mirror of
https://github.com/bitnami/charts.git
synced 2026-10-06 21:44:36 +08:00
[bitnami/airflow] Add seccomp profile to pod security contexts (#36621)
* airflow security changes Signed-off-by: Subhadeep Maity <322813880+deepnemesis@users.noreply.github.com> * [bitnami/airflow] Link PR in CHANGELOG Signed-off-by: Subhadeep Maity <322813880+deepnemesis@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> * Update CHANGELOG.md Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com> --------- Signed-off-by: Subhadeep Maity <322813880+deepnemesis@users.noreply.github.com> Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Bitnami Bot <bitnami.bot@broadcom.com>
This commit is contained in:
co-authored by
Cursor
Bitnami Bot
parent
17930f75cd
commit
bb5e98a6e3
@@ -1,8 +1,15 @@
|
||||
# Changelog
|
||||
|
||||
## 25.1.1 (2026-10-02)
|
||||
|
||||
* [bitnami/airflow] Add seccomp profile to pod security contexts ([#36621](https://github.com/bitnami/charts/pull/36621))
|
||||
|
||||
## 25.1.0 (2026-01-12)
|
||||
|
||||
* [bitnami/airflow] Allow customizing the empty-dir volume parameters ([#36432](https://github.com/bitnami/charts/pull/36432))
|
||||
* [bitnami/*][TNZ-62332] Modify charts' READMEs title (#36372) ([2012e46](https://github.com/bitnami/charts/commit/2012e46699f555bb1e10134691031975bb5ca50b)), closes [#36372](https://github.com/bitnami/charts/issues/36372)
|
||||
* [bitnami/airflow] Allow customizing the empty-dir volume parameters (#36432) ([c58edb8](https://github.com/bitnami/charts/commit/c58edb88cb9f39ae12bc06a507050c00b7b1c8cd)), closes [#36432](https://github.com/bitnami/charts/issues/36432)
|
||||
* Change wording in Chart's READMEs (#36379) ([a4ef0a6](https://github.com/bitnami/charts/commit/a4ef0a63877fcf32895869ceef0916c15a4718e5)), closes [#36379](https://github.com/bitnami/charts/issues/36379)
|
||||
* Remove TAC sentence present in some READMEs (#36381) ([e07d331](https://github.com/bitnami/charts/commit/e07d3319b61f49ddf6f431da3ed7ec0e0be3d5d0)), closes [#36381](https://github.com/bitnami/charts/issues/36381)
|
||||
|
||||
## <small>25.0.4 (2025-09-02)</small>
|
||||
|
||||
|
||||
@@ -41,4 +41,4 @@ maintainers:
|
||||
name: airflow
|
||||
sources:
|
||||
- https://github.com/bitnami/charts/tree/main/bitnami/airflow
|
||||
version: 25.1.0
|
||||
version: 25.1.1
|
||||
|
||||
@@ -590,6 +590,7 @@ The Bitnami Airflow chart relies on the PostgreSQL chart persistence. This means
|
||||
| `web.podSecurityContext.sysctls` | Set kernel settings using the sysctl interface | `[]` |
|
||||
| `web.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` |
|
||||
| `web.podSecurityContext.fsGroup` | Set Airflow webserver pod's Security Context fsGroup | `1001` |
|
||||
| `web.podSecurityContext.seccompProfile.type` | Set Airflow webserver pod's Security Context seccomp profile | `RuntimeDefault` |
|
||||
| `web.containerSecurityContext.enabled` | Enabled Airflow webserver containers' Security Context | `true` |
|
||||
| `web.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` |
|
||||
| `web.containerSecurityContext.runAsUser` | Set Airflow webserver containers' Security Context runAsUser | `1001` |
|
||||
@@ -692,6 +693,7 @@ The Bitnami Airflow chart relies on the PostgreSQL chart persistence. This means
|
||||
| `scheduler.podSecurityContext.sysctls` | Set kernel settings using the sysctl interface | `[]` |
|
||||
| `scheduler.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` |
|
||||
| `scheduler.podSecurityContext.fsGroup` | Set Airflow scheduler pod's Security Context fsGroup | `1001` |
|
||||
| `scheduler.podSecurityContext.seccompProfile.type` | Set Airflow scheduler pod's Security Context seccomp profile | `RuntimeDefault` |
|
||||
| `scheduler.containerSecurityContext.enabled` | Enabled Airflow scheduler containers' Security Context | `true` |
