Skip to content

Separate JWT secret env var from the standard Airflow environment helper - #70896

Merged
Miretpl merged 2 commits into
apache:mainfrom
rohan9446:separate-jwt-secret-env-helper
Aug 4, 2026
Merged

Miretpl merged 2 commits into
apache:mainfrom
rohan9446:separate-jwt-secret-env-helper

Conversation

@rohan9446

Copy link
Copy Markdown
Contributor

AIRFLOW__API_AUTH__JWT_SECRET was rendered from inside the
standard_airflow_environment helper behind an IncludeJwtSecret flag, which
meant every component had to opt out of it explicitly with
(merge (dict "IncludeJwtSecret" false) .).

This moves the variable into its own jwt_secret_environment helper, following
the shape of the existing keda_airflow_environment helper, and includes it
only in the two containers that actually need it — the API server and the
scheduler. Every other caller of standard_airflow_environment passes a plain
context again, and the IncludeJwtSecret context mutation is gone entirely.

What this changes:

  • Removes the IncludeJwtSecret plumbing from standard_airflow_environment
    and from all ten call sites.
  • Makes secret exposure explicit at the API server and scheduler call sites
    rather than implicit in a shared helper.
  • Preserves the least-privilege behaviour introduced in Remove JWT secrets from triggerer, worker and dag-processor #63204: migration/init
    containers, workers, the triggerer and the DAG processor still do not receive
    the raw signing secret.
  • Adds regression coverage asserting the secret appears in the API server and
    scheduler containers exactly once, and never in sidecars or init containers.

No behavioural change: the same containers receive the same variable, still
gated on enableBuiltInSecretEnvVars.AIRFLOW__API_AUTH__JWT_SECRET. The only
difference in rendered output is the position of the variable within the env
list, so the ordered assertion in test_have_all_variables is updated to match.

Tested locally with helm v3.21.3: pytest chart/tests/helm_tests/ → 2108 passed.

closes: #70843


Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

Generated-by: Claude (Cowork) following the guidelines

@boring-cyborg

boring-cyborg Bot commented Aug 1, 2026

Copy link
Copy Markdown

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example Dag that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

@SameerMesiah97 SameerMesiah97 left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved pending green CI.

Comment thread chart/tests/helm_tests/airflow_aux/test_airflow_common.py Outdated
Comment thread chart/tests/helm_tests/airflow_aux/test_airflow_common.py Outdated
Comment thread chart/tests/helm_tests/airflow_aux/test_airflow_common.py Outdated
Comment thread chart/tests/helm_tests/airflow_aux/test_airflow_common.py Outdated
Comment thread chart/tests/helm_tests/airflow_aux/test_airflow_common.py Outdated
`AIRFLOW__API_AUTH__JWT_SECRET` was rendered from inside
`standard_airflow_environment` behind an `IncludeJwtSecret` flag, so every
component had to opt out of it explicitly with
`(merge (dict "IncludeJwtSecret" false) .)`.

Move the variable into its own `jwt_secret_environment` helper, following the
shape of the existing `keda_airflow_environment` helper, and include it only in
the API server and scheduler containers that need it. Every other caller of
`standard_airflow_environment` passes a plain context again, and the
`IncludeJwtSecret` context mutation is gone.

No behavioural change: the same containers receive the same variable, still
gated on `enableBuiltInSecretEnvVars.AIRFLOW__API_AUTH__JWT_SECRET`, preserving
the least-privilege exposure introduced in apache#63204. Only the position of the
variable within the rendered env list changes, so the ordered assertion in
`test_have_all_variables` is updated to match.

Closes: apache#70843
@rohan9446
rohan9446 force-pushed the separate-jwt-secret-env-helper branch from 2b3c9ac to 5609a83 Compare August 2, 2026 17:31
@rohan9446
rohan9446 requested a review from Miretpl August 2, 2026 17:39
@Miretpl Miretpl added the backport-to-chart/v1-2x-test Automatic backport to chart 1.2x maintenance branch label Aug 4, 2026
@Miretpl
Miretpl merged commit 562cc3e into apache:main Aug 4, 2026
205 of 206 checks passed
@boring-cyborg

boring-cyborg Bot commented Aug 4, 2026

Copy link
Copy Markdown

Awesome work, congrats on your first merged pull request! You are invited to check our Issue Tracker for additional contributions.

@Miretpl

Miretpl commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Congrats and welcome to the community!

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Backport failed to create: chart/v1-2x-test. View the failure log Run details

Note: As of Merging PRs targeted for Airflow 3.X
the committer who merges the PR is responsible for backporting the PRs that are bug fixes (generally speaking) to the maintenance branches.

In matter of doubt please ask in #release-management Slack channel.

Status Branch Result
❌ chart/v1-2x-test Commit Link

You can attempt to backport this manually by running:

cherry_picker 562cc3e chart/v1-2x-test

This should apply the commit to the chart/v1-2x-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

If you don't have cherry-picker installed, see the installation guide.

@Miretpl

Miretpl commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

@rohan9446, could you create manual backport of it to chart/v1-2x-test branch?

@rohan9446

Copy link
Copy Markdown
Contributor Author

Thanks @Miretpl! Backport is up: #71129

The automated one failed because chart/v1-2x-test still supports Airflow 2 alongside 3, the JWT block there carries an extra semverCompare ">=3.0.0" .Values.airflowVersion gate, there's no keda_airflow_environment helper to anchor the new define against, and the helm tests live under helm-tests/tests/. The version gate now sits inside jwt_secret_environment, so Airflow 2 rendering is unchanged. Full chart suite passes locally (3454 tests).

Miretpl pushed a commit that referenced this pull request Aug 11, 2026
…low environment helper (#70896) (#71129)

`AIRFLOW__API_AUTH__JWT_SECRET` was rendered from inside
`standard_airflow_environment` behind an `IncludeJwtSecret` flag, so every
component had to opt out of it explicitly with
`(merge (dict "IncludeJwtSecret" false) .)`.

Move the variable into its own `jwt_secret_environment` helper, following the
shape of the existing `keda_airflow_environment` helper, and include it only in
the API server and scheduler containers that need it. Every other caller of
`standard_airflow_environment` passes a plain context again, and the
`IncludeJwtSecret` context mutation is gone.

No behavioural change: the same containers receive the same variable, still
gated on `enableBuiltInSecretEnvVars.AIRFLOW__API_AUTH__JWT_SECRET`, preserving
the least-privilege exposure introduced in #63204. Only the position of the
variable within the rendered env list changes, so the ordered assertion in
`test_have_all_variables` is updated to match.

Closes: #70843
(cherry picked from commit 562cc3e)

Co-authored-by: rohan9446 <bandaru04052004@gmail.com>
dabla pushed a commit to dabla/airflow that referenced this pull request Aug 14, 2026
…per (apache#70896)

`AIRFLOW__API_AUTH__JWT_SECRET` was rendered from inside
`standard_airflow_environment` behind an `IncludeJwtSecret` flag, so every
component had to opt out of it explicitly with
`(merge (dict "IncludeJwtSecret" false) .)`.

Move the variable into its own `jwt_secret_environment` helper, following the
shape of the existing `keda_airflow_environment` helper, and include it only in
the API server and scheduler containers that need it. Every other caller of
`standard_airflow_environment` passes a plain context again, and the
`IncludeJwtSecret` context mutation is gone.

No behavioural change: the same containers receive the same variable, still
gated on `enableBuiltInSecretEnvVars.AIRFLOW__API_AUTH__JWT_SECRET`, preserving
the least-privilege exposure introduced in apache#63204. Only the position of the
variable within the rendered env list changes, so the ordered assertion in
`test_have_all_variables` is updated to match.

Closes: apache#70843

Co-authored-by: rohan9446 <bandaru04052004@gmail.com>
imrichardwu pushed a commit to imrichardwu/airflow that referenced this pull request Sep 11, 2026
…per (apache#70896)

`AIRFLOW__API_AUTH__JWT_SECRET` was rendered from inside
`standard_airflow_environment` behind an `IncludeJwtSecret` flag, so every
component had to opt out of it explicitly with
`(merge (dict "IncludeJwtSecret" false) .)`.

Move the variable into its own `jwt_secret_environment` helper, following the
shape of the existing `keda_airflow_environment` helper, and include it only in
the API server and scheduler containers that need it. Every other caller of
`standard_airflow_environment` passes a plain context again, and the
`IncludeJwtSecret` context mutation is gone.

No behavioural change: the same containers receive the same variable, still
gated on `enableBuiltInSecretEnvVars.AIRFLOW__API_AUTH__JWT_SECRET`, preserving
the least-privilege exposure introduced in apache#63204. Only the position of the
variable within the rendered env list changes, so the ordered assertion in
`test_have_all_variables` is updated to match.

Closes: apache#70843

Co-authored-by: rohan9446 <bandaru04052004@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:helm-chart Airflow Helm Chart backport-to-chart/v1-2x-test Automatic backport to chart 1.2x maintenance branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Separate JWT Secret Env from Standard Airflow Environment Variables

3 participants