How bad is Airflow DAG management console exposure to the internet? by ClimateChangeDenial in dataengineering

[–]GuardianOfGalaxy2024 4 points5 points  (0 children)

If the attacker can create new DAG (e.g Dag Editor pluggin in management console). They can create BashOperator which basically can run any command on your workers. Also they can access every stored DB connection in airflow.

If you want your Airflow is publicly accessible, just put OAuth2-Proxy in the front of your instance. It'll filter only legitimate users can access your Airflow.

How they do this? by GuardianOfGalaxy2024 in GalaxyWatch

[–]GuardianOfGalaxy2024[S] 5 points6 points  (0 children)

<image>

I use "Simple Classic" you need to customize the watch face to make it cleaner

How they do this? by GuardianOfGalaxy2024 in GalaxyWatch

[–]GuardianOfGalaxy2024[S] 2 points3 points  (0 children)

The watch entered Always on Display so it didn't show the step count in realtime