|
||||
| `scheduler.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` |
|
||||
| `scheduler.containerSecurityContext.runAsUser` | Set Airflow scheduler containers' Security Context runAsUser | `1001` |
|
||||
@@ -794,6 +796,7 @@ The Bitnami Airflow chart relies on the PostgreSQL chart persistence. This means
|
||||
| `dagProcessor.podSecurityContext.sysctls` | Set kernel settings using the sysctl interface | `[]` |
|
||||
| `dagProcessor.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` |
|
||||
| `dagProcessor.podSecurityContext.fsGroup` | Set Airflow Dag Processor pod's Security Context fsGroup | `1001` |
|
||||
| `dagProcessor.podSecurityContext.seccompProfile.type` | Set Airflow Dag Processor pod's Security Context seccomp profile | `RuntimeDefault` |
|
||||
| `dagProcessor.containerSecurityContext.enabled` | Enabled Airflow Dag Processor containers' Security Context | `true` |
|
||||
| `dagProcessor.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` |
|
||||
| `dagProcessor.containerSecurityContext.runAsUser` | Set Airflow Dag Processor containers' Security Context runAsUser | `1001` |
|
||||
@@ -898,6 +901,7 @@ The Bitnami Airflow chart relies on the PostgreSQL chart persistence. This means
|
||||
| `triggerer.podSecurityContext.sysctls` | Set kernel settings using the sysctl interface | `[]` |
|
||||
| `triggerer.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` |
|
||||
| `triggerer.podSecurityContext.fsGroup` | Set Airflow Triggerer pod's Security Context fsGroup | `1001` |
|
||||
| `triggerer.podSecurityContext.seccompProfile.type` | Set Airflow Triggerer pod's Security Context seccomp profile | `RuntimeDefault` |
|
||||
| `triggerer.containerSecurityContext.enabled` | Enabled Airflow Triggerer containers' Security Context | `true` |
|
||||
| `triggerer.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` |
|
||||
| `triggerer.containerSecurityContext.runAsUser` | Set Airflow Triggerer containers' Security Context runAsUser | `1001` |
|
||||
@@ -1024,6 +1028,7 @@ The Bitnami Airflow chart relies on the PostgreSQL chart persistence. This means
|
||||
| `worker.podSecurityContext.sysctls` | Set kernel settings using the sysctl interface | `[]` |
|
||||
| `worker.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` |
|
||||
| `worker.podSecurityContext.fsGroup` | Set Airflow worker pod's Security Context fsGroup | `1001` |
|
||||
| `worker.podSecurityContext.seccompProfile.type` | Set Airflow worker pod's Security Context seccomp profile | `RuntimeDefault` |
|
||||
| `worker.containerSecurityContext.enabled` | Enabled Airflow worker containers' Security Context | `true` |
|
||||
| `worker.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` |
|
||||
| `worker.containerSecurityContext.runAsUser` | Set Airflow worker containers' Security Context runAsUser | `1001` |
|
||||
@@ -1113,6 +1118,7 @@ The Bitnami Airflow chart relies on the PostgreSQL chart persistence. This means
|
||||
| `setupDBJob.podSecurityContext.sysctls` | List of sysctls to allow in "setup-db" job's pods' Security Context | `[]` |
|
||||
| `setupDBJob.podSecurityContext.supplementalGroups` | List of supplemental groups to add to "setup-db" job's pods' Security Context | `[]` |
|
||||
| `setupDBJob.podSecurityContext.fsGroup` | Set fsGroup in "setup-db" job's pods' Security Context | `1001` |
|
||||
| `setupDBJob.podSecurityContext.seccompProfile.type` | Set seccomp profile in "setup-db" job's pods' Security Context | `RuntimeDefault` |
|
||||
| `setupDBJob.extraEnvVars` | Array containing extra env vars to configure the Airflow "setup-db" job's container | `[]` |
|
||||
| `setupDBJob.extraEnvVarsCM` | ConfigMap containing extra env vars to configure the Airflow "setup-db" job's container | `""` |
