confluence-cli
Markdown-sync-first Confluence CLI in Rust.
confluence-cli is built around a safe local workflow:
pullConfluence content into Markdown plus sidecar metadata.planexactly what would change remotely.applyonly when the diff is correct.
It also exposes direct page, blog, search, attachment, label, comment, and property commands for non-sync use cases.
Status
Early release, but already live-verified against both Confluence Cloud and Confluence Data Center.
| Area | Cloud | Data Center | Notes |
|---|---|---|---|
| Auth, spaces, search, page/blog CRUD | Verified | Verified | Live e2e |
| Attachments, labels, properties, comments | Verified | Verified | Live e2e |
pull -> plan -> apply sync flow |
Verified | Verified | Includes drift refusal and noop checks |
doctor environment/profile validation |
Verified | Verified | Live checked |
| Markdown round-trip for common built-in macros | Verified | Verified | Unsupported cases preserve storage safely |
Installation
From PyPI with uv:
uv tool install confluence-cli-rs
The PyPI distribution is named confluence-cli-rs; it installs the
confluence executable.
From crates.io:
cargo install confluence-cli
From Homebrew:
brew tap rvben/tap
brew install rvben/tap/confluence-cli
Prebuilt macOS and Linux archives are published on the GitHub releases page.
Quick Start
For guided setup, run confluence auth login (or confluence init) in a
terminal. The wizard opens Atlassian's token page when useful, discovers the
Cloud ID required by scoped tokens, hides credential entry, verifies access,
and stores the token in your operating-system keychain. Existing profiles are
offered as defaults. If no OS credential service is available, setup offers an
explicit protected-file fallback rather than silently weakening storage.
For Confluence Data Center, setup can create a dedicated PAT through the
official API using a one-time password or existing PAT; the bootstrap secret is
never saved. If automatic creation is unavailable, it opens
https://<your-host>/plugins/personalaccesstokens/usertokens.action (also
available under Avatar → Settings → Personal access tokens). Onboarding
never consumes accidental piped input as answers.
Cloud profile:
CONFLUENCE_API_TOKEN="$CONFLUENCE_API_TOKEN" confluence auth login \
--profile cloud \
--provider cloud \
--domain your-site.atlassian.net \
--auth-type basic \
--username you@example.com \
--non-interactive
confluence doctor --profile cloud --space SPACEKEY
Data Center profile:
printf '%s' "$CONFLUENCE_PAT" | confluence auth login \
--profile dc \
--provider data-center \
--domain http://localhost:8090 \
--auth-type bearer \
--token-stdin \
--non-interactive
confluence doctor --profile dc --space TEST
Environment-driven mode also works without a stored profile:
export CONFLUENCE_DOMAIN=https://your-site.atlassian.net
export CONFLUENCE_PROVIDER=cloud
export CONFLUENCE_AUTH_TYPE=basic
export CONFLUENCE_EMAIL=you@example.com
export CONFLUENCE_TOKEN="$CONFLUENCE_API_TOKEN"
confluence doctor --space SPACEKEY
Non-interactive login stores credentials in the OS keychain by default. For a
headless machine without a credential service, prefer environment-driven mode;
if persistent storage is necessary, explicitly accept the protected config-file
fallback with --insecure-storage. Existing inline-token profiles remain
readable and can be moved transactionally with confluence auth migrate.
Markdown Sync Workflow
Pull a page tree:
confluence pull tree SPACE:ParentPage ./docs/parent-page
Inspect the planned changes:
confluence plan ./docs/parent-page
Apply the diff:
confluence apply ./docs/parent-page
Local content is stored as:
<slug>/index.md<slug>/.confluence.json<slug>/attachments/*
The frontmatter carries editable metadata like title, type, labels, status, parent, and properties. The sidecar stores remote ids, versions, hashes, and attachment mappings used for safe sync and drift detection.
doctor
Use doctor before a first sync, in CI, or when a profile behaves unexpectedly.
confluence doctor --profile cloud --space SPACEKEY --path ./docs/parent-page
It checks:
- config loading and profile resolution
- base URL and auth shape
- provider reachability
- optional space access
- optional local sync path planning
doctor exits non-zero on failures and supports --json for machine-readable checks.
Commands
Top-level command groups:
auth login|status|logout|migrateprofile add|list|use|removespace list|getsearchpage get|tree|create|update|deleteblog get|create|update|deletepull page|tree|spaceplanapplyattachment list|download|upload|deletelabel list|add|removecomment list|add|deleteproperty list|get|set|deletedoctorcompletions
Every command accepts the suite-wide --output auto|text|json, --quiet, and --no-color flags. Auto output is readable text on a terminal and JSON when piped; --json remains a hidden compatibility alias. Errors use the shared exit-code contract (input 2, auth 3, not found 4, API 5, rate limit 6, conflict 7), and confluence schema --command 'page get' returns one token-efficient command contract.
Auth And Environment Overrides
Stored profiles live under the local config directory used by directories::ProjectDirs.
Supported environment overrides:
CONFLUENCE_PROFILECONFLUENCE_DOMAINCONFLUENCE_PROVIDERCONFLUENCE_API_PATHCONFLUENCE_AUTH_TYPECONFLUENCE_EMAILorCONFLUENCE_USERNAMECONFLUENCE_API_TOKEN,CONFLUENCE_TOKEN,CONFLUENCE_PASSWORD, orCONFLUENCE_BEARER_TOKENCONFLUENCE_READ_ONLY
CONFLUENCE_PROVIDER must be cloud or data-center. CONFLUENCE_AUTH_TYPE must be basic or bearer.
