Skip to content

Clean-up of our new security page#32951

Merged
jedcunningham merged 2 commits into
apache:mainfrom
potiuk:cleanup-security-page
Aug 1, 2023
Merged

Clean-up of our new security page#32951
jedcunningham merged 2 commits into
apache:mainfrom
potiuk:cleanup-security-page

Conversation

@potiuk

@potiuk potiuk commented Jul 30, 2023

Copy link
Copy Markdown
Member

The new security page of ours looked a bit messy - mixing the security model, information about security patches and index of "all other" security topics.

This change cleans it up quite a bit:

  • "Airflow Security Model" and "Releasing security patches" are separated out - each to a separate page focusing only on model/release respectively

  • The index now does not contain everything mixed together - both in navigation and main page index

  • The model and releasing are also explicitly called out in the intro paragraphs for the securtiy index, underlying their importance - explaining to the reader that they should look at them first to understand the important topics mentioned in them.


^ Add meaningful description above

Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in newsfragments.

@potiuk

potiuk commented Jul 30, 2023

Copy link
Copy Markdown
Member Author

Compare the current page:

image

With the new one:

image

The new security page of ours looked a bit messy - mixing the security
model, information about security patches and index of "all other"
security topics.

This change cleans it up quite a bit:

* "Airflow Security Model" and "Releasing security patches" are
  separated out - each to a separate page focusing only on model/release
  respectively

* The index now does not contain everything mixed together - both in
  navigation and main page index

* The model and releasing are also explicitly called out in the intro
  paragraphs for the securtiy index, underlying their importance -
  explaining to the reader that they should look at them first to
  understand the important topics mentioned in them.
@potiuk
potiuk force-pushed the cleanup-security-page branch from 0d04b88 to 5972383 Compare July 30, 2023 16:32
Comment thread docs/apache-airflow/security/index.rst Outdated
Comment thread docs/apache-airflow/security/index.rst Outdated
Comment thread docs/apache-airflow/security/releasing_security_patches.rst Outdated
Comment thread docs/apache-airflow/security/releasing_security_patches.rst Outdated
Comment thread docs/apache-airflow/security/releasing_security_patches.rst Outdated
Comment thread docs/apache-airflow/security/security_model.rst Outdated
Comment thread docs/apache-airflow/security/security_model.rst Outdated
Comment thread docs/apache-airflow/security/security_model.rst Outdated
Comment thread docs/apache-airflow/security/security_model.rst Outdated
Comment thread docs/apache-airflow/security/security_model.rst Outdated
@jedcunningham

Copy link
Copy Markdown
Member

Overall looks good. Feel free to take or leave all of these suggestions.

@potiuk

potiuk commented Jul 31, 2023

Copy link
Copy Markdown
Member Author

Overall looks good. Feel free to take or leave all of these suggestions.

I'll take 'em

@potiuk

potiuk commented Jul 31, 2023

Copy link
Copy Markdown
Member Author

All things addressed @jedcunningham.

clearing, re-running, triggering DAGs, and changing parameters.
Depending on access restrictions, they may also have access to
editing variables and viewing Airflow configuration. They should not
have access to sensitive system-level information or connections, and

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll start a separate PR for my suggestions here 👍

@jedcunningham
jedcunningham merged commit e79769c into apache:main Aug 1, 2023
@potiuk

potiuk commented Aug 1, 2023

Copy link
Copy Markdown
Member Author

cool

@ephraimbuddy ephraimbuddy added the type:doc-only Changelog: Doc Only label Aug 2, 2023
@potiuk
potiuk deleted the cleanup-security-page branch November 17, 2023 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants