This is an automated email from the ASF dual-hosted git repository.
Miretpl pushed a commit to branch chart/v1-2x-test
in repository https://gitbox.apache.org/repos/asf/airflow.git
The following commit(s) were added to refs/heads/chart/v1-2x-test by this push:
new 6b059a2d3f0 [chart/v1-2x-test] Fix Helm Chart regression with Kerberos
in Kubernetes (#70688) (#72984)
6b059a2d3f0 is described below
commit 6b059a2d3f0bf2123988723f4fb7c8028cca3547
Author: Nataneljpwd <[email protected]>
AuthorDate: Thu Sep 24 15:01:02 2026 -0700
[chart/v1-2x-test] Fix Helm Chart regression with Kerberos in Kubernetes
(#70688) (#72984)
* [chart/v1-2x-test] Fix Helm Chart regression with Kerberos in Kubernetes
(#70688)
* fixed helm chart regression with kerberos
* done for kubernetes executor as well
* moved the value around
* address cr comments
* changed the tests
* added tests
* fixed typo
* fix tests
* fixed tests
* fixed the tests
* fixed failing test
---------
(cherry picked from commit 3817ee64acaac138baf574f80656bc5cd1fcda77)
Co-authored-by: Nataneljpwd <[email protected]>
Co-authored-by: Przemysław Mirowski
<[email protected]>
* fixed comment and tests due to merge of workers
---------
Co-authored-by: Przemysław Mirowski
<[email protected]>
---
chart/files/pod-template-file.kubernetes-helm-yaml | 2 +-
chart/templates/workers/worker-deployment.yaml | 2 +-
chart/values.schema.json | 10 +++++++++
chart/values.yaml | 6 ++++++
.../airflow_aux/test_pod_template_file.py | 24 ++++++++++++++++++++++
.../tests/helm_tests/airflow_core/test_worker.py | 19 +++++++++++++++++
6 files changed, 61 insertions(+), 2 deletions(-)
diff --git a/chart/files/pod-template-file.kubernetes-helm-yaml
b/chart/files/pod-template-file.kubernetes-helm-yaml
index e3406c53796..e5aad0da930 100644
--- a/chart/files/pod-template-file.kubernetes-helm-yaml
+++ b/chart/files/pod-template-file.kubernetes-helm-yaml
@@ -159,7 +159,7 @@ spec:
readOnly: true
- name: kerberos-ccache
mountPath: {{ .Values.kerberos.ccacheMountPath | quote }}
- readOnly: true
+ readOnly: {{ .Values.workers.kubernetes.readonlyKerberosCache }}
{{- end }}
{{- if or .Values.workers.kubernetes.kerberosSidecar.enabled
.Values.workers.kerberosSidecar.enabled }}
- name: worker-kerberos
diff --git a/chart/templates/workers/worker-deployment.yaml
b/chart/templates/workers/worker-deployment.yaml
index 2ae69c0b012..223398993e8 100644
--- a/chart/templates/workers/worker-deployment.yaml
+++ b/chart/templates/workers/worker-deployment.yaml
@@ -336,7 +336,7 @@ spec:
readOnly: true
- name: kerberos-ccache
mountPath: {{ .Values.kerberos.ccacheMountPath | quote }}
- readOnly: true
+ readOnly: {{ .Values.workers.readonlyKerberosCache }}
{{- end }}
{{- if or .Values.dags.persistence.enabled
.Values.dags.gitSync.enabled }}
{{- include "airflow_dags_mount" . | nindent 12 }}
diff --git a/chart/values.schema.json b/chart/values.schema.json
index d1cbd1f09aa..91cb14ff783 100644
--- a/chart/values.schema.json
+++ b/chart/values.schema.json
@@ -2908,6 +2908,11 @@
],
"default": null
},
+ "readonlyKerberosCache": {
+ "description": "Should the celery kerberos cache
be readonly for the workers.",
+ "type": "boolean",
+ "default": true
+ },
"revisionHistoryLimit": {
"description": "Max number of old Airflow Celery
