Skip to content

Flag deprecated expose_config=non-sensitive-only in config lint - #72507

Open
FrankYang0529 wants to merge 1 commit into
apache:mainfrom
FrankYang0529:airflow-config-lint-expose-config-non-sensitive-only
Open

Flag deprecated expose_config=non-sensitive-only in config lint#72507
FrankYang0529 wants to merge 1 commit into
apache:mainfrom
FrankYang0529:airflow-config-lint-expose-config-non-sensitive-only

Conversation

@FrankYang0529

@FrankYang0529 FrankYang0529 commented Sep 4, 2026

Copy link
Copy Markdown
Member

Why

  • [api] expose_config = non-sensitive-only was deprecated in Treat non-sensitive-only as true and always mask sensitive values in public api's #59880 (3.2.0), but the only signal is a DeprecationWarning that the api-server emits once per process while serving GET /config.
  • On a config file that still carries non-sensitive-only, airflow config lint and airflowctl config lint report "No issues found in your airflow.cfg. It is ready for Airflow 3!".

How

  • Add a value-level ConfigChange rule (was_removed=False, is_invalid_if="non-sensitive-only") to both CONFIGS_CHANGES lists, following the existing rule.

Verification

  • Unit test
    • uv run --frozen --project airflow-core pytest airflow-core/tests/unit/cli/commands/test_config_command.py
    • uv run --frozen --project airflow-ctl pytest airflow-ctl/tests/airflow_ctl/ctl/commands/test_config_command.py
  • Integration test:
export AIRFLOW_HOME=/tmp/airflow-lint && mkdir -p $AIRFLOW_HOME
.venv/bin/airflow config lint --section api
sed -i '' 's/^expose_config = .*/expose_config = non-sensitive-only/' $AIRFLOW_HOME/airflow.cfg && grep -n '^expose_config' $AIRFLOW_HOME/airflow.cfg
.venv/bin/airflow config lint

On main branch, it shows No issues found in your airflow.cfg. It is ready for Airflow 3!. In this branch, it shows:

Found issues in your airflow.cfg:
  - Invalid value `non-sensitive-only` set for `expose_config` configuration parameter in `api` section. This value is deprecated and treated as
`True`. Set `expose_config` to `True` instead; sensitive configuration values are always masked.

Please update your configuration file accordingly.

Was generative AI tooling used to co-author this PR?
  • Yes - Claude Code

  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

Signed-off-by: PoAn Yang <payang@apache.org>
@FrankYang0529
FrankYang0529 force-pushed the airflow-config-lint-expose-config-non-sensitive-only branch from 300ac17 to 7a105ae Compare September 4, 2026 11:34
@FrankYang0529
FrankYang0529 marked this pull request as ready for review September 4, 2026 12:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant