Jira
Link investigations to open incidents and tickets for the affected service
Connecting Jira to Agent SRE
Connect Jira and Agent SRE searches it for open incidents and tickets about the affected service during investigations, so a known, in-progress cause is not rediscovered from scratch, and reads an issue's description and recent comments when they matter.
Both Atlassian Cloud and self-hosted Data Center are supported. One organisation can connect several Jira sites; each is its own account under the Jira tile.
Read-only: Agent SRE only searches and reads issues. It does not create, comment on or transition anything, and nothing is copied to KubeSense servers.
Prerequisites
Choose one of three ways to connect. The service account is the one to prefer for a long-lived connection.
Atlassian Cloud service account (recommended)
- Create a service account at admin.atlassian.com → Directory → Service accounts. Every organisation includes five at no cost. Give it product access to Jira only.
- Create an API token for that service account with read-only scopes:
read:jira-work,read:jira-user. - Allow outbound HTTPS from the KubeSense API service to
api.atlassian.comand to your Atlassian site. Service account tokens are only accepted through Atlassian's API gateway, so both hosts are needed. If Atlassian IP allow-listing is on, add the service's egress IP.
Atlassian Cloud (personal token)
- Create an API token at id.atlassian.com → Security → API tokens, signed in as the account Agent SRE will use.
- This token is tied to that person and stops working when they leave.
- Allow outbound HTTPS from the KubeSense API service to your Atlassian site.
Self-hosted (Data Center)
- Data Center has no service accounts. Create a dedicated user for KubeSense, not a person's account, so the token outlives staff changes, and give it read access to the spaces or projects the agent should see.
- Signed in as that user, create a personal access token under profile → Personal Access Tokens.
- The KubeSense API service must be able to resolve and reach the server. A private address needs
INTEGRATIONS_HTTP_ALLOW_PRIVATE_NETWORKS=trueon the API service; the default refuses private ranges.
Connecting
- Open Integrations and find Jira under the Integrations section. Click Connect.
- Choose Atlassian Cloud service account, Atlassian Cloud (personal token), or Self-hosted (Data Center).
- Fill in the form:
| Field | Service account | Personal token | Data Center |
|---|---|---|---|
| Name | A label, e.g. Platform Jira. Shown on the tile and in citations. | Same | Same |
| Site URL / Server URL | https://acme.atlassian.net | https://acme.atlassian.net | https://jira.acme.internal |
| Atlassian account email | — | The account the token belongs to | — |
| Token | Service account API token | API token | Personal access token |
Tokens are stored encrypted and never shown again after you save.
- Click Test connection, then Save and enable.
Managing connections
Clicking the Jira tile opens the accounts page: every connected site on the left, the selected one on the right. From there you can pause a connection without removing it, re-run the connection test, rotate the token (leave the token blank on edit to keep the stored one), or remove it.
The tile also shows a Capabilities panel: what KubeSense does with this integration, listed by the release that added it, newest first. It appears at the bottom of the accounts page and beside the connect form.
What Agent SRE does with it
| Tool | What it does |
|---|---|
search-jira | Finds issues by plain text, or by JQL, optionally within one project |
get-jira-issue | Reads one issue by key or pasted URL: fields, description and the last ten comments |
Results carry the issue key, summary, status, assignee and a link, so the report can point the on-call engineer at the ticket that already tracks the problem.
Access control and troubleshooting
Identical to Confluence: the Integrations RBAC module gates the page and the agent's use of the connection, and the same 401 and private-address errors have the same fixes.