Securing Orchestration

Securing the Orchestration Layer

An orchestrator holds credentials for every system it touches, runs whatever its DAG folder contains and answers an API that can start any of it. Airflow in Docker Compose's defaults (passwords in the compose file, airflow/airflow, a fixed JWT secret) were for a laptop; demos/ch07/security/final.sh rebuilds the stack with each layer below fixed, and every output here comes from it.

Subsections