deepnemesis opened a new issue, #74265:
URL: https://github.com/apache/airflow/issues/74265
### Under which category would you file this issue?
Helm chart
### Apache Airflow version
main (d339bb2767)
### What happened and how to reproduce it?
When the OTel Collector is enabled without an explicit
`otelCollector.securityContexts.container` value, its container renders with
an
empty security context.
Reproduction:
```yaml
otelCollector:
tracesEnabled: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
### What you think should happen instead?
The OTel Collector should use the existing external-container
security-context
defaults.
Explicit `otelCollector.securityContexts.container` values must remain
authoritative, and `securityContexts.disableDefaults: true` must continue to
suppress all defaults.
### Operating System
Ubuntu
### Deployment
Official Apache Airflow Helm Chart
### Apache Airflow Provider(s)
_No response_
### Versions of Apache Airflow Providers
_No response_
### Official Helm Chart version
1.22.0 (latest released)
### Kubernetes Version
Not Applicable — Reproduced Through Helm Rendering
### Helm Chart configuration
otelCollector:
tracesEnabled: true
### Docker Image customizations
Not Applicable
### Anything else?
This is a defense-in-depth consistency improvement, not an undisclosed
security
vulnerability. A fix and Helm rendering tests are ready.
### Are you willing to submit PR?
- [x] Yes I am willing to submit a PR!
### Code of Conduct
- [x] I agree to follow this project's [Code of
Conduct](https://github.com/apache/airflow/blob/main/CODE_OF_CONDUCT.md)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]