From d43e0904dd8187ee4143230bebc4742002fd7be9 Mon Sep 17 00:00:00 2001 From: Artur Kuznetsov Date: Wed, 7 Oct 2026 15:13:56 +0400 Subject: [PATCH 1/3] docs(config): fix CODE_EXECUTOR_SECURITY_THRESHOLD semantics and default EPMCDME-13877 Generated with AI Co-Authored-By: codemie-ai --- .../codemie/api-configuration.md | 22 ++++++++++----- .../update/release-notes/release-notes.md | 27 +++++++++++++++++++ ...ity-threshold-after-upgrading-to-2-57-0.md | 19 +++++++++++++ ...ld-control-and-which-value-should-i-use.md | 16 +++++++++++ 4 files changed, 77 insertions(+), 7 deletions(-) create mode 100644 faq/how-do-i-migrate-code-executor-security-threshold-after-upgrading-to-2-57-0.md create mode 100644 faq/what-does-code-executor-security-threshold-control-and-which-value-should-i-use.md diff --git a/docs/admin/configuration/codemie/api-configuration.md b/docs/admin/configuration/codemie/api-configuration.md index 502df054..90bf7cbc 100644 --- a/docs/admin/configuration/codemie/api-configuration.md +++ b/docs/admin/configuration/codemie/api-configuration.md @@ -1156,7 +1156,7 @@ Configure secure Python code execution in isolated Kubernetes pods for running u | `CODE_EXECUTOR_RUN_AS_USER` | integer | `1001` | Unix user ID for pod security context (non-root execution) | | `CODE_EXECUTOR_RUN_AS_GROUP` | integer | `1001` | Unix group ID for pod security context | | `CODE_EXECUTOR_FS_GROUP` | integer | `1001` | Filesystem group ID for pod volume permissions | -| `CODE_EXECUTOR_SECURITY_THRESHOLD` | string | `"LOW"` | Required security policy threshold: `SAFE`, `LOW`, `MEDIUM`, `HIGH` | +| `CODE_EXECUTOR_SECURITY_THRESHOLD` | string | `"HIGH"` | Security policy threshold controlling which operations are permitted in the sandbox: `SAFE` (most permissive), `LOW`, `MEDIUM`, `HIGH` (most restrictive). Higher values block more operations. See Security Considerations below. | | `CODE_EXECUTOR_YAML_POLICY_PATH` | string | `""` | Path to custom YAML security policy file (optional, overrides default policy) | | `CODE_EXECUTOR_VERBOSE` | boolean | `false` | Enable verbose logging for executor debugging | | `CODE_EXECUTOR_KEEP_TEMPLATE` | boolean | `true` | Persist pod template after execution for performance optimization | @@ -1173,13 +1173,21 @@ Example: to dedicate a kata-containers node pool to code execution, taint the po This is independent of the chart's top-level `tolerations` value: that one applies only to the CodeMie API Deployment/Rollout pod and has no effect on Code Executor Job pods, which are created dynamically at runtime and read their own tolerations from `CODE_EXECUTOR_TOLERATIONS`. -**Security Threshold:** The security policy controls what operations are allowed: +**Security Threshold:** `CODE_EXECUTOR_SECURITY_THRESHOLD` directly represents policy strictness — higher values enforce stricter restrictions: -- `SAFE` (0): Most permissive, blocks almost nothing -- `LOW` (1): Allows common operations like HTTP requests (recommended default) -- `MEDIUM` (2): More restrictive, blocks potentially dangerous operations -- `HIGH` (3): Very restrictive, only allows safe operations - ::: +- `SAFE`: Most permissive, blocks almost nothing +- `LOW`: Allows common operations such as HTTP requests +- `MEDIUM`: More restrictive, blocks potentially dangerous operations +- `HIGH` (default): Most restrictive, only allows safe operations + +:::note Migration note (2.57.0) +The semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected in 2.57.0. Previously the values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the most permissive — contradicting the parameter name. + +The default was also changed from `LOW` to `HIGH`. Under the corrected semantics, `HIGH` enforces exactly what `LOW` enforced before, so deployments that do not set `CODE_EXECUTOR_SECURITY_THRESHOLD` explicitly keep their current enforcement level unchanged. + +**Action required:** Any deployment that explicitly sets `CODE_EXECUTOR_SECURITY_THRESHOLD=LOW` to obtain strict enforcement must change it to `HIGH`. +::: +::: ### File Datasource Multiprocessing diff --git a/docs/admin/update/release-notes/release-notes.md b/docs/admin/update/release-notes/release-notes.md index 5401157c..ba17995b 100644 --- a/docs/admin/update/release-notes/release-notes.md +++ b/docs/admin/update/release-notes/release-notes.md @@ -13,6 +13,33 @@ This page provides information about updated third-party components and configur --- +### CodeMie 2.57.0 {#v2-57-0} + +
+Release details + +**Release Date:** TBD · [GitHub Tag ↗](https://github.com/codemie-ai/codemie/releases/tag/2.57.0) + +

Third-Party Component Updates

+ +No third-party component updates in this release. + +

Configuration Changes

+ +1. **Code Executor** — `CODE_EXECUTOR_SECURITY_THRESHOLD` semantics corrected — only applies if the Code Executor tool is enabled: + + The values of `CODE_EXECUTOR_SECURITY_THRESHOLD` previously behaved inverted (`LOW` enforced the strictest policy, `HIGH` the most permissive). The semantics now match the parameter name: `LOW` is permissive and `HIGH` is the most restrictive. + + The default value has also changed from `LOW` to `HIGH`. Under the corrected semantics, `HIGH` enforces exactly what `LOW` enforced before, so deployments that do not set this variable explicitly keep their current enforcement level unchanged. + + :::warning + Any deployment that explicitly sets `CODE_EXECUTOR_SECURITY_THRESHOLD=LOW` to obtain strict enforcement must change it to `HIGH`. + ::: + +
+ +--- + ### CodeMie 2.56.0 {#v2-56-0}
diff --git a/faq/how-do-i-migrate-code-executor-security-threshold-after-upgrading-to-2-57-0.md b/faq/how-do-i-migrate-code-executor-security-threshold-after-upgrading-to-2-57-0.md new file mode 100644 index 00000000..a2c56c51 --- /dev/null +++ b/faq/how-do-i-migrate-code-executor-security-threshold-after-upgrading-to-2-57-0.md @@ -0,0 +1,19 @@ +# How do I migrate CODE_EXECUTOR_SECURITY_THRESHOLD after upgrading to 2.57.0? + +In 2.57.0 the semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected. Previously the +values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the most permissive. +The values now match their names: `LOW` is permissive and `HIGH` is the most restrictive. + +The default was also changed from `LOW` to `HIGH`. Under the corrected semantics `HIGH` enforces +exactly what `LOW` enforced before, so deployments that do not set this variable explicitly are +unaffected. + +**Action required only if** the deployment explicitly sets `CODE_EXECUTOR_SECURITY_THRESHOLD=LOW` +to obtain strict enforcement — change it to `HIGH`. + +No other changes are needed for deployments relying on the default. + +## Sources + +- [Code Executor & Python Sandbox — API Configuration](https://docs.codemie.ai/admin/configuration/codemie/api-configuration#code-executor--python-sandbox) +- [Release Notes 2.57.0](https://docs.codemie.ai/admin/update/release-notes#v2-57-0) diff --git a/faq/what-does-code-executor-security-threshold-control-and-which-value-should-i-use.md b/faq/what-does-code-executor-security-threshold-control-and-which-value-should-i-use.md new file mode 100644 index 00000000..69f196e7 --- /dev/null +++ b/faq/what-does-code-executor-security-threshold-control-and-which-value-should-i-use.md @@ -0,0 +1,16 @@ +# What does CODE_EXECUTOR_SECURITY_THRESHOLD control and which value should I use? + +`CODE_EXECUTOR_SECURITY_THRESHOLD` sets the strictness of the security policy applied to Python +code running inside the Code Executor sandbox. Higher values block more operations: + +- `SAFE` — most permissive, blocks almost nothing +- `LOW` — allows common operations such as HTTP requests +- `MEDIUM` — more restrictive, blocks potentially dangerous operations +- `HIGH` (default) — most restrictive, only allows safe operations + +For production deployments the default `HIGH` is recommended. Lowering the threshold permits +additional operations but reduces the isolation guarantees of the sandbox. + +## Sources + +- [Code Executor & Python Sandbox — API Configuration](https://docs.codemie.ai/admin/configuration/codemie/api-configuration#code-executor--python-sandbox) From c315c5fd258d233a4a8aed0e7a81a8a3af2dd688 Mon Sep 17 00:00:00 2001 From: Artur Kuznetsov Date: Wed, 7 Oct 2026 15:57:10 +0400 Subject: [PATCH 2/3] docs(config): remove version references from security threshold migration notes Generated with AI Co-Authored-By: codemie-ai --- docs/admin/configuration/codemie/api-configuration.md | 4 ++-- docs/admin/update/release-notes/release-notes.md | 8 ++++++-- ...or-security-threshold-after-upgrading-to-2-57-0.md | 11 ++++++----- 3 files changed, 14 insertions(+), 9 deletions(-) diff --git a/docs/admin/configuration/codemie/api-configuration.md b/docs/admin/configuration/codemie/api-configuration.md index 90bf7cbc..1305849e 100644 --- a/docs/admin/configuration/codemie/api-configuration.md +++ b/docs/admin/configuration/codemie/api-configuration.md @@ -1180,8 +1180,8 @@ This is independent of the chart's top-level `tolerations` value: that one appli - `MEDIUM`: More restrictive, blocks potentially dangerous operations - `HIGH` (default): Most restrictive, only allows safe operations -:::note Migration note (2.57.0) -The semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected in 2.57.0. Previously the values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the most permissive — contradicting the parameter name. +:::note Migration note +The semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected in a recent release. Previously the values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the most permissive — contradicting the parameter name. The default was also changed from `LOW` to `HIGH`. Under the corrected semantics, `HIGH` enforces exactly what `LOW` enforced before, so deployments that do not set `CODE_EXECUTOR_SECURITY_THRESHOLD` explicitly keep their current enforcement level unchanged. diff --git a/docs/admin/update/release-notes/release-notes.md b/docs/admin/update/release-notes/release-notes.md index ba17995b..561a6a83 100644 --- a/docs/admin/update/release-notes/release-notes.md +++ b/docs/admin/update/release-notes/release-notes.md @@ -13,12 +13,16 @@ This page provides information about updated third-party components and configur --- -### CodeMie 2.57.0 {#v2-57-0} +{/_ TODO: replace heading and anchor with the actual release version once announced, e.g. ### CodeMie X.Y.Z {#vX-Y-Z} _/} + +### Upcoming Release {#upcoming}
Release details -**Release Date:** TBD · [GitHub Tag ↗](https://github.com/codemie-ai/codemie/releases/tag/2.57.0) +{/_ TODO: replace TBD with the actual release date and add the GitHub tag link once the release is published _/} + +**Release Date:** TBD

