Managed Airflow shared responsibility model

Managed Airflow (Gen 3) | Managed Airflow (Gen 2) | Managed Airflow (Legacy Gen 1)

Running a business-critical application on Managed Airflow requires multiple parties to carry different responsibilities. While not an exhaustive list, this document lists the responsibilities for both Google and the Customer sides.

Google Responsibilities

  • Hardening and patching the Managed Airflow environment's components and underlying infrastructure, including Google Kubernetes Engine cluster, Cloud SQL database (that hosts the Airflow database), Pub/Sub, Artifact Registry and other environment elements. In particular, this includes auto-upgrading the underlying infrastructure, including the GKE cluster and Cloud SQL instance of an environment.

  • Protecting access to Managed Airflow environments through incorporating access control provided by IAM, encrypting data at rest by default, providing additional customer-managed storage encryption, encrypting data in transit.

  • Providing Google Cloud integrations for Identity and Access Management, Cloud Audit Logs and Cloud Key Management Service.

  • Restricting and logging Google administrative access to customers' clusters for contractual support purposes with Access Transparency and Access Approval.

  • Publishing information about backward incompatible changes between Managed Airflow and Airflow versions in Managed Airflow Release Notes.

  • Keeping Managed Airflow documentation up to date:

    • Providing description of all functionalities provided by Managed Airflow.

    • Providing troubleshooting instructions that help to keep environments in a healthy state.

    • Publishing information about known issues with workarounds (if they exist).

  • Resolving critical security incidents related to Managed Airflow environments and Airflow images provided by Managed Airflow (excluding customer-installed Python packages) by delivering new environment versions addressing the incidents.

  • Depending on customer's Support Plan, troubleshooting of Managed Airflow environment health issues.

  • Maintaining and expanding the functionality of the Managed Airflow Terraform provider.

  • Cooperating with the Apache Airflow community to maintain and develop Google Airflow operators.

  • Troubleshooting and, if possible, fixing issues in Airflow core functionalities.

Customer responsibilities

  • Upgrading to new Managed Airflow and Airflow versions to keep support for the product and to resolve security issues once Managed Airflow service publishes a Managed Airflow version that addresses the issues.

  • Maintaining the DAGs code to keep it compatible with the used Airflow version.

  • Keeping the environment's GKE cluster configuration intact, particularly including its auto-upgrade feature.

  • Maintaining proper permissions in IAM for the environment's service account. Particularly, keeping permissions required by the