Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 15 additions & 7 deletions docs/admin/configuration/codemie/api-configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -1156,7 +1156,7 @@ Configure secure Python code execution in isolated Kubernetes pods for running u
| `CODE_EXECUTOR_RUN_AS_USER` | integer | `1001` | Unix user ID for pod security context (non-root execution) |
| `CODE_EXECUTOR_RUN_AS_GROUP` | integer | `1001` | Unix group ID for pod security context |
| `CODE_EXECUTOR_FS_GROUP` | integer | `1001` | Filesystem group ID for pod volume permissions |
| `CODE_EXECUTOR_SECURITY_THRESHOLD` | string | `"LOW"` | Required security policy threshold: `SAFE`, `LOW`, `MEDIUM`, `HIGH` |
| `CODE_EXECUTOR_SECURITY_THRESHOLD` | string | `"HIGH"` | Security policy threshold controlling which operations are permitted in the sandbox: `SAFE` (most permissive), `LOW`, `MEDIUM`, `HIGH` (most restrictive). Higher values block more operations. See Security Considerations below. |
| `CODE_EXECUTOR_YAML_POLICY_PATH` | string | `""` | Path to custom YAML security policy file (optional, overrides default policy) |
| `CODE_EXECUTOR_VERBOSE` | boolean | `false` | Enable verbose logging for executor debugging |
| `CODE_EXECUTOR_KEEP_TEMPLATE` | boolean | `true` | Persist pod template after execution for performance optimization |
Expand All @@ -1173,13 +1173,21 @@ Example: to dedicate a kata-containers node pool to code execution, taint the po

This is independent of the chart's top-level `tolerations` value: that one applies only to the CodeMie API Deployment/Rollout pod and has no effect on Code Executor Job pods, which are created dynamically at runtime and read their own tolerations from `CODE_EXECUTOR_TOLERATIONS`.

**Security Threshold:** The security policy controls what operations are allowed:
**Security Threshold:** `CODE_EXECUTOR_SECURITY_THRESHOLD` directly represents policy strictness — higher values enforce stricter restrictions:

- `SAFE` (0): Most permissive, blocks almost nothing
- `LOW` (1): Allows common operations like HTTP requests (recommended default)
- `MEDIUM` (2): More restrictive, blocks potentially dangerous operations
- `HIGH` (3): Very restrictive, only allows safe operations
:::
- `SAFE`: Most permissive, blocks almost nothing
- `LOW`: Allows common operations such as HTTP requests
- `MEDIUM`: More restrictive, blocks potentially dangerous operations
- `HIGH` (default): Most restrictive, only allows safe operations

:::note Migration note
The semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected in a recent release. Previously the values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the most permissive — contradicting the parameter name.

The default was also changed from `LOW` to `HIGH`. Under the corrected semantics, `HIGH` enforces exactly what `LOW` enforced before, so deployments that do not set `CODE_EXECUTOR_SECURITY_THRESHOLD` explicitly keep their current enforcement level unchanged.

**Action required:** Any deployment that explicitly sets `CODE_EXECUTOR_SECURITY_THRESHOLD=LOW` to obtain strict enforcement must change it to `HIGH`.
:::
:::

### File Datasource Multiprocessing

Expand Down
31 changes: 31 additions & 0 deletions docs/admin/update/release-notes/release-notes.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,37 @@ This page provides information about updated third-party components and configur

---

{/_ TODO: replace heading and anchor with the actual release version once announced, e.g. ### CodeMie X.Y.Z {#vX-Y-Z} _/}

### Upcoming Release {#upcoming}

<details>
<summary>Release details</summary>

{/_ TODO: replace TBD with the actual release date and add the GitHub tag link once the release is published _/}

**Release Date:** TBD

<h3>Third-Party Component Updates</h3>

No third-party component updates in this release.

<h3>Configuration Changes</h3>

1. **Code Executor** — `CODE_EXECUTOR_SECURITY_THRESHOLD` semantics corrected — only applies if the Code Executor tool is enabled:

The values of `CODE_EXECUTOR_SECURITY_THRESHOLD` previously behaved inverted (`LOW` enforced the strictest policy, `HIGH` the most permissive). The semantics now match the parameter name: `LOW` is permissive and `HIGH` is the most restrictive.

The default value has also changed from `LOW` to `HIGH`. Under the corrected semantics, `HIGH` enforces exactly what `LOW` enforced before, so deployments that do not set this variable explicitly keep their current enforcement level unchanged.

:::warning
Any deployment that explicitly sets `CODE_EXECUTOR_SECURITY_THRESHOLD=LOW` to obtain strict enforcement must change it to `HIGH`.
:::

</details>

---

### CodeMie 2.56.0 {#v2-56-0}

<details>
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# How do I migrate CODE_EXECUTOR_SECURITY_THRESHOLD after a recent upgrade?

The semantics of `CODE_EXECUTOR_SECURITY_THRESHOLD` were corrected in a recent release.
Previously the values behaved inverted — `LOW` enforced the strictest policy and `HIGH` the
most permissive. The values now match their names: `LOW` is permissive and `HIGH` is the most
restrictive.

The default was also changed from `LOW` to `HIGH`. Under the corrected semantics `HIGH` enforces
exactly what `LOW` enforced before, so deployments that do not set this variable explicitly are
unaffected.

**Action required only if** the deployment explicitly sets `CODE_EXECUTOR_SECURITY_THRESHOLD=LOW`
to obtain strict enforcement — change it to `HIGH`.

No other changes are needed for deployments relying on the default.

## Sources

- [Code Executor & Python Sandbox — API Configuration](https://docs.codemie.ai/admin/configuration/codemie/api-configuration#code-executor--python-sandbox)
- [Release Notes](https://docs.codemie.ai/admin/update/release-notes)
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# What does CODE_EXECUTOR_SECURITY_THRESHOLD control and which value should I use?

`CODE_EXECUTOR_SECURITY_THRESHOLD` sets the strictness of the security policy applied to Python
code running inside the Code Executor sandbox. Higher values block more operations:

- `SAFE` — most permissive, blocks almost nothing
- `LOW` — allows common operations such as HTTP requests
- `MEDIUM` — more restrictive, blocks potentially dangerous operations
- `HIGH` (default) — most restrictive, only allows safe operations

For production deployments the default `HIGH` is recommended. Lowering the threshold permits
additional operations but reduces the isolation guarantees of the sandbox.

## Sources

- [Code Executor & Python Sandbox — API Configuration](https://docs.codemie.ai/admin/configuration/codemie/api-configuration#code-executor--python-sandbox)