deepnemesis opened a new issue, #74270:
URL: https://github.com/apache/airflow/issues/74270

   ### Under which category would you file this issue?
   
   Helm chart
   
   ### Apache Airflow version
   
   main (20f90a6e10)
   
   ### What happened and how to reproduce it?
   
   When DAG git-sync is enabled without an explicit container security context,
   both the git-sync sidecar and init container receive only `runAsUser`.
   
   Configuration:
   
   ```yaml
   dags:
     gitSync:
       enabled: true
   ```
   
   The rendered security context lacks:
   ```yaml
   allowPrivilegeEscalation: false
   capabilities:
     drop:
       - ALL
   ```
   This remains reproducible on the current main branch. It is related to the 
previously closed stale issue #35350, but this proposal only addresses secure 
defaults rather than propagating the global container context.
   
   ### What you think should happen instead?
   
   Both git-sync container variants should retain their dedicated UID while 
disabling privilege escalation and dropping all Linux capabilities by default.
   
   Explicit dags.gitSync.securityContexts.container values must remain 
authoritative, and securityContexts.disableDefaults: true must continue to omit 
all defaults.
   
   ### Operating System
   
   _No response_
   
   ### Deployment
   
   Official Apache Airflow Helm Chart
   
   ### Apache Airflow Provider(s)
   
   _No response_
   
   ### Versions of Apache Airflow Providers
   
   _No response_
   
   ### Official Helm Chart version
   
   main (development)
   
   ### Kubernetes Version
   
   Not Applicable — Reproduced Through Helm Rendering
   
   ### Helm Chart configuration
   
   _No response_
   
   ### Docker Image customizations
   
   _No response_
   
   ### Anything else?
   
   _No response_
   
   ### Are you willing to submit PR?
   
   - [x] Yes I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [x] I agree to follow this project's [Code of 
Conduct](https://github.com/apache/airflow/blob/main/CODE_OF_CONDUCT.md)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to