Two more tools-only external-SaaS modules on the proven gitlab/cloudflare-dns template (runtime-only, no service, own-secrets token via secret accept, public config via config.json merge:json).
confluence — 3 tools (confluence_search, confluence_get_page, confluence_list_spaces). Lab-proven green (assigned-tools-confluence: runtime comes up, serves 3 tools with no creds, binds serve queues, scoped account). SUITE_EXIT=0.
jira — 8 tools (jira_search_issues, jira_get_issue, jira_create_issue, jira_update_issue, jira_add_comment, jira_list_transitions, jira_transition_issue, jira_list_projects). Runtime verified serving 8 tools in-image; identical shape to confluence. Its periodic ticket-poller is deliberately deferred pending the scheduled-task capability (noted in jira/tools/index.ts); the ADF rich-text converter was carried into the client so create/update/comment send valid Jira v3 bodies.
Both honour the Servarr lesson (lazy client, never throws at registration). Atlassian's two-key public config (URL + email) and Basic-auth scheme were the only deltas from gitlab's single-token shape.
Two more tools-only external-SaaS modules on the proven gitlab/cloudflare-dns template (runtime-only, no service, own-secrets token via `secret accept`, public config via `config.json` merge:json).
- **confluence** — 3 tools (`confluence_search`, `confluence_get_page`, `confluence_list_spaces`). **Lab-proven green** (`assigned-tools-confluence`: runtime comes up, serves 3 tools with no creds, binds serve queues, scoped account). SUITE_EXIT=0.
- **jira** — 8 tools (`jira_search_issues`, `jira_get_issue`, `jira_create_issue`, `jira_update_issue`, `jira_add_comment`, `jira_list_transitions`, `jira_transition_issue`, `jira_list_projects`). Runtime verified serving 8 tools in-image; identical shape to confluence. Its periodic **ticket-poller is deliberately deferred** pending the scheduled-task capability (noted in `jira/tools/index.ts`); the ADF rich-text converter was carried into the client so create/update/comment send valid Jira v3 bodies.
Both honour the Servarr lesson (lazy client, never throws at registration). Atlassian's two-key public config (URL + email) and Basic-auth scheme were the only deltas from gitlab's single-token shape.
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Port the HAL confluence and jira integrations to the tools-only,
outbound-only external-SaaS pattern proven by the merged gitlab module:
runtime-only containers (container-runtime capability), own-secret token +
broker, a settings-managed config.json for public config, and a
per-module runtime image.
Each module carries its own Atlassian API client and tools (ADR 0039),
translated from HAL's @hal/sdk zod-schema/MCP-content shape into
mesh-sdk's input/run-returns-data shape. Public config (ATLASSIAN_URL,
ATLASSIAN_EMAIL) lives in config.json; the API token is the one
own-secret. Clients are built lazily and never throw at registration, so
each runtime serves its full tool surface with no credentials (the
Servarr lesson) — confluence serves 3 tools, jira serves 8.
jira's periodic ticket-poller (update-tickets.service/.timer) is NOT
ported: the mesh has no scheduled-task primitive yet (a pending
decision). Only jira's tools are ported; a top-of-file note records the
deferral.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Two more tools-only external-SaaS modules on the proven gitlab/cloudflare-dns template (runtime-only, no service, own-secrets token via
secret accept, public config viaconfig.jsonmerge:json).confluence_search,confluence_get_page,confluence_list_spaces). Lab-proven green (assigned-tools-confluence: runtime comes up, serves 3 tools with no creds, binds serve queues, scoped account). SUITE_EXIT=0.jira_search_issues,jira_get_issue,jira_create_issue,jira_update_issue,jira_add_comment,jira_list_transitions,jira_transition_issue,jira_list_projects). Runtime verified serving 8 tools in-image; identical shape to confluence. Its periodic ticket-poller is deliberately deferred pending the scheduled-task capability (noted injira/tools/index.ts); the ADF rich-text converter was carried into the client so create/update/comment send valid Jira v3 bodies.Both honour the Servarr lesson (lazy client, never throws at registration). Atlassian's two-key public config (URL + email) and Basic-auth scheme were the only deltas from gitlab's single-token shape.
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF