Hubbry Logo
search
logo

Confluence (software)

logo
Community Hub0 Subscribers
Read side by side
from Wikipedia

Confluence
DeveloperAtlassian
Initial release25 March 2004; 22 years ago (2004-03-25)
Stable release
8.5.2[1] / 4 October 2023; 2 years ago (4 October 2023)[±]
Written inJava
Operating system
Available inEnglish, Spanish, Simplified Chinese, Czech, Finnish, French, German, Russian, Swedish, Japanese, Norwegian, Polish[3]
TypeWiki (Knowledge management software, Collaborative software)
LicenseProprietary
Websitewww.atlassian.com/software/confluence

Confluence is a web-based corporate wiki developed by Australian software company Atlassian.[4] Atlassian wrote Confluence in the Java programming language and first published it in 2004. Confluence Standalone comes with a built-in Tomcat web server and hsql database, and also supports other databases.[5]

The company markets Confluence as enterprise software, licensed as either on-premises software or software as a service running on AWS.[6][7] In 2025, Atlassian announced intentions to discontinue supporting on-premise deployments by 2029.[8]

History

[edit]

Atlassian released Confluence 1.0 on 25 March 2004, saying its purpose was to build "an application that was built to the requirements of an enterprise knowledge management system, without losing the essential, powerful simplicity of the wiki in the process."[9]

In recent versions, Confluence has evolved into part of an integrated collaboration platform[10] and has been adapted to work in conjunction with Jira and other Atlassian software products, including Bamboo, Clover, Crowd, Crucible, and Fisheye.[11]

In 2014, Atlassian released Confluence Data Center to add high availability with load balancing across nodes in a clustered setup.

Features

[edit]

The book Social Media Marketing for Dummies in 2007 considered Confluence an "emergent enterprise social software" that was "becoming an established player."[12] Wikis for Dummies described it as "one of the most popular wikis in corporate environments," "easy to set up and use," and "an exception to the rule" that wiki software search capabilities don't work well.[13]

In 2011, eWeek cited new features in version 4 such as auto-formatting and auto-complete, unified wiki and WYSIWYG, social network notifications and drag and drop integration of multimedia files.[14] Use cases include basic enterprise communication, collaboration workspaces for knowledge exchange, social networking, Personal Information Management and project management. The German newspaper Computerwoche from IDG Business Media compares it to Microsoft SharePoint and finds it "a good starting point" as a platform for social business collaboration, while SharePoint is better suited to companies with more structured processes.[15]

Confluence includes setting up CSS templates for styles and formatting for all pages, including those imported from Word documents. Built in search allows queries by date, the page's author, and content type such as graphics.

The tool has add-ons for integration with standard formats, with a flexible programmable API allowing expansion. The software is relevant as an outline tool for requirements that can be linked to tasks in the Jira issue tracker by the same company.[16]

Discontinuation of wiki markup

[edit]

As of version 4.0, in 2011,[17] Confluence ended support for wiki markup language.[18] This led to pushback by some previous versions' users who objected to the change.[19] In response, Atlassian provided a source code editor as a plugin, which allows advanced users the ability to edit the underlying XHTML-based document source.[20] The new source markup is XHTML-based, but it is not XHTML compliant.[21]

Additionally, wiki markup can be typed into the editor, and Confluence's autocomplete and auto-format function converts the wiki markup to the new format.[22] After the real-time conversion, content cannot be edited as wiki markup again.

Security

[edit]

Confluence Cloud data is encrypted in transit and at rest.[23] In June 2022, Atlassian disclosed a zero-day vulnerability in Confluence Server allowing remote code execution, which had been present for over a decade.[24]

In October 2023, Atlassian disclosed a critical broken access control vulnerability allowing exploitation remotely.[25]

See also

[edit]

References

[edit]
[edit]
Revisions and contributorsEdit on WikipediaRead on Wikipedia
from Grokipedia
Confluence is a web-based collaborative workspace software developed by Atlassian, designed to enable teams to create, organize, and share documentation, knowledge bases, and project information in a centralized platform.[1] It functions as a modern wiki system combined with features for real-time editing, content management, and integration with other tools, supporting remote and hybrid work environments by facilitating idea capture, brainstorming, and knowledge dissemination.[1] Originally released in 2004 as Confluence 1.0, the software was created to address the need for enterprise-grade team collaboration beyond simple email or file sharing, complementing Atlassian's earlier product, Jira, as a versatile content platform.[2] Over the years, Confluence has expanded significantly, with its first cloud version launched in 2011, allowing hosted deployment without on-premises infrastructure.[2] By 2025, it has become a cornerstone of Atlassian's ecosystem, recognized as a Leader in the Gartner Magic Quadrant for Collaborative Work Management due to its robust capabilities in team productivity tools.[1] Key features of Confluence include AI-powered assistance through Atlassian's Rovo for tasks like drafting content and intelligent search, alongside support for live documents, whiteboards, databases, embedded videos, and customizable templates to streamline workflows.[1] It integrates seamlessly with applications such as Jira for project tracking, Microsoft Teams for communication, Google Drive for file syncing, and Figma for design collaboration, enabling unified operations across diverse toolsets.[1] Primarily used for internal documentation, knowledge sharing, project planning, and onboarding, Confluence caters to organizations of all sizes, from startups to enterprises, by offering both cloud and data center deployment options.[1]

Overview

Description and Purpose

Confluence is a web-based corporate wiki software developed by Atlassian, designed primarily for creating, organizing, and sharing project documentation within teams.[1] It serves as a central platform where users can build and maintain structured content repositories, facilitating efficient knowledge capture and dissemination across organizations.[3] The core purpose of Confluence is to enable teams to construct internal knowledge bases, plan projects collaboratively, and engage in real-time documentation without relying on traditional email chains or fragmented tools.[1] By providing a unified workspace, it streamlines information flow, allowing contributors to co-edit content, attach files, and track changes seamlessly, thereby enhancing productivity and reducing miscommunication.[4] Key use cases include knowledge management for storing technical guides and policies, project wikis to centralize team insights and updates, onboarding guides to accelerate new hire integration, and support for development workflows through structured documentation of processes and requirements.[3] At a high level, Confluence is built as a Java-based application, deployable in various environments and accessible via web browsers, which supports a modular architecture centered on spaces, pages, and hierarchical content structures.[5] Spaces act as top-level containers for related content, pages form the individual units of information, and hierarchies enable nested organization for intuitive navigation and logical grouping.[6] This design promotes scalability for enterprise use while allowing brief integrations, such as with Atlassian's Jira for linking documentation to issue tracking.[1]

Development Background

Atlassian was founded in 2002 by university classmates Mike Cannon-Brookes and Scott Farquhar in Sydney, Australia, emerging as a bootstrapped startup amid the recovery from the dot-com bust. With an initial $10,000 drawn from credit cards, the duo focused on creating practical tools for software development teams, launching their flagship product Jira—an issue-tracking application—in the same year to streamline bug reporting and project management processes that had frustrated them in prior roles.[7][8] This self-reliant approach allowed Atlassian to prioritize product innovation over external dependencies, establishing a foundation in developer-centric software during a time when efficient collaboration tools were essential for lean, post-bust enterprises.[2] The motivation for Confluence stemmed from the need to address limitations in team documentation and knowledge sharing that Jira alone could not fully resolve, particularly in the post-dot-com landscape where remote and distributed teams required more flexible ways to capture and organize institutional knowledge.[8] Recognizing Jira's strength in task tracking but its shortfall in collaborative content creation, Cannon-Brookes and Farquhar envisioned Confluence as a complementary wiki platform to enable seamless integration, allowing users to link project details with shared documents for enhanced workflow efficiency.[7] This strategic extension aimed to foster a unified ecosystem for enterprise teams, transforming scattered notes into structured, accessible repositories that supported ongoing innovation without heavy administrative overhead.[8] Initial development of Confluence, released in 2004, centered on Java as the primary programming language to achieve cross-platform compatibility and leverage the robustness of the J2EE environment for web-based applications.[9] While influenced by the emerging open-source wiki movement—such as the concepts popularized by platforms like MediaWiki—the software was specifically tailored for enterprise collaboration, emphasizing scalability, user permissions, and integration with tools like Jira over pure community-driven models.[9] This design choice ensured Confluence could deploy reliably across diverse server setups, meeting the demands of professional teams seeking reliable, customizable documentation solutions.[2] Atlassian's early growth relied on self-funding, maintaining profitability from year one through a freemium model and direct online sales, with no venture capital until 2010 when it secured $60 million from Accel Partners to fuel international expansion and strategic acquisitions.[10] During this bootstrapped phase, Confluence solidified its role as a pivotal product in the company's portfolio, driving adoption by providing essential collaboration features that complemented Jira and broadened Atlassian's appeal beyond pure development tools.[8]

History

Founding and Early Years

Confluence was launched by Atlassian on March 25, 2004, with the release of version 1.0 as an on-premises software download targeted at small teams seeking a collaborative wiki solution.[9] Designed primarily for enterprise knowledge sharing, the initial version offered core functionalities such as creating and editing wiki pages, organizing content into dedicated spaces, and implementing basic permission controls to manage access.[11] These features enabled users to build structured documentation and foster team collaboration without requiring advanced technical expertise, positioning Confluence as a user-friendly alternative in the emerging wiki software landscape.[9] In its early years, Confluence experienced steady adoption, reaching integration with Atlassian's flagship product, Jira, from the outset to enhance agile workflows by linking project documentation directly to issue tracking.[12] By 2005, Atlassian had secured its 1,000th customer overall, reflecting growing interest in Confluence among development and IT teams.[2] This momentum continued into 2006, with the company reporting approximately 4,340 customers, many of whom adopted Confluence alongside Jira for streamlined content and project management.[13] Despite its progress, Confluence faced significant competition from open-source wikis like TWiki, which offered free alternatives with customizable features appealing to cost-conscious organizations.[14] To counter this, Atlassian emphasized enterprise-grade reliability and support, channeling sales efforts through a burgeoning reseller network that included early partners like Pix Software in Europe to expand reach into larger businesses. By 2009, these foundations paved the way for Confluence's initial shift to cloud hosting, broadening accessibility beyond on-premises installations.[2]

Key Milestones and Releases

Confluence 4.0, released on September 19, 2011, marked a pivotal shift in the software's editing paradigm by introducing a brand new rich text editor that simplified content creation and collaboration. This update ended native support for the dedicated wiki markup editor, replacing it with autoformatting capabilities that allowed users to input wiki-style shortcuts directly into the rich text interface for on-the-fly conversion to HTML. The changes aimed to reduce barriers for non-technical users while maintaining compatibility for advanced formatting needs.[15] Atlassian's push toward cloud deployment culminated with the launch of Confluence Cloud in 2010, enabling hosted access without on-premises infrastructure.[2] By 2015, following Atlassian's initial public offering, cloud deployments were growing rapidly but still represented a minority of installations, reflecting growing enterprise preference for scalable, managed hosting amid the company's expanding market reach.[16] This migration trend accelerated Confluence's evolution, with cloud revenue comprising a minority but rapidly growing share of overall sales at the time.[16] Subsequent major releases built on these foundations. Confluence 7.0, launched on September 10, 2019, enhanced mobile accessibility through improved responsive design and support tools, alongside backend optimizations like Synchrony data eviction for better collaborative editing performance.[17][15] In November 2022, Confluence 8.0 introduced platform-wide performance enhancements, including an upgrade to Java 17 and the Atlassian platform version 6, which streamlined resource usage and improved scalability for large instances.[15] More recently, Confluence 10.0, released in August 2025, incorporated critical framework updates such as Spring and Jakarta EE migrations to bolster security and modernity, while removing deprecated components including the Original theme, LESS support, and Trusted apps framework.[15] In February 2024, Atlassian ended support for Confluence Server, encouraging migrations to Data Center or Cloud deployments. In 2025, Atlassian announced the end-of-life for Confluence Data Center on March 28, 2029, signaling a strategic pivot to a cloud-only model that emphasizes seamless scalability and integrated AI capabilities.[18] This decision, coupled with new sales restrictions starting March 30, 2026, for Data Center licenses, underscores a focus on cloud-exclusive innovations like enhanced AI-driven content discovery and automation.[18] Security patches have been integral to these releases, addressing vulnerabilities such as CVE-2019-15006 in version 7.0 through targeted bug fixes.[17] Atlassian's acquisitions have further shaped Confluence's trajectory. The 2017 purchase of Trello for $425 million integrated card-based task management into Confluence's ecosystem, enabling hybrid workflows for project documentation and tracking. In 2024, the launch of the Rovo AI platform introduced generative AI tools like intelligent search and chat agents, directly influencing Confluence by embedding AI-assisted editing, summarization, and knowledge retrieval to streamline team collaboration.[19]

Core Features

Collaboration and Editing Tools

Confluence provides robust real-time collaborative editing capabilities, enabling multiple users to simultaneously edit a single page or blog post. This feature utilizes shared drafts and web socket synchronization via the Synchrony microservice, allowing changes to appear instantly for all participants. Live cursors, or telepointers, display the positions of other editors' cursors in the HTML WYSIWYG editor, facilitating awareness during concurrent sessions. Conflict resolution is managed through policies such as aborting publication if external changes occur outside the editor, ensuring data integrity.[4][20] Page creation in Confluence begins with the "Create" button or sidebar "+" icon, initiating a draft that autosaves progress visible only to the creator unless shared. Upon publishing, each update generates a new version, with full history tracking accessible via the "Version history" option to compare changes, view authors and timestamps, or rollback to previous versions by restoring them. Attachments can be uploaded directly to pages, supporting file versions and up to unlimited storage in premium plans, while inline and page-level comments allow threaded discussions with support for images, emojis, and likes to resolve feedback collaboratively.[21][4][22] Permissions in Confluence operate at three levels to control access: global permissions managed by site administrators for overall user capabilities; space permissions set by space admins to grant or revoke view, add, edit, and delete rights for users, groups, or anonymous visitors; and page-level restrictions that further limit viewing or editing to specific individuals or groups. Anonymous access is configurable at the space level for public viewing without login, though editing requires authentication. These controls ensure secure collaboration by preventing unauthorized modifications while allowing flexible team interactions.[23][24] Templates and macros streamline content creation and enhance interactivity in Confluence. Pre-built templates, such as those for meeting notes, project roadmaps, or product requirements, provide structured starting points with placeholders for team input, promoting consistency across collaborative documents. Macros extend page functionality; for instance, the Team Calendar macro embeds event calendars from integrated sources, displaying schedules directly on pages for shared planning, while the Task Report macro lists and filters tasks by assignee, label, or date to track progress in real time. These tools integrate briefly with external applications like Jira for dynamic updates, but their core value lies in embedding collaborative elements within Confluence pages.[25]

Content Organization and Management

Confluence organizes content through spaces, which serve as top-level containers for grouping related pages, blog posts, and attachments into hierarchical structures resembling folders. Each space functions as a dedicated workspace, allowing teams to maintain distinct areas for projects, departments, or topics, with pages arranged in a tree-like hierarchy where child pages nest under parents for intuitive navigation.[26] Space administrators can customize permissions, themes, and layouts to enforce organization and access control within these hierarchies.[27] To enhance navigation, Confluence employs labels as flexible tags that users apply to pages and attachments, enabling cross-space categorization and quick retrieval of related content. Labels support both predefined and custom terms, facilitating dynamic grouping beyond rigid hierarchies.[28] Archiving removes outdated or inactive pages from active view and search results while preserving their history, comments, and attachments; archived items remain accessible via a dedicated space archive for reference or restoration.[29] Content discovery in Confluence relies on a robust full-text search engine that indexes pages, blogs, and attachments, allowing users to query across the entire site or filter results by space, creation/modification date, content type, creator, or labels. Advanced search syntax supports operators like "AND," "OR," and field-specific filters (e.g., "title:project plan") to refine queries precisely.[30] Additionally, the platform suggests related pages on individual content views, drawing from internal links, shared labels, and semantic similarities to surface contextual information and promote knowledge connections.[31] For preservation and compliance, Confluence supports exporting spaces or individual pages to formats such as PDF, Microsoft Word, HTML, or XML, enabling offline access or migration while retaining structure and embedded media where possible. Space backups generate complete XML archives of content, including pages, attachments, and permissions, which can be scheduled or performed manually for recovery purposes.[32][33] Audit logs track all user actions, such as page creations, edits, and permission changes, with exportable reports for regulatory compliance and troubleshooting.[34] Analytics tools in Confluence provide metrics to evaluate content effectiveness, including page view counts, estimated read times, and contributor activity statistics like edit frequency and authorship distribution. Space-level insights aggregate usage data, such as total views, active users, and content health indicators (e.g., outdated pages or low-engagement sections), helping administrators identify high-impact areas and optimize organization.[35][36] Whiteboard integration offers a visual layer for diagramming ideas within spaces, complementing hierarchical organization with interactive canvases.[37]

Templates

Confluence provides page templates to help users create structured content quickly and consistently. Templates can be custom-created or use pre-built ones from Atlassian. There are four main categories of page templates:
  • Space templates: Available only within a specific space. Space administrators can create and manage them for team-specific needs.
  • Global page templates: Available across all spaces on the site. Only Confluence administrators can create or edit them for organization-wide consistency.
  • Blueprints: Predefined templates with added functionality (e.g., wizards, macros) to create, manage, and organize content. A collection ships with Confluence, and more can come from Atlassian or third-party developers.
  • System templates: Built-in templates for core elements like site welcome messages or default space homepages (primarily in Data Center/Server versions).
In Confluence Cloud, the distinction emphasizes space and global templates, with blueprints as enhanced templates. Atlassian offers a library of over 70 pre-built templates (more via Marketplace), organized into categories such as:
  • Project management (e.g., project plan, Kanban board, retrospective)
  • Product management (e.g., product requirements, roadmap)
  • Strategic planning (e.g., strategic planning, OKRs)
  • Design (e.g., design system, flowchart, concept map)
  • Software development & IT
  • Human resources & employee development
  • Documentation & reporting
  • Templates for remote workers
These include placeholders, macros, and variables for easy customization. Users access them when creating pages, filtering by category or searching. Templates streamline repetitive tasks like meeting notes, reports, and planning, ensuring uniform structure across teams. Page templates documentation Confluence templates library

Advanced Functionality

Integrations and Extensibility

Confluence provides native integrations with other Atlassian products to streamline workflows across tools. It seamlessly links with Jira for issue tracking, allowing users to embed Jira tickets and issues directly into Confluence pages for contextual documentation and real-time updates. This integration enables teams to reference project progress without switching applications, fostering better alignment between planning and execution. Similarly, Confluence supports imports of Trello boards, permitting users to embed visual representations of tasks and workflows into pages to enhance project visibility and collaboration. The Atlassian Marketplace extends Confluence's functionality through over 1,000 third-party add-ons tailored for Cloud deployments. These apps facilitate connections to external services, such as sending notifications to Slack channels for page updates, comments, or mentions, which keeps distributed teams informed in their preferred communication platform. Another common example is embedding Google Drive files, including documents, sheets, and videos, directly into Confluence pages via dedicated macros, enabling seamless access to shared resources without leaving the workspace. For deeper customization, Confluence exposes REST APIs that developers can use to build custom scripts and integrations with external systems, supporting operations like content creation, retrieval, and modification programmatically. Complementing this, Confluence's built-in automation rules allow administrators to define workflows triggered by events, such as auto-archiving outdated pages or notifying users of content changes, reducing manual oversight and improving content governance. Confluence's extensibility model is evolving to prioritize security and scalability. The Trusted Apps framework, which granted select plugins elevated access to instance resources, ceased support starting with version 10.0, released in August 2025. In its place, Atlassian encourages adoption of Forge, a serverless platform for developing secure, cloud-native extensions that integrate with Confluence without requiring broad permissions.

