baton-confluence is a connector for Confluence built using the Baton SDK. It communicates with the Confluence API to sync data about users, groups, spaces, and space role assignments (RBAC or granular permissions).
Check out Baton to learn more the project in general.
brew install conductorone/baton/baton conductorone/baton/baton-confluence
baton-confluence
baton resources
docker run --rm -v $(pwd):/out -e BATON_DOMAIN_URL=domain_url -e BATON_API_KEY=apiKey -e BATON_USERNAME=username ghcr.io/conductorone/baton-confluence:latest -f "/out/sync.c1z"
docker run --rm -v $(pwd):/out ghcr.io/conductorone/baton:latest -f "/out/sync.c1z" resources
go install github.com/conductorone/baton/cmd/baton@main
go install github.com/conductorone/baton-confluence/cmd/baton-confluence@main
BATON_API_KEY=apiKey BATON_DOMAIN_URL=domainUrl BATON_USERNAME=username
baton resources
baton-confluence will pull down information about the following Confluence resources:
- Spaces & Space Permissions
- Groups
- Users
- Space Roles (opt-in, requires
--use-rbac) - Space Role Assignments (opt-in, requires
--use-rbac)
Confluence is transitioning to an RBAC model for space access control. The connector supports both modes.
By default, the connector syncs granular space permissions as Entitlements. Each permission is represented as a pair of "operation" and "target".
Valid targets include:
applicationattachmentblogpostcommentdatabaseembedpagespaceuserProfilewhiteboard
Valid operations include:
administerarchivecopycreatecreate_spacedeleteexportmovepurgepurge_versionreadrestorerestrict_contentupdate
Not all operation-target pairs are valid, but here are some examples of valid ones:
administer-spacecreate-attachmentcreate-blogpostcreate-commentcreate-pagedelete-spaceexport-spaceread-spaceupdate-space
See Space Permissions Overview documentation page.
When --use-rbac is set, the connector instead syncs Confluence RBAC space
roles as Entitlements. Role assignments to users and groups are synced as
Grants, and provisioning (grant/revoke) operates on role assignments.
Use this mode when your Confluence instance has space roles enabled and you want to manage access through Confluence's newer RBAC model rather than granular permissions.
We started Baton because we were tired of taking screenshots and manually building spreadsheets. We welcome contributions, and ideas, no matter how small -- our goal is to make identity and permissions sprawl less painful for everyone. If you have questions, problems, or ideas: Please open a GitHub Issue!
See CONTRIBUTING.md for more details.
baton-confluence
Usage:
baton-confluence [flags]
baton-confluence [command]
Available Commands:
capabilities Get connector capabilities
completion Generate the autocompletion script for the specified shell
help Help about any command
Flags:
--api-key string required: The API key for your Confluence account ($BATON_API_KEY)
--client-id string The client ID used to authenticate with ConductorOne ($BATON_CLIENT_ID)
--client-secret string The client secret used to authenticate with ConductorOne ($BATON_CLIENT_SECRET)
--domain-url string required: The domain URL for your Confluence account ($BATON_DOMAIN_URL)
-f, --file string The path to the c1z file to sync with ($BATON_FILE) (default "sync.c1z")
-h, --help help for baton-confluence
--log-format string The output format for logs: json, console ($BATON_LOG_FORMAT) (default "json")
--log-level string The log level: debug, info, warn, error ($BATON_LOG_LEVEL) (default "info")
--noun strings The nouns for your Confluence Space sync ($BATON_NOUN)
-p, --provisioning This must be set in order for provisioning actions to be enabled ($BATON_PROVISIONING)
--skip-full-sync This must be set to skip a full sync ($BATON_SKIP_FULL_SYNC)
--skip-personal-spaces Skip syncing personal spaces and their permissions ($BATON_SKIP_PERSONAL_SPACES)
--ticketing This must be set to enable ticketing support ($BATON_TICKETING)
--use-rbac Use Confluence RBAC space roles instead of granular space permissions ($BATON_USE_RBAC)
--username string required: The username for your Confluence account ($BATON_USERNAME)
--verb strings The verbs for your Confluence Space sync ($BATON_VERB)
-v, --version version for baton-confluence
Use "baton-confluence [command] --help" for more information about a command.