Third-Party Component Updates

diff --git a/faq/how-do-i-migrate-code-executor-security-threshold-after-upgrading-to-2-57-0.md b/faq/how-do-i-migrate-code-executor-security-threshold-after-upgrading-to-2-57-0.md index a2c56c51..066f8e5c 100644 --- a/faq/how-do-i-migrate-code-executor-security-threshold-after-upgrading-to-2-57-0.md +++ b/faq/how-do-i-migrate-code-executor-security-threshold-after-upgrading-to-2-57-0.md @@ -1,8 +1,9 @@ -# How do I migrate CODE_EXECUTOR_SECURITY_THRESHOLD after upgrading to 2.57.0? +# How do I migrate CODE_EXECUTOR_SECURITY_THRESHOLD after a recent upgrade? -In 2.57.0 the semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected. Previously the -values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the most permissive. -The values now match their names: `LOW` is permissive and `HIGH` is the most restrictive. +The semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected in a recent release. +Previously the values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the +most permissive. The values now match their names: `LOW` is permissive and `HIGH` is the most +restrictive. The default was also changed from `LOW` to `HIGH`. Under the corrected semantics `HIGH` enforces exactly what `LOW` enforced before, so deployments that do not set this variable explicitly are @@ -16,4 +17,4 @@ No other changes are needed for deployments relying on the default. ## Sources - [Code Executor & Python Sandbox — API Configuration](https://docs.codemie.ai/admin/configuration/codemie/api-configuration#code-executor--python-sandbox) -- [Release Notes 2.57.0](https://docs.codemie.ai/admin/update/release-notes#v2-57-0) +- [Release Notes](https://docs.codemie.ai/admin/update/release-notes) From 8e6f89605af03dcd89c2a7487db8c0a36310f967 Mon Sep 17 00:00:00 2001 From: Artur Kuznetsov Date: Fri, 9 Oct 2026 14:16:13 +0400 Subject: [PATCH 3/3] docs(config): reword security threshold migration note to be neutral Remove characterizations of prior behavior as corrected or inverted; state the value-to-enforcement mapping change factually without version references. Also add markdownlint-disable comments around Prettier- enforced MDX comment syntax in release-notes.md to resolve MD037 errors. Generated with AI Co-Authored-By: codemie-ai --- docs/admin/configuration/codemie/api-configuration.md | 6 +++--- docs/admin/update/release-notes/release-notes.md | 8 ++++++++ 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/docs/admin/configuration/codemie/api-configuration.md b/docs/admin/configuration/codemie/api-configuration.md index 1305849e..c4bd49c8 100644 --- a/docs/admin/configuration/codemie/api-configuration.md +++ b/docs/admin/configuration/codemie/api-configuration.md @@ -1181,11 +1181,11 @@ This is independent of the chart's top-level `tolerations` value: that one appli - `HIGH` (default): Most restrictive, only allows safe operations :::note Migration note -The semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected in a recent release. Previously the values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the most permissive — contradicting the parameter name. +The value-to-enforcement mapping for `CODE_EXECUTOR_SECURITY_THRESHOLD` changed in a recent release. Previously, `LOW` enforced the strictest policy and `HIGH` the most permissive. -The default was also changed from `LOW` to `HIGH`. Under the corrected semantics, `HIGH` enforces exactly what `LOW` enforced before, so deployments that do not set `CODE_EXECUTOR_SECURITY_THRESHOLD` explicitly keep their current enforcement level unchanged. +The default also changed from `LOW` to `HIGH`. `HIGH` now applies the same enforcement level that `LOW` applied previously, so deployments that do not set `CODE_EXECUTOR_SECURITY_THRESHOLD` explicitly keep their current enforcement level unchanged. -**Action required:** Any deployment that explicitly sets `CODE_EXECUTOR_SECURITY_THRESHOLD=LOW` to obtain strict enforcement must change it to `HIGH`. +**Action required:** Any deployment that explicitly sets `CODE_EXECUTOR_SECURITY_THRESHOLD=LOW` for strict enforcement must change it to `HIGH`. ::: ::: diff --git a/docs/admin/update/release-notes/release-notes.md b/docs/admin/update/release-notes/release-notes.md index 561a6a83..6c42704b 100644 --- a/docs/admin/update/release-notes/release-notes.md +++ b/docs/admin/update/release-notes/release-notes.md @@ -13,15 +13,23 @@ This page provides information about updated third-party components and configur --- + + {/_ TODO: replace heading and anchor with the actual release version once announced, e.g. ### CodeMie X.Y.Z {#vX-Y-Z} _/} + + ### Upcoming Release {#upcoming}
Release details + + {/_ TODO: replace TBD with the actual release date and add the GitHub tag link once the release is published _/} + + **Release Date:** TBD

Third-Party Component Updates