AI and Emerging Capabilities

In 2024, Atlassian introduced Rovo AI as a core integration within Confluence, enabling features such as content summarization, automated generation of pages and comments, and smart search capabilities that contextualize results across dispersed information sources.[19] Rovo AI leverages natural language processing to assist users in tasks like extracting key insights from long documents or brainstorming outlines, thereby streamlining knowledge management in team workspaces.[38] Building on this, 2025 updates expanded AI functionalities to Confluence whiteboards, introducing tools for idea mapping such as generating similar concepts from existing sticky notes, clustering related content, and summarizing entire boards into actionable overviews.[39] These enhancements, including the "Smart Create" feature, allow users to prompt AI for diagrams, cards, or visual structures directly on the canvas, fostering more dynamic ideation sessions.[40] Confluence whiteboards provide unlimited collaborative spaces in Premium and Enterprise plans, supporting real-time brainstorming with elements like sticky notes, shapes, stamps, and freehand drawing tools.[41] Teams can export whiteboard content directly to Confluence pages, converting visual drafts into structured documentation while maintaining version history and permissions.[42] Automation in Confluence includes rule-based triggers for notifications, such as alerting users on page updates or space changes, configurable via a low-code interface.[43] AI enhancements, powered by Atlassian Intelligence, enable natural language rule creation and generate insights like automated summaries or action items from content analytics, aiding in content recommendations based on usage patterns.[44] Atlassian's cloud roadmap outlines improvements for Q4 2025, including AI-generated diagrams from discussions in Confluence whiteboards using Rovo.[45]

Editing Evolution

Transition from Wiki Markup

Prior to the release of Confluence 4.0, wiki markup served as the primary syntax for formatting content since the software's initial launch in 2003, allowing users to apply styles through simple text-based codes such as text for bold or text for italics. This approach enabled precise control over page structure and was particularly favored by technical users for its similarity to lightweight markup languages.[46] In September 2011, with Confluence 4.0, Atlassian shifted content storage from wiki markup to an XHTML-based format and introduced a rich text editor (RTE) to provide a WYSIWYG editing experience, aiming to streamline content creation.[46] To facilitate the upgrade, an automated migration tool converted existing wiki markup pages to the new XHTML format during installation from Confluence 3.5 or later, though manual intervention was sometimes required for complex macros or templates.[47] Atlassian justified the change by emphasizing enhanced usability for non-technical users, elimination of inconsistencies between the dual markup and visual editors—which had been the top barrier to improvements—and reduced long-term maintenance burdens on the development team.[48] The transition sparked significant backlash from power users accustomed to code-based editing, who argued that the RTE lacked the precision and flexibility of wiki markup for advanced formatting and scripting tasks.[49] This led to community demands for restoration, as evidenced by JIRA issue CONFSERVER-23818.[49] In response, third-party developer Bob Swift released the Wiki Markup Addon, a free plugin that enabled insertion and editing of wiki markup within dedicated macros, allowing partial preservation of the old syntax amid the new system.[50] Although the wiki markup editor was fully deprecated, limited support persisted through macro-based insertions and ongoing migration utilities.[47]

Current Editing Interfaces

Confluence's primary editing interface is the visual editor, a rich text environment (RTE) that serves as the default for creating and modifying pages, blogs, and live documents. This editor emphasizes intuitive interaction through drag-and-drop functionality for rearranging elements such as text blocks, images, tables, and layouts. Inline formatting options enable users to apply styles like bold, italics, headings, and lists directly within the text flow, while slash commands—activated by typing "/"—provide quick access to inserts including code blocks, mentions, emojis, and macros, supported by autocomplete suggestions for streamlined workflows.[51] The visual editor also facilitates real-time collaboration, where multiple users can edit simultaneously with live updates visible to all participants.[52] Complementing the visual mode, Confluence integrates markdown support directly into the editor, allowing users to input common markdown syntax that converts on-the-fly to formatted content without needing a separate source view. Key markdown commands include bold for emphasis, italics for subtle styling, # for headings (up to ###### for level 6), - or * for bulleted lists, 1. for numbered lists, > for blockquotes, code for inline snippets, and ```language for delimited code blocks, all rendering seamlessly in the visual interface.[53] Keyboard shortcuts enhance productivity, such as Ctrl+B (or Cmd+B on Mac) for bold and Ctrl+K for links, with full lists accessible via the help menu. While a native toggle to a pure HTML or markdown source editor is not built-in, users can insert markup via the "+" menu for advanced formatting, and third-party apps from the Atlassian Marketplace extend capabilities with code-like editing environments featuring syntax highlighting and validation.[51][54] This hybrid approach maintains compatibility with legacy macros, which can be embedded using slash commands or the macro browser, ensuring remnants of older content formats integrate without disruption.[52] Accessibility is a core consideration in the editing interfaces, aligning with WCAG 2.1 AA standards through features like alt text for images, semantic HTML output for screen reader compatibility, and keyboard-navigable controls.[55] The Confluence mobile app extends editing to iOS and Android devices, supporting touch-based interactions for on-the-go modifications while preserving visual fidelity. Internationalization supports over 20 languages, with right-to-left text rendering for scripts like Arabic and Hebrew, enabling global teams to collaborate effectively in their preferred locales.[55]

Deployment Options

Hosting Models

Confluence offers two primary hosting models: Cloud, which is managed by Atlassian, and self-hosted options through Server and Data Center editions, though the latter are being phased out.[56] The Cloud edition is hosted by Atlassian on Amazon Web Services (AWS), providing a fully managed infrastructure that handles server maintenance, backups, and disaster recovery.[57] This model includes automatic updates to the latest features and security patches without user intervention, ensuring continuous access to innovations such as AI-powered tools and enhanced collaboration features.[56] Scalability is inherent, with automatic resource allocation to support growing teams, and it comes with premium support from Atlassian, including 24/7 assistance for enterprise users.[56] In contrast, the Server and Data Center editions allow self-hosting on-premises or in a private cloud for greater control over data location and customization.[56] Confluence Server is designed for single-node deployments suitable for smaller organizations, while Data Center supports clustered, high-availability setups for large-scale enterprises, enabling load balancing across multiple nodes to handle thousands of concurrent users.[56] However, Server reached end of support on February 15, 2024, meaning no further updates, bug fixes, or security patches are available, leaving instances vulnerable if not migrated.[58] Data Center support will continue until March 28, 2029, after which subscriptions expire and sites become read-only, with technical support winding down from March 30, 2026. New Data Center license sales to new customers end on March 30, 2026, and to existing customers on March 30, 2028.[59] Atlassian provides migration tools and paths to transition from Server or Data Center to Cloud, including automated data export/import utilities and compatibility assessments to minimize downtime.[60] For Data Center users, 2025 incentives include discounted cloud subscriptions—up to 75% off for eligible enterprise customers—and free migration assistance programs like Atlassian Ascend, which offer expert guidance and resources to facilitate the shift.[61] These efforts aim to ease the move to Cloud, where security features like automated compliance monitoring differ from the self-managed protections in on-premises models.[56] Licensing for the Cloud edition is subscription-based, using a progressive per-user model billed monthly, with tiers such as Free (up to 10 users), Standard ($6.05/user/month as of November 2025), Premium ($11.25/user/month as of November 2025), and Enterprise (custom pricing for advanced needs).[41] Legacy Server licenses were perpetual, allowing indefinite use after initial purchase, but new Server sales ended prior to the 2024 support cutoff, and maintenance renewals are no longer available.[58] Data Center follows a subscription model similar to Cloud but tied to annual renewals until its 2029 end-of-life.[62]

System Requirements and Architecture

Confluence is developed using Java, requiring JDK 17 or later, with recent versions bundling Eclipse Temurin OpenJDK 21 for compatibility and security.[63] It leverages the Spring Framework for core functionalities such as dependency injection and web services, including upgrades to Spring 6.x in version 10.0 to address security and maintenance needs.[64] For data persistence, Confluence supports relational databases including PostgreSQL (versions 12, 13, 14, 16, and 17), MySQL (8.0 and later), and Oracle Database (19c and later), with Amazon Aurora and Azure PostgreSQL available exclusively for Data Center editions.[63] The architecture of Confluence is built on Apache Tomcat as the servlet container, with bundled versions such as Tomcat 9.0.76 in Confluence 8.5 and updates to 10.x in later releases for enhanced stability. It employs a modular design through its plugin system, allowing extensions via the Atlassian Plugin Framework (APF) for custom functionalities without altering the core codebase.[5] Scalability is achieved in Confluence Data Center through clustering, where multiple nodes share a load-balanced setup with synchronized indexes and a shared home directory to handle high availability and increased user loads.[65] Minimum system requirements for Confluence Server or Data Center include at least 8 GB of RAM for small instances serving up to 100 users, scaling to 64 GB or more for large deployments exceeding 5,000 users to ensure performance under heavy load.[66] CPU recommendations start with a quad-core 2 GHz processor, alongside sufficient disk space (minimum 10 GB for the database). Client-side, Confluence supports the latest stable versions of Google Chrome, Mozilla Firefox, Microsoft Edge, and Safari, with a minimum resolution of 1024x768 for optimal rendering.[63] In 2025, Confluence version 10.0 introduced a migration to Jakarta EE 10, replacing the deprecated javax namespace to align with modern enterprise standards and mitigate compatibility issues in future Java ecosystems.[67] Concurrently, support for LESS CSS preprocessing ended, requiring developers to shift to build-time CSS compilation or native CSS for styling plugins and themes to improve security and performance.[68]

Security

Built-in Protections

Confluence provides robust authentication mechanisms to secure user access, including support for OAuth 2.0 for API integrations and SAML 2.0 for single sign-on (SSO) with identity providers like Microsoft Entra ID.[69][70] These features enable seamless integration with external authentication systems, reducing the need for separate credentials. Authorization is enforced through granular role-based access controls at global, space, and page levels, allowing administrators to define permissions for viewing, editing, and administering content based on user groups or individuals. Data protections in Confluence include secure password storage using bcrypt hashing via integration with Atlassian Crowd for authentication, which resists brute-force attacks through its adaptive work factor.[71] Attachments and stored data are encrypted at rest with AES-256, while data in transit uses TLS 1.2 or higher with perfect forward secrecy to prevent interception.[72] To mitigate common web vulnerabilities, Confluence employs input sanitization and validation techniques that render it highly resistant to SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF) attacks, including origin header checks for REST API requests.[73][74] For audit and compliance, Confluence maintains detailed logging of user actions, such as page edits, permission changes, and login events, accessible via the administration interface to track modifications and support forensic analysis.[75] In the Cloud version, it supports GDPR compliance through data processing agreements and privacy controls, as well as HIPAA via business associate agreements (BAAs) and security assessments for handling protected health information.[76][77] In 2025, Confluence Cloud introduced enhanced security controls, including IP allowlisting to restrict access to specified networks and integration with Atlassian Guard for advanced threat detection, such as data loss prevention (DLP) and automated alerts on suspicious activities.[78][79] These features build on existing protections to address evolving threats without compromising usability.

Notable Vulnerabilities and Responses

One of the most significant security incidents involving Confluence occurred in June 2022 with CVE-2022-26134, a critical unauthenticated remote code execution (RCE) vulnerability stemming from an OGNL injection flaw in Confluence Server and Data Center versions from 6.0 up to but not including 7.19.1, 7.18.1, 7.17.4, 7.16.4, 7.15.2, 7.14.3, and 7.13.7.[80][81] This zero-day vulnerability was actively exploited by malicious cyber actors shortly after its discovery, enabling arbitrary code execution on affected instances without authentication, often for deploying web shells, cryptocurrency miners, or further malware.[82][83] Exploitation was widespread, with security firms reporting spikes in attacks targeting thousands of exposed instances globally.[84] Atlassian responded swiftly by issuing a security advisory on June 2, 2022, and releasing patches within days, urging immediate upgrades or mitigations such as JAR file replacements.[80] Other notable vulnerabilities include the 2021 OGNL injection flaws, such as CVE-2021-26084, which allowed unauthenticated attackers to execute arbitrary code on Confluence Server and Data Center instances through Webwork module exploitation and was actively targeted in the wild.[85][86] In 2022, the "Questions for Confluence" plugin introduced CVE-2022-26138, where hardcoded credentials for a "disabledsystemuser" account granted unauthorized access to the confluence-users group, enabling viewing and editing of content; this affected plugin versions up to 3.0.1 and was patched via app updates.[87][88] In 2023, multiple critical vulnerabilities affected Confluence Data Center and Server. CVE-2023-22515, a broken access control flaw (CVSS 9.8), allowed unauthenticated attackers to create unauthorized administrator accounts on publicly accessible instances (versions 6.0-8.0.3, 8.1.0-8.1.3, 8.2.0-8.2.3, 8.3.0-8.3.2, 8.4.0-8.4.5, 8.5.0-8.5.1); it was added to CISA's Known Exploited Vulnerabilities Catalog due to active exploitation.[89][90] Atlassian issued patches in October 2023. Similarly, CVE-2023-22527, a server-side template injection (SSTI) vulnerability (CVSS 10.0) in versions up to 8.5.5, enabled unauthenticated RCE and was exploited for cryptocurrency mining and remote access; patches were released in January 2024, with ongoing exploitation reported into 2025.[91][92] Other 2023 issues included CVE-2023-22518 (improper authorization for instance reset) and CVE-2023-22522 (RCE via template injection).[93][94] In 2024 and 2025, exploitation of prior flaws like CVE-2023-22527 continued, with attacks enabling RDP access and RCE on exposed servers as of May 2025.[95] Atlassian patched additional critical unauthenticated RCE vulnerabilities in February 2025, including CVE-2024-50379 and CVE-2024-56337 (CVSS 9.8) affecting Confluence Data Center and Server.[96] Security bulletins in 2025 addressed further high-severity issues.[97] Atlassian's response protocols emphasize rapid disclosure for zero-days, as seen with CVE-2022-26134, where notifications and patches were provided within 24-48 hours of awareness.[98] They enforce mandatory patching timelines through their bug fix policy, prioritizing critical vulnerabilities for resolution within 90 days, though zero-days receive expedited treatment.[99] In 2025, Atlassian enhanced its vulnerability management with a greater focus on automated scanning tools during development, app onboarding, and post-deployment monitoring to proactively identify and mitigate risks.[100][101] The impact of these issues was substantial, with Atlassian disclosing over 20 CVEs across its products in 2022 alone, several critical and specific to Confluence, contributing to its inclusion in CISA's Known Exploited Vulnerabilities Catalog.[102][103] This has accelerated a shift toward Confluence Cloud, where Atlassian handles patching and security updates, reducing the risks associated with self-hosted Data Center and Server deployments, especially as Server support ended in 2024 and Data Center support is set to conclude in 2029.[104]

Adoption and Impact

Usage and Market Position

Confluence has achieved widespread adoption as a key tool for team collaboration and knowledge management. As of 2025, Atlassian reports over 300,000 customers globally using its suite of products, with Confluence serving as a central component for documentation and information sharing among a significant portion of these organizations. Atlassian products, including Confluence, are used by more than 80% of Fortune 500 companies.[2][105] This extensive user base underscores Confluence's role in enabling structured knowledge repositories across enterprises. In the market landscape, Confluence holds a leading position in the collaborative work management and enterprise wiki software segments. Atlassian was recognized as a Leader in the 2025 Gartner Magic Quadrant for Collaborative Work Management Tools, highlighting Confluence's strengths in integrating with tools like Jira to support agile workflows.[106] Within knowledge management, it commands approximately 2.3% market share, positioning it ahead of many competitors in enterprise settings, particularly when bundled as part of the Atlassian Intelligence suite that enhances AI-driven productivity across Jira and Confluence.[107][108] Notable case studies illustrate Confluence's practical impact. NASA employs Atlassian products, including Confluence, for project documentation and team coordination in complex engineering initiatives, leveraging its scalability for large-scale collaboration.[109][110] Similarly, Coca-Cola uses Atlassian products, including Confluence, to centralize knowledge sharing and streamline internal processes, contributing to efficient global operations.[110] Adoption surged following the 2020 shift to remote work, as organizations sought robust platforms for distributed teams, with Atlassian's cloud offerings like Confluence seeing accelerated growth amid hybrid work models.[111] In the competitive arena, Confluence differentiates itself from alternatives like Notion, which caters more to consumer and small-team use with its flexible, all-in-one workspace, and SharePoint, which thrives within the Microsoft ecosystem for document-heavy enterprise intranets.[112] Confluence's particular strength lies in development teams, where its seamless integration with Jira facilitates agile planning, issue tracking, and real-time documentation updates.[113]

Criticisms and Limitations

Confluence has faced criticism for performance issues, particularly slow loading times in large spaces and indexing delays in on-premises installations. In large-scale deployments, pages with extensive content or numerous attachments can experience significant delays, prompting users to employ performance tuning measures such as cache optimization to mitigate database load and improve response times.[114] On-premises setups often encounter indexing lags during content processing, which can exacerbate slowdowns when creating or updating spaces with high volumes of data.[115] Additionally, complex pages with many macros contribute to degraded performance, as excessive macro rendering can exceed time limits and cause editor freezes or prolonged load times.[116] Usability critiques of Confluence highlight a steep learning curve, especially for non-technical users unfamiliar with Atlassian ecosystems, due to unintuitive interfaces and complex setup options for spaces and hierarchies.[117] The platform's heavy reliance on macros for advanced functionality often leads to page bloat, resulting in cluttered content and maintenance challenges as users accumulate nested or outdated macros without streamlined cleanup tools.[118] Cost concerns have been raised regarding Confluence's premium cloud pricing, with the Standard plan starting at $5.42 per user per month and the Premium plan at $10.44 per user per month (billed annually), which can accumulate significantly for large teams.[41] Migrations from Server or Data Center editions to Cloud involve additional expenses for data transfer, reconfiguration, and potential add-ons, further straining budgets for organizations transitioning away from self-hosted models.[119] Other limitations include minimal offline support, as Confluence lacks a native offline client, requiring constant internet connectivity for editing and access, which hinders productivity in disconnected environments. The announced discontinuation of Data Center support by March 28, 2029—following the end of new sales to new customers in March 2026 and to existing customers in March 2028—has drawn criticism for forcing migrations to Cloud, raising concerns about vendor lock-in as users face compatibility issues with custom integrations and data portability.[18]

References

User Avatar
No comments yet.