I really like the Runs on Atlassian trust signal and would love to offer it to our customers on our upcoming full Forge rewrite. But in our case, that’s not easy: Our app uses the customers Confluence content and displays it as a slideshow.
It’s hard to explain why the customer can embed YouTube videos in the Confluence pages, but in our app, these are blocked “for security reasons”. Most of our customers use Confluence with embedded content - Tableau Dashboards, internal analytics systems embedded etc.
Until now, our only choice was:
- either allow ALL egress in the manifest, thereby giving our customers their content, but look like a complete security nightmare from the customers perspective - OR -
- Be Runs on Atlassian, the darling of all admins, and have users despair about their missing Tableau Dashboards.
Then, customer-managed egress appeared and we hoped that our customers can choose individually what content they allow. Wonderful. If not for the fact that “Runs on Atlassian” is mutually exclusive with customer-managed egress.
The resulting dilemma
Now, we have to choose the nearly same dilemma:
- Do we allow our customers to choose whether their internal dashboards or YouTube videos are allowed in their presentation content but loose “Runs on Atlassian”?
- OR do we pride ourselves with “Runs on Atlassian” but deny our customers their own content?
I cannot see why customer-managed egress costs the “Runs on Atlassian” badge. It makes no sense to me and puts us in a strange position. Especially in our case, since we only show content that is already inside of Confluence.
Maybe we should release our app on an additional marketplace listing - the “RoA edition” and the “with content” edition? Just joking.
Arguments against it
I’ve read the arguments @SeanBourke presented in another thread but they aren’t convincing to me.
- Custom expectation of zero egress: this went out of the window in the meantime anyway as Analytics egress snuck in. Also, the customer - a full-grown adult admin in charge of the installation - has to approve the egress. What more do we want here?
- Potential abuse: We’re not the Google Play Store here. Professional customers need working solutions from us and we shouldn’t deny them because we are afraid of some black sheep. This is a pure review process problem, the remaining problems can be caught in the approval user interface design (which could use a better overview, just saying).
- Other badges: Not really an argument, is it? “Hey according to RoA we’re potentially dangerous, but look at that other badge” doesn’t work for me. I also strongly agree with Scott’s argument that customers will filter the marketplace for RoA apps and won’t see our customer-managed apps at all.
TL;DR:
Please re-consider RoA vs customer-managed egress and save us from having to choose to either disappoint customers or loose the badge.
Time is ticking!
I’m dropping this post in FRGE-1531 as well.