Skip to content

Clarify sensitive data handling in security model#70424

Open
bharatkhanna-dev wants to merge 2 commits into
apache:mainfrom
bharatkhanna-dev:docs/clarify-sensitive-data-security-model
Open

Clarify sensitive data handling in security model#70424
bharatkhanna-dev wants to merge 2 commits into
apache:mainfrom
bharatkhanna-dev:docs/clarify-sensitive-data-security-model

Conversation

@bharatkhanna-dev

Copy link
Copy Markdown

What

Clarify the sensitive-information section of the security model so it matches Airflow 3's current behavior.

Why

The previous wording said sensitive information would not be exposed through the API, UI, or airflowctl, while the same section documented authorized access through the Task Execution API. The updated wording distinguishes default masking from authorized execution-time access and makes the CLI behavior explicit.

Validation

  • git diff --check
  • Focused content checks for the updated security-model wording

This is a documentation-only change; no runtime behavior is affected.

Closes #59839

Generative AI disclosure

Generative AI tools were used to help research the issue, draft the wording, and prepare this pull request. I reviewed the final change and validation results.

@boring-cyborg

boring-cyborg Bot commented Jul 25, 2026

Copy link
Copy Markdown

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example Dag that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

@bharatkhanna-dev
bharatkhanna-dev marked this pull request as ready for review July 25, 2026 03:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update Security model documentation to explain our approach for sensitive data exposure over API

1 participant