This is an automated email from the ASF dual-hosted git repository.

Miretpl pushed a commit to branch chart/v1-2x-test
in repository https://gitbox.apache.org/repos/asf/airflow.git


The following commit(s) were added to refs/heads/chart/v1-2x-test by this push:
     new 6b059a2d3f0 [chart/v1-2x-test] Fix Helm Chart regression with Kerberos 
in Kubernetes (#70688) (#72984)
6b059a2d3f0 is described below

commit 6b059a2d3f0bf2123988723f4fb7c8028cca3547
Author: Nataneljpwd <[email protected]>
AuthorDate: Thu Sep 24 15:01:02 2026 -0700

    [chart/v1-2x-test] Fix Helm Chart regression with Kerberos in Kubernetes 
(#70688) (#72984)
    
    * [chart/v1-2x-test] Fix Helm Chart regression with Kerberos in Kubernetes 
(#70688)
    
    * fixed helm chart regression with kerberos
    
    * done for kubernetes executor as well
    
    * moved the value around
    
    * address cr comments
    
    * changed the tests
    
    * added tests
    
    * fixed typo
    
    * fix tests
    
    * fixed tests
    
    * fixed the tests
    
    * fixed failing test
    
    ---------
    (cherry picked from commit 3817ee64acaac138baf574f80656bc5cd1fcda77)
    
    Co-authored-by: Nataneljpwd <[email protected]>
    Co-authored-by: Przemysław Mirowski 
<[email protected]>
    
    * fixed comment and tests due to merge of workers
    
    ---------
    
    Co-authored-by: Przemysław Mirowski 
<[email protected]>
---
 chart/files/pod-template-file.kubernetes-helm-yaml |  2 +-
 chart/templates/workers/worker-deployment.yaml     |  2 +-
 chart/values.schema.json                           | 10 +++++++++
 chart/values.yaml                                  |  6 ++++++
 .../airflow_aux/test_pod_template_file.py          | 24 ++++++++++++++++++++++
 .../tests/helm_tests/airflow_core/test_worker.py   | 19 +++++++++++++++++
 6 files changed, 61 insertions(+), 2 deletions(-)

diff --git a/chart/files/pod-template-file.kubernetes-helm-yaml 
b/chart/files/pod-template-file.kubernetes-helm-yaml
index e3406c53796..e5aad0da930 100644
--- a/chart/files/pod-template-file.kubernetes-helm-yaml
+++ b/chart/files/pod-template-file.kubernetes-helm-yaml
@@ -159,7 +159,7 @@ spec:
           readOnly: true
         - name: kerberos-ccache
           mountPath: {{ .Values.kerberos.ccacheMountPath | quote }}
-          readOnly: true
+          readOnly: {{ .Values.workers.kubernetes.readonlyKerberosCache }}
         {{- end }}
     {{- if or .Values.workers.kubernetes.kerberosSidecar.enabled 
.Values.workers.kerberosSidecar.enabled }}
     - name: worker-kerberos
diff --git a/chart/templates/workers/worker-deployment.yaml 
b/chart/templates/workers/worker-deployment.yaml
index 2ae69c0b012..223398993e8 100644
--- a/chart/templates/workers/worker-deployment.yaml
+++ b/chart/templates/workers/worker-deployment.yaml
@@ -336,7 +336,7 @@ spec:
               readOnly: true
             - name: kerberos-ccache
               mountPath: {{ .Values.kerberos.ccacheMountPath | quote }}
-              readOnly: true
+              readOnly: {{ .Values.workers.readonlyKerberosCache }}
             {{- end }}
             {{- if or .Values.dags.persistence.enabled 
.Values.dags.gitSync.enabled }}
               {{- include "airflow_dags_mount" . | nindent 12 }}
diff --git a/chart/values.schema.json b/chart/values.schema.json
index d1cbd1f09aa..91cb14ff783 100644
--- a/chart/values.schema.json
+++ b/chart/values.schema.json
@@ -2908,6 +2908,11 @@
                             ],
                             "default": null
                         },
+                        "readonlyKerberosCache": {
+                            "description": "Should the celery kerberos cache 
be readonly for the workers.",
+                            "type": "boolean",
+                            "default": true
+                        },
                         "revisionHistoryLimit": {
                             "description": "Max number of old Airflow Celery 
workers ReplicaSets to retain.",
                             "type": [
@@ -4446,6 +4451,11 @@
                                 }
                             }
                         },
+                        "readonlyKerberosCache": {
+                            "description": "Should the kubernetes kerberos 
cache be readonly for the workers.",
+                            "type": "boolean",
+                            "default": true
+                        },
                         "resources": {
                             "description": "Resource configuration for pods 
created with pod-template-file.",
                             "type": "object",
diff --git a/chart/values.yaml b/chart/values.yaml
index 41a61171d33..f5aa6aa61f3 100644
--- a/chart/values.yaml
+++ b/chart/values.yaml
@@ -1513,6 +1513,9 @@ workers:
       # Container level lifecycle hooks
       containerLifecycleHooks: {}
 
+    # Should the kerberos-ccache mount be readonly for Celery Workers
+    readonlyKerberosCache: true
+
     # Resource configuration for Airflow Celery workers
     resources: {}
     #  limits:
@@ -1775,6 +1778,9 @@ workers:
       # Container level lifecycle hooks
       containerLifecycleHooks: {}
 
+    # Should the kerberos-ccache mount be readonly for Kubernetes Workers
+    readonlyKerberosCache: true
+
     # Resource configuration for pods created with pod-template-file
     resources: {}
     #  limits:
diff --git a/helm-tests/tests/helm_tests/airflow_aux/test_pod_template_file.py 
b/helm-tests/tests/helm_tests/airflow_aux/test_pod_template_file.py
index 02b611c6bbd..5c2122129df 100644
--- a/helm-tests/tests/helm_tests/airflow_aux/test_pod_template_file.py
+++ b/helm-tests/tests/helm_tests/airflow_aux/test_pod_template_file.py
@@ -1976,6 +1976,30 @@ class TestPodTemplateFile:
         assert initContainers["name"] == "kerberos-init"
         assert initContainers["args"] == ["kerberos", "-o"]
 
+    @pytest.mark.parametrize("readonly_cache", [False, True])
+    def test_kerberos_readonly_cache(self, readonly_cache: bool):
+        docs = render_chart(
+            name="test-release",
+            values={
+                "workers": {
+                    "kubernetes": {
+                        "readonlyKerberosCache": readonly_cache,
+                    },
+                },
+                "kerberos": {"enabled": True},
+            },
+            show_only=["templates/pod-template-file.yaml"],
+            chart_dir=self.temp_chart_dir,
+        )
+
+        assert (
+            jmespath.search(
+                "spec.containers[?name=='base'].volumeMounts | [] | 
[?name=='kerberos-ccache'] | [0].readOnly",
+                docs[0],
+            )
+            == readonly_cache
+        )
+
     @pytest.mark.parametrize(
         ("workers_values", "expected"),
         [
diff --git a/helm-tests/tests/helm_tests/airflow_core/test_worker.py 
b/helm-tests/tests/helm_tests/airflow_core/test_worker.py
index deb922d0e03..0bf168912bc 100644
--- a/helm-tests/tests/helm_tests/airflow_core/test_worker.py
+++ b/helm-tests/tests/helm_tests/airflow_core/test_worker.py
@@ -1428,6 +1428,25 @@ class TestWorker:
             "spec.template.spec.initContainers[?name=='kerberos-init'] | 
[0].lifecycle", docs[0]
         ) == {"postStart": {"exec": {"command": ["echo", "test-release"]}}}
 
+    @pytest.mark.parametrize("readonly_cache", [False, True])
+    def test_kerberos_readonly_cache(self, readonly_cache: bool):
+        docs = render_chart(
+            name="test-release",
+            values={
+                "workers": {"celery": {"readonlyKerberosCache": 
readonly_cache}},
+                "kerberos": {"enabled": True},
+            },
+            show_only=["templates/workers/worker-deployment.yaml"],
+        )
+
+        assert (
+            jmespath.search(
+                "spec.template.spec.containers[?name=='worker'] | 
[0].volumeMounts[?name=='kerberos-ccache'] | [0].readOnly",
+                docs[0],
+            )
+            == readonly_cache
+        )
+
     @pytest.mark.parametrize(
         ("airflow_version", "expected_arg"),
         [

Reply via email to