Skip to content

Conversation

@ananich
Copy link

@ananich ananich commented Jan 5, 2026

Problem

Currently, the Airflow worker log server (serve_logs.py) is hardcoded to bind to all available interfaces (0.0.0.0 or [::]) via socket.has_dualstack_ipv6(). This exposes port 8793 to the entire network by default, creating a potential security risk where task logs could be intercepted or scanned by unauthorized entities.

Proposed Change

This PR modifies the log server initialization to respect the WORKER_LOG_SERVER_HOST configuration variable. If this variable is set (e.g., to 127.0.0.1), the server will bind specifically to that address. If not set, it falls back to the existing dual-stack wildcard logic to maintain backward compatibility.

@boring-cyborg
Copy link

boring-cyborg bot commented Jan 5, 2026

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide (https://github.com/apache/airflow/blob/main/contributing-docs/README.rst)
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example DAG that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: [email protected]
    Slack: https://s.apache.org/airflow-slack

setproctitle("airflow serve-logs")

port = port or conf.getint("logging", "WORKER_LOG_SERVER_PORT")
host = conf.get("logging", "WORKER_LOG_SERVER_HOST", fallback=host)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants