Uh oh!
There was an error while loading. Please reload this page.
Add the section describing the security model of DAG Author capabilities - #36022
Conversation
There was a problem hiding this comment.
I'm working on moving the new priority weight strategy to a plugin, I will update this part once I finish my PR.
There was a problem hiding this comment.
Perfect :) . I was just asking in the original PR #35210
cc4f7b0 to
59e38a7CompareUh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
dafefdf to
e231047CompareUh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
This change codifies and explains assumptions and decisions made by Airflow maintainers with regards to capabilities of DAG Authors. While DAG authors are pretty powerful and capable actors in Airflow, they cannot do everything and Deployment Managers haw ways to restrict their potential capabilities, especially in the context of influencing other tasks and common components such as Scheduler, Webserver and Triggerer. This PR adds a chapter explaining those assumptions and decisions and tell the Deployment Managers what responsibilities they have with that regardsm and what mechanismes they currently have available to limit capabilities of DAG Authors.
Co-authored-by: Pankaj Koti <pankajkoti699@gmail.com>
Co-authored-by: Pankaj Koti <pankajkoti699@gmail.com>
c2aa0ba to
f11afb8Comparepotiuk
commented
Dec 4, 2023
I will merge it as is now, and we can update it later @hussein-awala :) |
…ies (#36022) * Add the section describing the security model of DAG Author capabilities This change codifies and explains assumptions and decisions made by Airflow maintainers with regards to capabilities of DAG Authors. While DAG authors are pretty powerful and capable actors in Airflow, they cannot do everything and Deployment Managers haw ways to restrict their potential capabilities, especially in the context of influencing other tasks and common components such as Scheduler, Webserver and Triggerer. This PR adds a chapter explaining those assumptions and decisions and tell the Deployment Managers what responsibilities they have with that regardsm and what mechanismes they currently have available to limit capabilities of DAG Authors. * Update docs/apache-airflow/security/security_model.rst Co-authored-by: Pankaj Koti <pankajkoti699@gmail.com> * Update docs/apache-airflow/security/security_model.rst Co-authored-by: Pankaj Koti <pankajkoti699@gmail.com> --------- Co-authored-by: Pankaj Koti <pankajkoti699@gmail.com> (cherry picked from commit 395ac46)
This change codifies and explains assumptions and decisions made by Airflow maintainers with regards to capabilities of DAG Authors.
While DAG authors are pretty powerful and capable actors in Airflow, they cannot do everything and Deployment Managers have ways to restrict their potential capabilities, especially in the context of influencing other tasks and common components such as Scheduler, Webserver and Triggerer.
This PR adds a chapter explaining those assumptions and decisions and tell the Deployment Managers what responsibilities they have with that regards and what mechanisms they currently have available to limit capabilities of DAG Authors.
^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named
{pr_number}.significant.rstor{issue_number}.significant.rst, in newsfragments.