This is an automated email from the ASF dual-hosted git repository.
shahar1 pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/airflow.git
The following commit(s) were added to refs/heads/main by this push:
new ec5b621a9cc Prepare ad-hoc providers release 2026-10-02 (#74097)
ec5b621a9cc is described below
commit ec5b621a9cc2e6c05332dbf2281665a01bc051e5
Author: Shahar Epstein <[email protected]>
AuthorDate: Fri Oct 2 20:04:55 2026 +0300
Prepare ad-hoc providers release 2026-10-02 (#74097)
Re-cut of cncf.kubernetes 10.23.0, edge3 5.0.0 and duckdb 0.2.0, which
were held back from the 2026-09-22 wave. Their changelog sections pick up
the commits that landed on main since that wave was prepared.
---
providers/.last_release_date.txt | 2 +-
providers/cncf/kubernetes/docs/changelog.rst | 5 +++++
providers/cncf/kubernetes/provider.yaml | 2 +-
providers/duckdb/provider.yaml | 2 +-
providers/edge3/docs/changelog.rst | 7 +++++++
providers/edge3/provider.yaml | 14 +++++++-------
.../edge3/src/airflow/providers/edge3/get_provider_info.py | 12 ++++++------
7 files changed, 28 insertions(+), 16 deletions(-)
diff --git a/providers/.last_release_date.txt b/providers/.last_release_date.txt
index 89b6def6c46..0af6c8eac74 100644
--- a/providers/.last_release_date.txt
+++ b/providers/.last_release_date.txt
@@ -1 +1 @@
-2026-09-22
+2026-10-02
diff --git a/providers/cncf/kubernetes/docs/changelog.rst
b/providers/cncf/kubernetes/docs/changelog.rst
index 1a8a1ecac2d..6329c882298 100644
--- a/providers/cncf/kubernetes/docs/changelog.rst
+++ b/providers/cncf/kubernetes/docs/changelog.rst
@@ -38,6 +38,7 @@ Features
Bug Fixes
~~~~~~~~~
+* ``Fix KubernetesExecutor not queuing tasks on Airflow 3.0.x (#73764)``
* ``Prevent KubernetesExecutor from launching stale workloads (#69762)``
* ``Fix KubernetesPodOperator discarding successful XCom when sidecar kill
fails (#72068)``
* ``Fix deferrable Kubernetes 401s with a default exec-based kubeconfig
(#72300)``
@@ -47,6 +48,7 @@ Bug Fixes
Misc
~~~~
+* ``Bump the default XCom sidecar image to alpine 3.24.2 (#73629)``
* ``Unify executor workload queues (#63491)``
Doc-only
@@ -58,6 +60,9 @@ Doc-only
.. Below changes are excluded from the changelog. Move them to
appropriate section above if needed. Do not delete the lines(!):
+ * ``Correlate executor task events by attempt UUID (#73916)``
+ * ``Add dedicated tests for cncf.kubernetes secret and k8s_model modules
(#73751)``
+ * ``Prepare providers release 2026-09-22 (#73506)``
* ``Revert "[main] Upgrade important CI environment (#73308)" (#73621)``
* ``[main] Upgrade important CI environment (#73308)``
* ``Remove real sleeps from slow provider unit tests (#73478)``
diff --git a/providers/cncf/kubernetes/provider.yaml
b/providers/cncf/kubernetes/provider.yaml
index 71f92b85b09..4d403b38797 100644
--- a/providers/cncf/kubernetes/provider.yaml
+++ b/providers/cncf/kubernetes/provider.yaml
@@ -23,7 +23,7 @@ description: |
state: ready
lifecycle: production
-source-date-epoch: 1790023613
+source-date-epoch: 1790955848
# Note that those versions are maintained by release manager - do not update
them manually
# with the exception of case where other provider in sources has >= new
provider version.
# In such case adding >= NEW_VERSION and bumping to NEW_VERSION in a provider
have
diff --git a/providers/duckdb/provider.yaml b/providers/duckdb/provider.yaml
index 95284703063..20c40c54758 100644
--- a/providers/duckdb/provider.yaml
+++ b/providers/duckdb/provider.yaml
@@ -21,7 +21,7 @@ name: DuckDB
state: ready
lifecycle: incubation
-source-date-epoch: 1790023613
+source-date-epoch: 1790955848
description: |
`DuckDB <https://duckdb.org/>`__ provider for Apache Airflow. Runs SQL
against an in-process
DuckDB database — in memory, backed by a local file, or hosted by MotherDuck
— and manages
diff --git a/providers/edge3/docs/changelog.rst
b/providers/edge3/docs/changelog.rst
index 47537d6db60..1741821c983 100644
--- a/providers/edge3/docs/changelog.rst
+++ b/providers/edge3/docs/changelog.rst
@@ -41,6 +41,11 @@ Breaking changes
* ``Make EdgeExecutor respect [core] parallelism (#72048)``
+Features
+~~~~~~~~
+
+* ``Add OIDC worker token verification to Edge3 (#72262)``
+
Bug Fixes
~~~~~~~~~
@@ -62,6 +67,8 @@ Doc-only
.. Below changes are excluded from the changelog. Move them to
appropriate section above if needed. Do not delete the lines(!):
+ * ``[main] Upgrade important CI environment (#73629)``
+ * ``Prepare providers release 2026-09-22 (#73506)``
* ``Revert "[main] Upgrade important CI environment (#73308)" (#73621)``
* ``[main] Upgrade important CI environment (#73308)``
* ``Add missing test modules for the edge3 provider (#73111)``
diff --git a/providers/edge3/provider.yaml b/providers/edge3/provider.yaml
index 39334a8315a..b8b809204d4 100644
--- a/providers/edge3/provider.yaml
+++ b/providers/edge3/provider.yaml
@@ -34,7 +34,7 @@ description: |
state: ready
lifecycle: production
-source-date-epoch: 1790023613
+source-date-epoch: 1790955848
build-system: hatchling
# Note that those versions are maintained by release manager - do not update
them manually
@@ -126,7 +126,7 @@ config:
an edge worker. If the issuer serves other workloads, configure
``jwt_issuer`` and a ``jwt_verifier`` to restrict which identities
are
accepted; otherwise any validly signed token from the issuer is
accepted.
- version_added: 4.4.0
+ version_added: 5.0.0
type: string
example: https://idp.example.com/oauth2/v1/keys
default: ~
@@ -138,7 +138,7 @@ config:
configured to decide which identities may act as edge workers
(requests are
rejected otherwise). Set it to bind tokens to your provider. Ignored
when
``trusted_jwks_url`` is empty.
- version_added: 4.4.0
+ version_added: 5.0.0
type: string
example: https://idp.example.com
default: ~
@@ -148,7 +148,7 @@ config:
set. When set, the token must carry a matching ``aud``. When empty,
only
tokens that carry no ``aud`` claim are accepted (a token that does
carry
an ``aud`` is rejected). Ignored when ``trusted_jwks_url`` is empty.
- version_added: 4.4.0
+ version_added: 5.0.0
type: string
example: api
default: ~
@@ -157,7 +157,7 @@ config:
Comma-separated list of JWS signing algorithms accepted for edge
worker
tokens when ``trusted_jwks_url`` is set. Set it to match the
algorithm the
trusted provider signs with. Ignored when ``trusted_jwks_url`` is
empty.
- version_added: 4.4.0
+ version_added: 5.0.0
type: string
example: RS256,RS512
default: RS256
@@ -167,7 +167,7 @@ config:
claims of edge worker tokens issued by a trusted OIDC provider, to
account for
clock skew between the identity provider and the API server. Ignored
when
``trusted_jwks_url`` is empty.
- version_added: 4.4.0
+ version_added: 5.0.0
type: integer
example: ~
default: "30"
@@ -184,7 +184,7 @@ config:
issuer verification is then skipped. When empty (and ``jwt_issuer``
is set)
any token that passes signature, issuer and audience verification is
authorized. Ignored when ``trusted_jwks_url`` is empty.
- version_added: 4.4.0
+ version_added: 5.0.0
type: string
example: my_company.edge_auth.verify_worker_token
default: ~
diff --git a/providers/edge3/src/airflow/providers/edge3/get_provider_info.py
b/providers/edge3/src/airflow/providers/edge3/get_provider_info.py
index 58488f5c327..083895585c1 100644
--- a/providers/edge3/src/airflow/providers/edge3/get_provider_info.py
+++ b/providers/edge3/src/airflow/providers/edge3/get_provider_info.py
@@ -55,42 +55,42 @@ def get_provider_info():
},
"trusted_jwks_url": {
"description": "When set, edge worker tokens are
verified against this JSON Web Key Set\n(JWKS) URL of a trusted OpenID Connect
provider, using asymmetric\nsignatures, instead of the shared ``[api_auth]
jwt_secret``. This lets\nedge workers authenticate with tokens minted by an
external identity\nprovider.\n\nWhen empty (the default) the shared-secret
(symmetric) verification is\nused, so existing deployments are
unaffected.\n\nSecurity note: enabling this disable [...]
- "version_added": "4.4.0",
+ "version_added": "5.0.0",
"type": "string",
"example": "https://idp.example.com/oauth2/v1/keys",
"default": None,
},
"jwt_issuer": {
"description": "Expected ``iss`` claim of edge worker
tokens when ``trusted_jwks_url`` is\nset. Leaving it empty skips issuer
verification, so a token from any issuer\nwhose key is in the JWKS is accepted;
in that case ``jwt_verifier`` must be\nconfigured to decide which identities
may act as edge workers (requests are\nrejected otherwise). Set it to bind
tokens to your provider. Ignored when\n``trusted_jwks_url`` is empty.\n",
- "version_added": "4.4.0",
+ "version_added": "5.0.0",
"type": "string",
"example": "https://idp.example.com",
"default": None,
},
"jwt_audience": {
"description": "Expected ``aud`` claim of edge worker
tokens when ``trusted_jwks_url`` is\nset. When set, the token must carry a
matching ``aud``. When empty, only\ntokens that carry no ``aud`` claim are
accepted (a token that does carry\nan ``aud`` is rejected). Ignored when
``trusted_jwks_url`` is empty.\n",
- "version_added": "4.4.0",
+ "version_added": "5.0.0",
"type": "string",
"example": "api",
"default": None,
},
"jwt_algorithm": {
"description": "Comma-separated list of JWS signing
algorithms accepted for edge worker\ntokens when ``trusted_jwks_url`` is set.
Set it to match the algorithm the\ntrusted provider signs with. Ignored when
``trusted_jwks_url`` is empty.\n",
- "version_added": "4.4.0",
+ "version_added": "5.0.0",
"type": "string",
"example": "RS256,RS512",
"default": "RS256",
},
"jwt_leeway": {
"description": "Number of seconds of leeway allowed
when validating the expiry and issued-at\nclaims of edge worker tokens issued
by a trusted OIDC provider, to account for\nclock skew between the identity
provider and the API server. Ignored when\n``trusted_jwks_url`` is empty.\n",
- "version_added": "4.4.0",
+ "version_added": "5.0.0",
"type": "integer",
"example": None,
"default": "30",
},
"jwt_verifier": {
"description": 'Import path of a callable that
authorizes edge worker tokens issued by a\ntrusted OIDC provider, run after
signature, issuer and audience checks pass.\nIt receives the validated claims
(``dict``) and a request context object\ncarrying the request ``method``, and
returns a mapping with an\n``authorized`` boolean (e.g. ``{"authorized":
True}``); a falsy result or a\nraised exception rejects the request. Use it to
restrict which identities\n(for examp [...]
- "version_added": "4.4.0",
+ "version_added": "5.0.0",
"type": "string",
"example": "my_company.edge_auth.verify_worker_token",
"default": None,