Skip to content

Document Kubernetes RBAC permissions - #68716

Merged
Miretpl merged 5 commits into
apache:mainfrom
dhkim1920:docs/kubernetes-privileges-40210
Aug 1, 2026
Merged

Document Kubernetes RBAC permissions#68716
Miretpl merged 5 commits into
apache:mainfrom
dhkim1920:docs/kubernetes-privileges-40210

Conversation

@dhkim1920

@dhkim1920 dhkim1920 commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Document Kubernetes RBAC permissions for the CNCF Kubernetes provider.

This adds a new guide describing the Kubernetes API permissions needed by KubernetesExecutor, KubernetesPodOperator, KubernetesJobOperator, cleanup jobs, and custom resource operators. It also links the guide from related Kubernetes provider docs.

closes: #40210

Validation performed:

  • prek run --files providers/cncf/kubernetes/docs/kubernetes_rbac.rst providers/cncf/kubernetes/docs/index.rst providers/cncf/kubernetes/docs/kubernetes_executor.rst providers/cncf/kubernetes/docs/local_kubernetes_executor.rst providers/cncf/kubernetes/docs/operators.rst
  • git diff --check
  • breeze build-docs --docs-only cncf.kubernetes

Was generative AI tooling used to co-author this PR?
  • Yes — Codex (GPT-5)

Generated-by: Codex (GPT-5) following the guidelines

@boring-cyborg boring-cyborg Bot added area:providers kind:documentation provider:cncf-kubernetes Kubernetes (k8s) provider related issues labels Jun 18, 2026
@boring-cyborg

boring-cyborg Bot commented Jun 18, 2026

Copy link
Copy Markdown

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example Dag that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

@dhkim1920
dhkim1920 marked this pull request as ready for review June 18, 2026 14:14
@potiuk potiuk added the ready for maintainer review Set after triaging when all criteria pass. label Jul 11, 2026
Comment thread providers/cncf/kubernetes/docs/kubernetes_rbac.rst Outdated
Comment thread providers/cncf/kubernetes/docs/kubernetes_rbac.rst Outdated
The provider guide duplicated Helm-specific details that could drift as the chart evolves. Sphinx examples should also follow the project's standard indentation.
@dhkim1920
dhkim1920 force-pushed the docs/kubernetes-privileges-40210 branch 2 times, most recently from c1883cc to be11a5b Compare August 1, 2026 04:38
@dhkim1920
dhkim1920 requested a review from bugraoz93 as a code owner August 1, 2026 04:38
@dhkim1920
dhkim1920 force-pushed the docs/kubernetes-privileges-40210 branch from be11a5b to aa100b5 Compare August 1, 2026 07:39
The documented access scopes should match the behavior of the Kubernetes components and avoid overstating permissions.
@dhkim1920
dhkim1920 force-pushed the docs/kubernetes-privileges-40210 branch 2 times, most recently from ae4edc8 to 44349db Compare August 1, 2026 09:36
Keeping permission details in one dedicated page avoids documentation drift and makes future updates easier to maintain.
@dhkim1920
dhkim1920 force-pushed the docs/kubernetes-privileges-40210 branch from 44349db to 535e87c Compare August 1, 2026 11:21
@dhkim1920
dhkim1920 requested a review from Miretpl August 1, 2026 11:40
@Miretpl
Miretpl merged commit 0b313f9 into apache:main Aug 1, 2026
95 checks passed
@dhkim1920
dhkim1920 deleted the docs/kubernetes-privileges-40210 branch August 2, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:providers kind:documentation provider:cncf-kubernetes Kubernetes (k8s) provider related issues ready for maintainer review Set after triaging when all criteria pass.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provide access privilege required for cncf.kubernetes operators/executors

3 participants