Building a Forge app brings with it new capabilities and responsibilities beyond those set out in the Cloud shared responsibility model.
For example, Forge apps can choose to implement one or more of the following capabilities, which change the division of security responsibilities between you and Atlassian.
Custom UI, which lets you define app user interfaces using static resources, such as HTML, CSS, JavaScript, and images.
UI kit, which lets you build intuitive and familiar app user interfaces by composing built-in Atlassian components.
Web triggers, which is a mechanism to invoke Forge applications through incoming HTTP calls.
This page is intended to help you understand your responsibilities when building and supporting a Forge app, and what responsibilities Atlassian takes care of. Also make sure you have read and are adhering to the Developer terms and Marketplace partner agreement.
The following matrix covers front-end and invocation capabilities (Custom UI, UI kit, and web triggers). Responsibilities that vary by runtime execution environment are described in Runtime execution environments and the sections below the matrix.
| Responsibility | Custom UI | UI kit | Web triggers |
|---|---|---|---|
| App elements | |||
| Authentication of requests to the app | Atlassian | Atlassian | You |
| Authorization of requests to the app | Atlassian & You | Atlassian & You | You |
| Input validation and output encoding | You | Atlassian & You | You |
| Application logic | You | You | You |
| Application framework | Atlassian & You | Atlassian | Atlassian |
| Data storage | Atlassian & You | Atlassian & You | Atlassian & You |
| Software development lifecycle (SDLC) activities | Atlassian & You | Atlassian & You | Atlassian & You |
| Deployment artifacts | Atlassian | Atlassian | Atlassian |
| Tenant safety | Atlassian & You | Atlassian & You | Atlassian & You |
| Operational elements | |||
| Logging | Atlassian & You | Atlassian & You | Atlassian & You |
| Monitoring and alerting | Atlassian | Atlassian | Atlassian |
| Network security | Atlassian | Atlassian | Atlassian |
| Runtime/Server security | Atlassian | Atlassian | Atlassian |
| Vulnerability management and disclosure | Atlassian & You | Atlassian & You | Atlassian & You |
| Bug bounty | Atlassian & You | Atlassian & You | Atlassian & You |
| Security incident response | Atlassian & You | Atlassian & You | Atlassian & You |
| Disaster recovery | Atlassian & You | Atlassian & You | Atlassian & You |
| Security features | |||
| User identity and access management | Atlassian | Atlassian | Atlassian |
| DoS protection | Atlassian | Atlassian | Atlassian |
| Abuse prevention | Atlassian & You | Atlassian & You | Atlassian & You |
The division of responsibilities also depends on where your app's back end runs. A Forge app can execute its back-end logic in one or more of the following runtime execution environments, and the responsibilities shift depending on who supplies the runtime and where it executes.
Forge Functions, which run your back-end code on Atlassian-managed serverless compute. Atlassian supplies and operates the runtime.
Forge Remote, which lets your app invoke back-end services that you host on your own infrastructure. You supply and operate the runtime.
Forge Container services, which run a container image you build on Atlassian-hosted compute. You supply the image; Atlassian supplies and operates the runtime that executes it.
Because Forge Container services introduce a runtime where you supply the executable image but Atlassian hosts it, some responsibilities that are wholly Atlassian's for Forge Functions become shared. These differences are called out in the relevant sections below. Forge Container services are a Runs on Atlassian capability, so they inherit the Runs on Atlassian responsibilities described throughout this page.
Ensure that every request made to the application is sufficiently authenticated.
Your responsibilities:
Atlassian's responsibilities:
Ensure that every request made to the application is sufficiently authorized.
Your responsibilities
asUser() whenever you are performing an operation on behalf
of a user. This ensures your app has at most the permissions of
the calling user.asApp(), you must verify expected permissions
(for example, from Atlassian app context) with the permissions REST APIs
before making the request.Atlassian's responsibilities
Ensure sufficient input validation and output encoding is applied within the application.
Your responsibilities
Atlassian's responsibilities:
Your responsibilities
Ensure the framework used to build apps is free of security bugs, and fixes are delivered in line with Atlassian's security bug fix policy SLOs.
Your responsibilities:
Atlassian's responsibilities
Ensure that data is appropriately stored and read by your app.
Your responsibilities
Ensure that sensitive security data, such as pre-shared keys, API keys, or
encryption keys are not hardcoded in the source code. Secure storage,
such as encrypted environment variables, should be used to supply keys
at runtime. For Forge Container services, supply secrets as
encrypted environment variables at deployment time (using forge variables set), or through the
Forge KVS secret store at runtime. Never bake
secrets into a container image.
Ensure that keys are rotated on a regular basis. You should rotate sensitive API keys at least every 90 days.
Ensure that authorisation controls exist to segregate data access between different user roles within the same tenant.
