Confluence
Let Agent SRE read your runbooks and postmortems during investigations
Connecting Confluence to Agent SRE
Connect a Confluence site and Agent SRE searches it for runbooks and postmortems about the affected service at the start of every investigation, before it forms hypotheses, and cites the pages it used in the report. In chat, it reads Confluence when a question is better answered by your team's own documentation than by telemetry alone.
Both Atlassian Cloud and self-hosted Data Center are supported. One organisation can connect several sites; each is its own account under the Confluence tile.
Read-only: Agent SRE only searches and reads. Nothing is written to Confluence, and nothing is copied to KubeSense servers: pages are read at investigation time, and only their titles and links are kept in the report.
Prerequisites
Choose one of three ways to connect. The service account is the one to prefer for a long-lived connection.
Atlassian Cloud service account (recommended)
- Create a service account at admin.atlassian.com → Directory → Service accounts. Every organisation includes five at no cost. Give it product access to Confluence only.
- Create an API token for that service account with read-only scopes:
read:confluence-content.all,read:confluence-space.summary,read:confluence-user,search:confluence. - Allow outbound HTTPS from the KubeSense API service to
api.atlassian.comand to your Atlassian site. Service account tokens are only accepted through Atlassian's API gateway, so both hosts are needed. If Atlassian IP allow-listing is on, add the service's egress IP.
Atlassian Cloud (personal token)
- Create an API token at id.atlassian.com → Security → API tokens, signed in as the account Agent SRE will use.
- This token is tied to that person and stops working when they leave.
- Allow outbound HTTPS from the KubeSense API service to your Atlassian site.
Self-hosted (Data Center)
- Data Center has no service accounts. Create a dedicated user for KubeSense, not a person's account, so the token outlives staff changes, and give it read access to the spaces or projects the agent should see.
- Signed in as that user, create a personal access token under profile → Personal Access Tokens.
- The KubeSense API service must be able to resolve and reach the server. A private address needs
INTEGRATIONS_HTTP_ALLOW_PRIVATE_NETWORKS=trueon the API service; the default refuses private ranges.
Connecting
- Open Integrations and find Confluence under the Integrations section. Click Connect.
- Choose how Confluence is hosted: Atlassian Cloud service account, Atlassian Cloud (personal token), or Self-hosted (Data Center).
- Fill in the form:
| Field | Service account | Personal token | Data Center |
|---|---|---|---|
| Name | A label, e.g. Engineering wiki. Shown on the tile and in citations. | Same | Same |
| Site URL / Server URL | https://acme.atlassian.net | https://acme.atlassian.net | https://confluence.acme.internal |
| Atlassian account email | — | The account the token belongs to | — |
| Token | Service account API token | API token | Personal access token |
Tokens are stored encrypted and never shown again after you save.
- Click Test connection. A successful test shows the account the token resolved to and how many spaces it can see.
- Click Save and enable.
The connection is refused if the test fails, so a saved connection always worked at least once.
Managing connections
Clicking the Confluence tile opens the accounts page: every connected site on the left, the selected one on the right. From there you can pause a connection without removing it, re-run the connection test, rotate the token (leave the token blank on edit to keep the stored one), or remove it.
The tile also shows a Capabilities panel: what KubeSense does with this integration, listed by the release that added it, newest first. It appears at the bottom of the accounts page and beside the connect form.
What Agent SRE does with it
| Tool | What it does |
|---|---|
search-confluence | Finds pages by plain text, or by CQL when the model knows exactly what it wants, optionally within one space |
get-confluence-page | Reads one page as plain text, by id or by a pasted page URL (share links work) |
If an alert rule's description contains a Confluence page link, the agent reads that page first, before searching.
The agent treats page content as guidance from the team, not as evidence about the current incident: a runbook describes what usually happens, telemetry shows what is happening now. It cites every page it relies on by URL and never cites a page it did not read.
Access control
The Integrations RBAC module gates the page: Viewer sees tiles and connections, Editor can connect, edit, test and remove. It is granted to the Admin role on upgrade; other roles are opened from Settings → Role Access. Agent SRE checks the same module for the user who started the investigation or chat.
Troubleshooting
"rejected the stored credentials (401)"
The token is wrong, expired, or belongs to a different account than the email entered. Cloud tokens are tied to the account that created them.
"refusing to call private address"
The server is on a private network and the API service's egress policy is closed. Set INTEGRATIONS_HTTP_ALLOW_PRIVATE_NETWORKS=true on the API service.
The agent never searches Confluence
The agent is only told about Confluence when at least one connection is enabled. Check the connection is not paused, and that the user running the investigation has the Integrations module.