workers ReplicaSets to retain.",
"type": [
@@ -4446,6 +4451,11 @@
}
}
},
+ "readonlyKerberosCache": {
+ "description": "Should the kubernetes kerberos
cache be readonly for the workers.",
+ "type": "boolean",
+ "default": true
+ },
"resources": {
"description": "Resource configuration for pods
created with pod-template-file.",
"type": "object",
diff --git a/chart/values.yaml b/chart/values.yaml
index 41a61171d33..f5aa6aa61f3 100644
--- a/chart/values.yaml
+++ b/chart/values.yaml
@@ -1513,6 +1513,9 @@ workers:
# Container level lifecycle hooks
containerLifecycleHooks: {}
+ # Should the kerberos-ccache mount be readonly for Celery Workers
+ readonlyKerberosCache: true
+
# Resource configuration for Airflow Celery workers
resources: {}
# limits:
@@ -1775,6 +1778,9 @@ workers:
# Container level lifecycle hooks
containerLifecycleHooks: {}
+ # Should the kerberos-ccache mount be readonly for Kubernetes Workers
+ readonlyKerberosCache: true
+
# Resource configuration for pods created with pod-template-file
resources: {}
# limits:
diff --git a/helm-tests/tests/helm_tests/airflow_aux/test_pod_template_file.py
b/helm-tests/tests/helm_tests/airflow_aux/test_pod_template_file.py
index 02b611c6bbd..5c2122129df 100644
--- a/helm-tests/tests/helm_tests/airflow_aux/test_pod_template_file.py
+++ b/helm-tests/tests/helm_tests/airflow_aux/test_pod_template_file.py
@@ -1976,6 +1976,30 @@ class TestPodTemplateFile:
assert initContainers["name"] == "kerberos-init"
assert initContainers["args"] == ["kerberos", "-o"]
+ @pytest.mark.parametrize("readonly_cache", [False, True])
+ def test_kerberos_readonly_cache(self, readonly_cache: bool):
+ docs = render_chart(
+ name="test-release",
+ values={
+ "workers": {
+ "kubernetes": {
+ "readonlyKerberosCache": readonly_cache,
+ },
+ },
+ "kerberos": {"enabled": True},
+ },
+ show_only=["templates/pod-template-file.yaml"],
+ chart_dir=self.temp_chart_dir,
+ )
+
+ assert (
+ jmespath.search(
+ "spec.containers[?name=='base'].volumeMounts | [] |
[?name=='kerberos-ccache'] | [0].readOnly",
+ docs[0],
+ )
+ == readonly_cache
+ )
+
@pytest.mark.parametrize(
("workers_values", "expected"),
[
diff --git a/helm-tests/tests/helm_tests/airflow_core/test_worker.py
b/helm-tests/tests/helm_tests/airflow_core/test_worker.py
index deb922d0e03..0bf168912bc 100644
--- a/helm-tests/tests/helm_tests/airflow_core/test_worker.py
+++ b/helm-tests/tests/helm_tests/airflow_core/test_worker.py
@@ -1428,6 +1428,25 @@ class TestWorker:
"spec.template.spec.initContainers[?name=='kerberos-init'] |
[0].lifecycle", docs[0]
) == {"postStart": {"exec": {"command": ["echo", "test-release"]}}}
+ @pytest.mark.parametrize("readonly_cache", [False, True])
+ def test_kerberos_readonly_cache(self, readonly_cache: bool):
+ docs = render_chart(
+ name="test-release",
+ values={
+ "workers": {"celery": {"readonlyKerberosCache":
readonly_cache}},
+ "kerberos": {"enabled": True},
+ },
+ show_only=["templates/workers/worker-deployment.yaml"],
+ )
+
+ assert (
+ jmespath.search(
+ "spec.template.spec.containers[?name=='worker'] |
[0].volumeMounts[?name=='kerberos-ccache'] | [0].readOnly",
+ docs[0],
+ )
+ == readonly_cache
+ )
+
@pytest.mark.parametrize(
("airflow_version", "expected_arg"),
[