Define and implement app-level data retention and deletion timelines.
Forge hosted storage capabilities already have a pre-defined data lifecycle.
Do not use container instances as a persistence mechanism. For example, do not run your own database inside a Forge container service. Container instances are stateless and ephemeral, so they provide no durable persistence. Data held inside a container is also outside Forge's data-residency controls and cannot participate in data-residency migrations. Persist data instead in Forge hosted storage or a remote data store that you operate, so it remains durable and consistent with your app's data residency and lifecycle commitments.
Atlassian's responsibilities
Apply secure software development practices when building and maintaining your app.
Your responsibilities
forge lint or forge deploy), and rebuild images
at least every 180 days to avoid stale base layers. See the
container image security guidelines.The deployment artifact is the packaged unit that Forge runs when your app is deployed. For most Forge apps, the artifact is your back-end source code, which Atlassian bundles and validates. When you supply your own pre-built artifact, some of this responsibility becomes shared.
Atlassian's responsibilities
Your responsibilities
UID 1000, GID 1000), and keep images free of embedded secrets. See the
container image security guidelines for
the full mandatory requirements and recommendations.forge lint or forge deploy, so an image that fails to start will fail its deployment at runtime.Developers and Atlassian are jointly responsible for tenant safety. Your responsibilities depend on the runtime execution environment your app uses.
Your responsibilities
For all runtime execution environments:
cloudId. Do
not use identifiers that are not globally unique (such as Jira issue keys) as global cache keys,
because the same key can exist in multiple tenants' instances.For Forge Functions:
Atlassian's responsibilities
A common source of cross-tenant data leaks is module-level caching — a standard Node.js pattern that is unsafe in Forge's shared runtime environment. See Tenant data isolation in Forge apps for safe and unsafe code examples, and an audit checklist for your app.
With the legacy runtime, Atlassian was responsible for tenant isolation. An app installed on tenant A could not communicate with an app installed on tenant B.
When listing your app on the Atlassian Marketplace with data residency support, ensure that you are correctly declaring your app’s eligibility and data collection policy.
Your responsibilities
Accurately define, document, and communicate what data is in-scope for data residency in your app listing’s Privacy and Security tab. See In-Scope End-User Data for more information.
If your app uses any remote back ends, declare them in your manifest file with the properties matching their purpose. See Remotes for more information.
Your responsibilities
x-forge-invocation-log-attributes value to structured logs under a forge_invocation key to keep
logs filterable per invocation. See the
container services logging reference.Atlassian's responsibilities
Atlassian's responsibilities
Atlassian's responsibilities
Your responsibilities
permissions.external). Use explicit domains.
*) are strongly discouraged.http://) for sensitive operations.For Forge Functions, the runtime and its contents are wholly Atlassian's responsibility. For Forge Container services, Atlassian operates and hardens the hosting runtime, but you supply and are responsible for the contents and behavior of the container process that runs inside it.
Atlassian's responsibilities
Your responsibilities
UID 1000, GID 1000);
root-owned processes will fail to deploy.SIGTERM signal so your process shuts down gracefully within the termination grace
period, and ensure your process runs as PID 1 (for example, by using exec in an entrypoint
script) so it receives the signal directly. See
Managing a service: Termination behavior.Your responsibilities
Atlassian's responsibilities
Your responsibilities
Atlassian's responsibilities
Effective security incident response is a collaborative effort. You're responsible for promptly reporting incidents to Atlassian, keeping your security contacts up to date, acknowledging Atlassian's notifications, and containing incidents on your side. Atlassian provides triage and investigative support, ranging from asynchronous guidance to real-time joint collaboration where required.
Your responsibilities
Atlassian's responsibilities
Responsibilities per hosting model
Incident response responsibilities depend on where your app runs. When your app runs entirely on our platform, Atlassian can fully support investigation, containment, and log sharing while you remediate your app and notify customers. For any components of your app that are hosted outside the Atlassian Platform (such as Forge Remote and Connect on Forge modules), you are responsible for detection, containment, and recovery on your infrastructure, while Atlassian provides platform-side investigative support and coordinates the joint response where required.
It is your responsibility to notify customers of incidents involving your app. For incidents originating from the Atlassian platform, Atlassian will coordinate with you on next steps.
| Responsibility | Detect | Contain | Fix | Notify Customers |
|---|---|---|---|---|
| Runs on Atlassian | Atlassian & You | Atlassian & You | You | You |
| Forge Remote | You | You | You | You |
| Connect on Forge | You | You | You | You |
Your responsibilities
forge deploy. This differs from Forge Functions, which Atlassian
restores without developer involvement.Atlassian's responsibilities
Atlassian's responsibilities
Your responsibilities
Atlassian's responsibilities
Your responsibilities
Your responsibilities
Atlassian's responsibilities
Rate this page: