PlantUML Private
PlantUML diagrams in Confluence that never leave your instance. The engine runs in your browser, so there is no render server to send your diagram source to.
What it is
PlantUML Private is a Confluence Cloud macro (built on Atlassian Forge) that renders PlantUML diagrams directly in the page editor and on the published page. You type or paste PlantUML source into the macro, see it rendered, and save. It is a focused tool: PlantUML in Confluence, and nothing else.
Inserting and editing a diagram
- In the Confluence editor, type
/(or use the + insert menu) and search for PlantUML. - Insert the macro. An editor opens inside the page.
- Type or paste your PlantUML source.
- Choose Render to preview the diagram.
- Choose Save to store it. The diagram now shows on the page.
To change a saved diagram, open the macro again: it shows the current source. Edit, Render, then Save. There is no upload step; the source you type is the only input. A minimal example:
@startuml
Alice -> Bob : hello
Bob --> Alice : hi back
@enduml
The editor also has optional theme and scale fields. Dark mode follows Confluence’s own light/dark setting.
Supported diagram types
| Type | Start tag |
|---|---|
| Sequence | @startuml |
| Class | @startuml |
| Activity | @startuml |
| State | @startuml |
| Component | @startuml |
| Mindmap | @startmindmap |
| Gantt | @startgantt |
| JSON | @startjson |
| Deployment | @startuml |
Salt (wireframe) and Ditaa diagrams are not supported. If you paste one, the macro says so in plain language rather than showing an unexplained blank.
Themes
Add a !theme line near the top of your source to apply a bundled colour theme. 43 themes ship with the app and nothing is downloaded when you use one. A theme name that is not bundled produces a visible message.
@startuml
!theme cerulean
Alice -> Bob : hello
@enduml
Bundled icon libraries
Three PlantUML standard-library namespaces are bundled and are included locally, with nothing fetched at render time. The !include syntax is the same as in PlantUML’s own documentation.
- C4, for example
!include <C4/C4_Container> - Kubernetes, for example
!include <kubernetes/...> - Microsoft Office, for example
!include <office/...>
Other namespaces, including AWS and Azure icon sets, are not bundled. Including one produces PlantUML’s normal “cannot include” message.
Links and highlighting
On sequence, class, state, component and deployment diagrams, a [[url]] link in your PlantUML source is rendered as a clickable link. On the same five diagram types, hovering or selecting an element highlights related elements.
Security: the plain version
This section is written for the administrator or security reviewer deciding whether to approve the install.
- Rendering happens in your browser. The PlantUML engine runs as JavaScript and WebAssembly inside the macro’s frame on the page you are already viewing. I do not operate a render server.
- No backend. The app is static files only. Its manifest declares no function module and no resolver, so there is no server-side code of mine processing your diagrams.
- No permissions requested. The app requests no OAuth scopes, so the install screen lists none. Check it yourself.
- Where the source lives. Diagram source is stored in the macro’s own configuration on the page, like any other macro’s settings, and is subject to the same residency, backup and access control as the rest of that page.
- Remote includes are refused. A remote
!includein a diagram produces a visible in-diagram error and no network request is attempted. This was checked against the bundled engine, PlantUML core 1.2026.6. - Libraries are bundled. Themes and the C4, Kubernetes and Office libraries ship inside the app instead of being fetched.
Browser security grants
The app asks Forge for two content-security grants, and no others. unsafe-eval for scripts is used only to instantiate the bundled Graphviz WebAssembly module. unsafe-inline for styles lets the browser accept the inline style attributes that the PlantUML engine writes into every SVG it produces; without it the browser would report each refusal to a platform endpoint off-origin, which is exactly the kind of traffic this app is designed to avoid. Neither grant allows loading anything from elsewhere.
Other PlantUML apps for Confluence commonly work by sending diagram source to a render server and receiving an image. That design means the source leaves your instance. This one has no such server. See also the privacy statement.
Known limits
- Very large or deeply nested diagrams are refused before rendering, with a clear message, rather than being allowed to freeze the page.
- Diagrams render in your browser, so fonts and spacing may differ slightly from a server-rendered PlantUML diagram. Layout and content are the same.
- When a diagram cannot be rendered, the macro shows a plain-language message and a reference code beginning
PU-. Include it when you contact support. - Confluence Cloud only.
Pricing
Billed through Atlassian. Free for sites with up to 10 users. Listed anchor prices: $29/month at 50 users, $58/month at 100 users and $240/month at 500 users (USD). Atlassian’s Marketplace listing shows the exact tier for your site size.