Aaryan123456679 commented on code in PR #70242:
URL: https://github.com/apache/airflow/pull/70242#discussion_r3632577380


##########
chart/docs/production-guide.rst:
##########
@@ -260,6 +260,59 @@ generated using the secret key has a short expiry time 
though. Make sure that ti
 that you run Airflow components on is synchronized (for example using ntpd). 
You might get
 "forbidden" errors when the logs are accessed otherwise.
 
+Fernet Key
+----------
+
+Airflow uses a Fernet key to encrypt sensitive data, such as connection 
passwords, stored in the metadata database.
+See :doc:`Fernet <apache-airflow:security/secrets/fernet>` for background on 
how this works. If you do not provide a
+key, the chart generates one and stores it in the 
``<RELEASE_NAME>-fernet-key`` Kubernetes Secret the first time you
+run ``helm install``.
+
+.. warning::
+
+   The chart only creates that Secret on ``helm install`` -- it is not 
re-created or otherwise updated by
+   ``helm upgrade``. This applies both to the auto-generated key and to a key 
you pass through ``fernetKey`` in the
+   values file, so neither can be changed by re-running ``helm upgrade``. To 
rotate the Fernet key you need to manage
+   the Secret yourself, as described below.
+
+To provide your own key, either set ``fernetKey`` in the values file:
+
+.. code-block:: yaml
+   :caption: values.yaml
+
+   fernetKey: <fernet_key>
+
+.. warning::
+
+   Due to security concerns, it is advised to use a Kubernetes Secret instead 
of setting the Fernet key directly in the values file.
+
+or create your own Kubernetes Secret containing a ``fernet-key`` key with a 
base64-encoded value, and point the chart at it with ``fernetKeySecretName``:
+
+.. code-block:: bash
+
+   kubectl create secret generic my-fernet-key 
--from-literal="fernet-key=<fernet_key>"

Review Comment:
   Good point, done -- added a note recommending managing the self-created 
Secret through the normal Infrastructure-as-Code process (GitOps repo, Sealed 
Secret, External Secrets Operator, etc.) so it isn't lost on a cluster 
migration or full redeploy.
   
   ---
   Drafted-by: Claude Code (Sonnet 5) (no human review before posting)



##########
chart/docs/production-guide.rst:
##########
@@ -260,6 +260,59 @@ generated using the secret key has a short expiry time 
though. Make sure that ti
 that you run Airflow components on is synchronized (for example using ntpd). 
You might get
 "forbidden" errors when the logs are accessed otherwise.
 
+Fernet Key
+----------
+
+Airflow uses a Fernet key to encrypt sensitive data, such as connection 
passwords, stored in the metadata database.
+See :doc:`Fernet <apache-airflow:security/secrets/fernet>` for background on 
how this works. If you do not provide a
+key, the chart generates one and stores it in the 
``<RELEASE_NAME>-fernet-key`` Kubernetes Secret the first time you
+run ``helm install``.
+
+.. warning::
+
+   The chart only creates that Secret on ``helm install`` -- it is not 
re-created or otherwise updated by
+   ``helm upgrade``. This applies both to the auto-generated key and to a key 
you pass through ``fernetKey`` in the
+   values file, so neither can be changed by re-running ``helm upgrade``. To 
rotate the Fernet key you need to manage
+   the Secret yourself, as described below.
+
+To provide your own key, either set ``fernetKey`` in the values file:
+
+.. code-block:: yaml
+   :caption: values.yaml
+
+   fernetKey: <fernet_key>
+

Review Comment:
   Added an explicit warning: "Never commit a `values.yaml` containing a 
plaintext Fernet key to version control."
   
   ---
   Drafted-by: Claude Code (Sonnet 5) (no human review before posting)



##########
chart/docs/production-guide.rst:
##########
@@ -260,6 +260,59 @@ generated using the secret key has a short expiry time 
though. Make sure that ti
 that you run Airflow components on is synchronized (for example using ntpd). 
You might get
 "forbidden" errors when the logs are accessed otherwise.
 
+Fernet Key
+----------
+
+Airflow uses a Fernet key to encrypt sensitive data, such as connection 
passwords, stored in the metadata database.
+See :doc:`Fernet <apache-airflow:security/secrets/fernet>` for background on 
how this works. If you do not provide a
+key, the chart generates one and stores it in the 
``<RELEASE_NAME>-fernet-key`` Kubernetes Secret the first time you
+run ``helm install``.
+
+.. warning::
+
+   The chart only creates that Secret on ``helm install`` -- it is not 
re-created or otherwise updated by
+   ``helm upgrade``. This applies both to the auto-generated key and to a key 
you pass through ``fernetKey`` in the
+   values file, so neither can be changed by re-running ``helm upgrade``. To 
rotate the Fernet key you need to manage
+   the Secret yourself, as described below.
+
+To provide your own key, either set ``fernetKey`` in the values file:
+
+.. code-block:: yaml
+   :caption: values.yaml
+
+   fernetKey: <fernet_key>
+
+.. warning::
+
+   Due to security concerns, it is advised to use a Kubernetes Secret instead 
of setting the Fernet key directly in the values file.
+
+or create your own Kubernetes Secret containing a ``fernet-key`` key with a 
base64-encoded value, and point the chart at it with ``fernetKeySecretName``:
+
+.. code-block:: bash
+
+   kubectl create secret generic my-fernet-key 
--from-literal="fernet-key=<fernet_key>"
+
+.. code-block:: yaml
+   :caption: values.yaml
+
+   fernetKeySecretName: my-fernet-key
+
+Rotating the Fernet key
+^^^^^^^^^^^^^^^^^^^^^^^^
+
+Once connections, variables and triggers have been encrypted with a Fernet 
key, changing the key outright makes the
+existing encrypted values unreadable. To rotate the key without losing access 
to them, follow the same procedure as
+:doc:`Rotating encryption keys <apache-airflow:security/secrets/fernet>`, 
applied to the Kubernetes Secret that backs
+``AIRFLOW__CORE__FERNET_KEY``:
+
+#. Make sure you are using a self-managed Secret through 
``fernetKeySecretName`` -- as noted above, the

Review Comment:
   Added explicit `kubectl create secret ... --dry-run=client -o yaml | kubectl 
apply -f -` commands to both rotation steps (setting `new_key,old_key`, then 
trimming back to `new_key`), reusing the same command shown in the creation 
snippet above so it updates the existing Secret in place.
   
   ---
   Drafted-by: Claude Code (Sonnet 5) (no human review before posting)



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to