10.2.16 or later, when the tunnel is created via the cloud connector wizard the security key is exchanged automatically - you do not need to copy it manually, and no restart is required.

Example

This is how a tunnel looks after being created in admin.atlassian.com. The status is Incomplete until you add the tunnel security key to your Data Center instance:

Image showing an application tunnel on the cloud side.

Add the tunnel’s security key to your Data Center instance

To add the tunnel’s security key:

  1. Go to application tunnels. If you were redirected here from cloud, you should already be on the right screen. If you weren’t redirected:

    1. Go to Atlassian Administration. Select your organization if you have more than one.

    2. Select Data management, then Data sources, then Application tunnels.

    3. Select Add security key.

  2. Paste your security key and follow the steps in the wizard.

Your tunnel is created. Wait until its status changes to Connected. For more info on statuses, see Available statuses for application tunnels.

If a tunnel displays the Error status…

Because of an incident on our side, some application tunnels might have stopped working. If a tunnel worked previously, but now displays the Error status, restart the Marketplace app in your Data Center instance. Learn more

Example

This is how a sample tunnel looks in your Data Center instance:

An application tunnel on the server side.

Next steps

Your tunnel is ready. To make your cloud apps use it, do one of the following:

  • if you created app tunnel as part of setting up cloud connector to your Data Center instance behind the firewall, return to the original page to continue the setup. Configure cloud connector

  • if you created app tunnel as part of connecting cloud to Data Center with application links, proceed to create a tunneled application link

Still need help?

The Atlassian Community is here for you.