---
title: "STACKIT Workflows"
description: "Managed Apache Airflow service for programmatically authoring, scheduling, and monitoring complex data pipelines as code."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Airflow", "Data Pipelines", "ETL", "Data and AI", "Orchestration"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/data-and-ai/assetcontainer/stackit/stackit-service-workflows/"
source_file: "docs/data-and-ai/assetcontainer/stackit/stackit-service-workflows.mdx"
---

STACKIT Workflows provides a managed Apache Airflow platform for orchestrating Directed Acyclic Graphs (DAGs) without managing underlying servers.

## Service Overview
- **Noops Airflow Operations**: Handles deployment, security updates, and maintenance automatically.
- **Pipelines as Code**: Author pipelines in Python with full Git version control integration.
- **Isolated Execution**: Executes pipeline tasks inside dedicated, isolated Kubernetes pods for maximum security.

## Technical Details
- **Scaling Architecture**: Automatically scales execution pods based on workload demands.
- **Identity & Observability**: OIDC identity provider integration and native connection to STACKIT Observability.
- **Digital Sovereignty**: Operates entirely within European data centers ensuring full GDPR compliance.

## Roles

The values below come from the STACKIT documentation and update themselves.

> From the STACKIT docs: [Concepts › STACKIT Portal roles](https://docs.stackit.cloud/products/data-and-ai/workflows/basics/concepts/#stackit-portal-roles) (Source updated 03.06.2026, copied 05.10.2026)

The following roles are available in the STACKIT Portal for managing Workflows instances:

- **Workflows Admin**: Full administrative access to all STACKIT Workflows resources.
- **Workflows Editor**: Permissions to create, modify, and manage STACKIT Workflows sub-resources (DAGs repository, identity provider configuration, etc.).
- **Workflows Reader**: Read-only access to all STACKIT Workflows resources.

These permissions are managed through the STACKIT Portal and STACKIT API.

> From the STACKIT docs: [Concepts › Airflow UI roles](https://docs.stackit.cloud/products/data-and-ai/workflows/basics/concepts/#airflow-ui-roles) (Source updated 03.06.2026, copied 05.10.2026)

The permissions inside the Airflow UI are separate from the access control in the STACKIT Portal. Access to the Airflow UI is managed through Role-Based Access Control (RBAC) using your connected Identity Provider (IdP).

When users log in, their roles are extracted from the authentication token provided by the IdP. These roles determine what users can access and perform within the Airflow interface. For detailed configuration instructions, see the [Identity Provider](https://docs.stackit.cloud/products/data-and-ai/workflows/basics/concepts/#identity-provider) section.

The following roles are available within Airflow:

- **Admin**: Complete access to all Airflow features, settings, and configurations.
- **User**: Can view and trigger DAGs, but cannot modify system settings or configurations.
- **Viewer**: Read-only access to view DAGs and their running statuses.

## Limitations & Constraints
- **Fixed Role Models**: Custom internal Airflow RBAC roles cannot be defined.
- **Flavor Scaling Boundaries**: Task concurrency and DAG worker limits are capped by the chosen instance flavor size.
- **Deployment Mechanics**: Direct SSH or manual file uploads are blocked; DAG code must be synced via Git or storage.

<LinkCard title="STACKIT Workflows Overview" href="https://docs.stackit.cloud" />