|
||||
| `setupDBJob.extraEnvVarsSecret` | Secret containing extra env vars to configure the Airflow "setup-db" job's container (in case of sensitive data) | `""` |
|
||||
@@ -1232,6 +1238,7 @@ The Bitnami Airflow chart relies on the PostgreSQL chart persistence. This means
|
||||
| `metrics.podSecurityContext.sysctls` | Set kernel settings using the sysctl interface | `[]` |
|
||||
| `metrics.podSecurityContext.supplementalGroups` | Set filesystem extra groups | `[]` |
|
||||
| `metrics.podSecurityContext.fsGroup` | Set StatsD exporter pod's Security Context fsGroup | `1001` |
|
||||
| `metrics.podSecurityContext.seccompProfile.type` | Set StatsD exporter pod's Security Context seccomp profile | `RuntimeDefault` |
|
||||
| `metrics.containerSecurityContext.enabled` | Enable StatsD exporter containers' Security Context | `true` |
|
||||
| `metrics.containerSecurityContext.seLinuxOptions` | Set SELinux options in container | `{}` |
|
||||
| `metrics.containerSecurityContext.runAsUser` | Set StatsD exporter containers' Security Context runAsUser | `1001` |
|
||||
|
||||
@@ -689,6 +689,7 @@ web:
|
||||
## @param web.podSecurityContext.sysctls Set kernel settings using the sysctl interface
|
||||
## @param web.podSecurityContext.supplementalGroups Set filesystem extra groups
|
||||
## @param web.podSecurityContext.fsGroup Set Airflow webserver pod's Security Context fsGroup
|
||||
## @param web.podSecurityContext.seccompProfile.type Set Airflow webserver pod's Security Context seccomp profile
|
||||
##
|
||||
podSecurityContext:
|
||||
enabled: true
|
||||
@@ -696,6 +697,8 @@ web:
|
||||
sysctls: []
|
||||
supplementalGroups: []
|
||||
fsGroup: 1001
|
||||
seccompProfile:
|
||||
type: "RuntimeDefault"
|
||||
## Configure Airflow webserver containers (only main one) Security Context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||
## @param web.containerSecurityContext.enabled Enabled Airflow webserver containers' Security Context
|
||||
@@ -1067,6 +1070,7 @@ scheduler:
|
||||
## @param scheduler.podSecurityContext.sysctls Set kernel settings using the sysctl interface
|
||||
## @param scheduler.podSecurityContext.supplementalGroups Set filesystem extra groups
|
||||
## @param scheduler.podSecurityContext.fsGroup Set Airflow scheduler pod's Security Context fsGroup
|
||||
## @param scheduler.podSecurityContext.seccompProfile.type Set Airflow scheduler pod's Security Context seccomp profile
|
||||
##
|
||||
podSecurityContext:
|
||||
enabled: true
|
||||
@@ -1074,6 +1078,8 @@ scheduler:
|
||||
sysctls: []
|
||||
supplementalGroups: []
|
||||
fsGroup: 1001
|
||||
seccompProfile:
|
||||
type: "RuntimeDefault"
|
||||
## Configure Airflow scheduler containers (only main one) Security Context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||
## @param scheduler.containerSecurityContext.enabled Enabled Airflow scheduler containers' Security Context
|
||||
@@ -1446,6 +1452,7 @@ dagProcessor:
|
||||
## @param dagProcessor.podSecurityContext.sysctls Set kernel settings using the sysctl interface
|
||||
## @param dagProcessor.podSecurityContext.supplementalGroups Set filesystem extra groups
|
||||
## @param dagProcessor.podSecurityContext.fsGroup Set Airflow Dag Processor pod's Security Context fsGroup
|
||||
## @param dagProcessor.podSecurityContext.seccompProfile.type Set Airflow Dag Processor pod's Security Context seccomp profile
|
||||
##
|
||||
podSecurityContext:
|
||||
enabled: true
|
||||
@@ -1453,6 +1460,8 @@ dagProcessor:
|
||||
sysctls: []
|
||||
supplementalGroups: []
|
||||
fsGroup: 1001
|
||||
seccompProfile:
|
||||
type: "RuntimeDefault"
|
||||
## Configure Airflow Dag Processor containers (only main one) Security Context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||
## @param dagProcessor.containerSecurityContext.enabled Enabled Airflow Dag Processor containers' Security Context
|