Shell Completions
confluence completions bash > /usr/local/etc/bash_completion.d/confluence
confluence completions zsh > ~/.zsh/completions/_confluence
confluence completions fish > ~/.config/fish/completions/confluence.fish
Local Data Center
The repo includes a local Confluence Data Center stack for integration testing.
make confluence-start
make confluence-wait
make test-e2e
The default e2e path targets the local local-dc profile and the TEST space.
Available helpers:
make confluence-backupmake confluence-restoremake confluence-resetmake confluence-logs
Backups are written to:
docker/backup/confluence-data.tar.gzdocker/backup/postgres-data.tar.gz
The first boot after make confluence-restore can take several minutes before HTTP responds.
To point the e2e suite at another instance:
CONFLUENCE_E2E_PROFILE=other-profile CONFLUENCE_E2E_SPACE=SPACE make test-e2e
Or run fully env-driven:
CONFLUENCE_E2E_PROFILE= \
CONFLUENCE_E2E_BASE_URL=http://localhost:8090 \
CONFLUENCE_E2E_TOKEN="$CONFLUENCE_PAT" \
CONFLUENCE_E2E_PROVIDER=data-center \
CONFLUENCE_E2E_SPACE=TEST \
make test-e2e
Release And CI
Local release gate:
make release-check
That runs formatting, clippy, tests, CLI smoke checks, and cargo package.
Local versioned releases use vership, matching the other CLI projects:
make release-patch
make release-minor
make release-major
vership uses vership.toml in this repo so vership preflight runs the stricter make release-check gate rather than the default Rust-only lint/test commands.
GitHub Actions is set up to:
- run CI on pushes and pull requests
- publish tagged releases to crates.io
- publish native macOS and Linux wheels to PyPI as
confluence-cli-rs - build tagged macOS and Linux release archives
- attach release archives and checksum files to GitHub releases
- update
rvben/tapautomatically on tagged releases whenHOMEBREW_TAP_TOKENis configured
Markdown Fidelity
Remote canonical content stays in Confluence storage format. Markdown is the editable local representation.
The converter already handles a large set of common Confluence constructs directly, including:
- headings, lists, tables, code blocks, task lists, links, and attachments
- page links and typed page/user/space resource parameters
- layouts, panels, expand blocks, status, TOC-family macros, and search/navigation macros
- excerpt, excerpt-include, include-page, page-tree, page-tree-search, and page-index
- label/reporting/content-property/report-table/task-report families
- attachment preview and other common built-in macros
When a construct is unsupported or would be lossy, confluence-cli preserves the Confluence storage fragment instead of flattening the whole page.
Known Limits
- Storage fidelity is strongest for supported built-in macros and generic resource-aware macro fallback. Unknown provider-specific macro behavior can still vary between Cloud and Data Center.
- CI does not run live tenant e2e by default. Use
make test-e2eagainst a real instance for provider validation. applyrefuses remote version drift unless--forceis used.
License
MIT
Releasing
Vership owns versioning, changelog generation, release commits, and tags. See the release runbook for the verified workflow and recovery policy.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file confluence_cli_rs-0.1.19.tar.gz.
File metadata
- Download URL: confluence_cli_rs-0.1.19.tar.gz
- Upload date:
- Size: 135.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3809dfaed58bf95ae90f16683d332a88b7eb55f021f063a48908b04267586b39
|
|
| MD5 |
2eaf19230b1bdb63902f07c2d4ed0e51
|
|
| BLAKE2b-256 |
af6f61ff705cad7b7aebdd29f09fa8310efcb052b6bd725e391dc2f7853072cb
|
File details
Details for the file confluence_cli_rs-0.1.19-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.
File metadata
- Download URL: confluence_cli_rs-0.1.19-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
- Upload date:
- Size: 6.4 MB
- Tags: Python 3, manylinux: glibc 2.17+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
75723d601fad79fd0d1bdb770a79cc17a00d549c24bf967810266734e4cab9e9
|
|
| MD5 |
f81198d305ee2b7e61b5db2eb9893c1d
|
|
| BLAKE2b-256 |
904f5d6ecc58d624c4513656065cdd65d9fbb7cb5be66926f3c5c9ce027e9bf8
|
File details
Details for the file confluence_cli_rs-0.1.19-py3-none-macosx_11_0_arm64.whl.
File metadata
- Download URL: confluence_cli_rs-0.1.19-py3-none-macosx_11_0_arm64.whl
- Upload date:
- Size: 4.8 MB
- Tags: Python 3, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7a410cbb1fd6c20aa00a500601efbc1143cd25e5db2415413c780ea008c64479
|
|
| MD5 |
8ec292f123891fbb796ea930982cd772
|
|
| BLAKE2b-256 |
ffb0dda23ad2c51fc8bb4fe92b5a2a83177e50572ab247e2646b48dbcdf4ba1b
|
File details
Details for the file confluence_cli_rs-0.1.19-py3-none-macosx_10_12_x86_64.whl.
File metadata
- Download URL: confluence_cli_rs-0.1.19-py3-none-macosx_10_12_x86_64.whl
- Upload date:
- Size: 5.0 MB
- Tags: Python 3, macOS 10.12+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
fcdc754933070767276b5580af88e4915ad49906ca52eaef27281b4751e550b5
|
|
| MD5 |
34e6e9f5624699231d9b457a201c31d5
|
|
| BLAKE2b-256 |
cc264dd2690fe7c7901ec5fc32b31c19bee7df4e308b393673360a5a4a5c26a0
|