nwalens opened a new pull request #18249:
URL: https://github.com/apache/airflow/pull/18249


   <!--
   Thank you for contributing! Please make sure that your code changes
   are covered with tests. And in case of new features or big changes
   remember to adjust the documentation.
   
   Feel free to ping committers for the review!
   
   In case of existing issue, reference it using one of the following:
   
   closes: #17744 
   related: #18136 
   
   How to write a good git commit message:
   http://chris.beams.io/posts/git-commit/
   -->
   
   closes: #17744 
   related: #18136 
   
   This PR replaces the global "uid" and "gid" with a per deployment 
securityContext setting.
   
   Fields are configured as follows:
   ```
   podSecurity:
     default:
       securityContext:
         runAsUser: 50000
         fsGroup: 0
         runAsGroup: 0
       containerSecurityContext:
         runAsUser: 50000
         runAsGroup: 0
     webserver:
       securityContext:
         enabled: false
       containerSecurityContext:
         enabled: false
   ```
   
   The default will be used in case the individual setting is disabled.
   
   This change allows for more configurability and allows the usage of 
arbitrary securityContexts as permitted by the official docker images.
   The issue #18136 still requires the PR #18147 for Openshift clusters since 
there is no option to remove securityContexts altogether.
   
   ---
   **^ Add meaningful description above**
   
   Read the **[Pull Request 
Guidelines](https://github.com/apache/airflow/blob/main/CONTRIBUTING.rst#pull-request-guidelines)**
 for more information.
   In case of fundamental code change, Airflow Improvement Proposal 
([AIP](https://cwiki.apache.org/confluence/display/AIRFLOW/Airflow+Improvements+Proposals))
 is needed.
   In case of a new dependency, check compliance with the [ASF 3rd Party 
License Policy](https://www.apache.org/legal/resolved.html#category-x).
   In case of backwards incompatible changes please leave a note in 
[UPDATING.md](https://github.com/apache/airflow/blob/main/UPDATING.md).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscr...@airflow.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


Reply via email to