||||
@@ -1832,6 +1841,7 @@ triggerer:
|
||||
## @param triggerer.podSecurityContext.sysctls Set kernel settings using the sysctl interface
|
||||
## @param triggerer.podSecurityContext.supplementalGroups Set filesystem extra groups
|
||||
## @param triggerer.podSecurityContext.fsGroup Set Airflow Triggerer pod's Security Context fsGroup
|
||||
## @param triggerer.podSecurityContext.seccompProfile.type Set Airflow Triggerer pod's Security Context seccomp profile
|
||||
##
|
||||
podSecurityContext:
|
||||
enabled: true
|
||||
@@ -1839,6 +1849,8 @@ triggerer:
|
||||
sysctls: []
|
||||
supplementalGroups: []
|
||||
fsGroup: 1001
|
||||
seccompProfile:
|
||||
type: "RuntimeDefault"
|
||||
## Configure Airflow Triggerer containers (only main one) Security Context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||
## @param triggerer.containerSecurityContext.enabled Enabled Airflow Triggerer containers' Security Context
|
||||
@@ -2320,6 +2332,7 @@ worker:
|
||||
## @param worker.podSecurityContext.sysctls Set kernel settings using the sysctl interface
|
||||
## @param worker.podSecurityContext.supplementalGroups Set filesystem extra groups
|
||||
## @param worker.podSecurityContext.fsGroup Set Airflow worker pod's Security Context fsGroup
|
||||
## @param worker.podSecurityContext.seccompProfile.type Set Airflow worker pod's Security Context seccomp profile
|
||||
##
|
||||
podSecurityContext:
|
||||
enabled: true
|
||||
@@ -2327,6 +2340,8 @@ worker:
|
||||
sysctls: []
|
||||
supplementalGroups: []
|
||||
fsGroup: 1001
|
||||
seccompProfile:
|
||||
type: "RuntimeDefault"
|
||||
## Configure Airflow worker containers (only main one) Security Context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||
## @param worker.containerSecurityContext.enabled Enabled Airflow worker containers' Security Context
|
||||
@@ -2654,6 +2669,7 @@ setupDBJob:
|
||||
## @param setupDBJob.podSecurityContext.sysctls List of sysctls to allow in "setup-db" job's pods' Security Context
|
||||
## @param setupDBJob.podSecurityContext.supplementalGroups List of supplemental groups to add to "setup-db" job's pods' Security Context
|
||||
## @param setupDBJob.podSecurityContext.fsGroup Set fsGroup in "setup-db" job's pods' Security Context
|
||||
## @param setupDBJob.podSecurityContext.seccompProfile.type Set seccomp profile in "setup-db" job's pods' Security Context
|
||||
##
|
||||
podSecurityContext:
|
||||
enabled: true
|
||||
@@ -2661,6 +2677,8 @@ setupDBJob:
|
||||
sysctls: []
|
||||
supplementalGroups: []
|
||||
fsGroup: 1001
|
||||
seccompProfile:
|
||||
type: "RuntimeDefault"
|
||||
## @param setupDBJob.extraEnvVars Array containing extra env vars to configure the Airflow "setup-db" job's container
|
||||
##
|
||||
extraEnvVars: []
|
||||
@@ -3123,6 +3141,7 @@ metrics:
|
||||
## @param metrics.podSecurityContext.sysctls Set kernel settings using the sysctl interface
|
||||
## @param metrics.podSecurityContext.supplementalGroups Set filesystem extra groups
|
||||
## @param metrics.podSecurityContext.fsGroup Set StatsD exporter pod's Security Context fsGroup
|
||||
## @param metrics.podSecurityContext.seccompProfile.type Set StatsD exporter pod's Security Context seccomp profile
|
||||
##
|
||||
podSecurityContext:
|
||||
enabled: true
|
||||
@@ -3130,6 +3149,8 @@ metrics:
|
||||
sysctls: []
|
||||
supplementalGroups: []
|
||||
fsGroup: 1001
|
||||
seccompProfile:
|
||||
type: "RuntimeDefault"
|
||||
## StatsD exporter containers' Security Context
|
||||
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
|
||||
## @param metrics.containerSecurityContext.enabled Enable StatsD exporter containers' Security Context
|
||||
|
||||
Reference in New Issue
Block a user