Secure, Flexible Data Orchestration: Meet Remote Execution on Astro

  • Joyce Ling

Data teams need the freedom to move fast, experiment, and build workflows without roadblocks, while security teams must ensure sensitive information remains protected at all times.

Too often, this results in an impossible trade-off: either compromise security to enable efficiency or enforce strict controls that slow teams down.

But security and efficiency don’t have to be at odds. Organizations need a way to run workloads anywhere—on-prem, in a private cloud, or across multiple cloud providers—while still benefiting from centralized orchestration, observability, and control.

Solving the Security vs. Efficiency Trade-Off

With Remote Execution on Astro, enterprises no longer have to choose; you can now run workloads exactly wherever they need to be, while still benefiting from centralized orchestration and observability in Astro. This means no exposed data, code or secrets; no unnecessary firewall openings; and no compliance headaches, all while maintaining full control over your workflows.


What is Remote Execution on Astro?

Remote Execution is a new way to run Airflow on your own terms—securely, flexibly, and without giving up the benefits of a managed service. It lets you run workloads in your own infrastructure—regardless of environment—while maintaining centralized orchestration and observability in Astro.

Why Is It Called Remote Execution?

Remote Execution allows you to run tasks in your own infrastructure while leveraging Astro for centralized orchestration. This ensures security and compliance without compromising on orchestration capabilities. Remote Execution eliminates risks associated with exposing infrastructure to external control while still delivering a seamless orchestration experience.


Orchestrate Anywhere: How Astro Makes It Work

Remote Execution on Astro is built on a decoupled architecture that separates the control layer from the execution layer—what we call the Orchestration Plane and the Execution Plane:

  • Execution Plane (Customer-Controlled): Your infrastructure—hybrid or not—where tasks actually run. This is where your code, data, secrets, and task logs stay. Inside this environment are Remote Execution Agents, lightweight services that pull tasks from the Remote Execution API, run them locally, and report status and metrics back to Astro. Agents can be configured for different workloads (e.g., async, GPU-heavy), offering full flexibility without compromising security.
  • Orchestration Plane (Managed by Astronomer): The centralized control layer that handles activities like scheduling, task management, and the Airflow UI. At its core is the Remote Execution API, which securely manages all communication with Remote Execution Agents running in your infrastructure—assigning tasks, tracking agent health, and maintaining observability—all without accessing your data or code.

This architecture lets you run tasks wherever it makes sense—whether for performance, cost, compliance, or security—while managing everything centrally through Astro.

By decoupling orchestration from execution, you can scale execution independently and keep your most sensitive data within your environment. It’s a modern approach designed to support complex infrastructure needs and strict regulatory requirements without sacrificing observability or control.

Remote Execution in Action: Solving Real-World Problems

Remote Execution solves some of the most persistent challenges data teams face when orchestrating modern pipelines. From tightening security posture to scaling across hybrid environments, here’s how Astro helps address these operational and architectural hurdles.

1. Tighten Security Without Limiting Access

Astro's Remote Execution ensures that your environment stays secure without compromising orchestration. Agents connect via outbound-only, encrypted channels—eliminating the need for open ports or inbound firewall rules. This aligns with zero-trust architecture and keeps your infrastructure safe from external exposure. With data, secrets, and workloads remaining within your environment, Remote Execution helps you maintain strict data boundaries and support compliance goals—especially for teams operating under regulations like GDPR and HIPAA.

2. Run Workloads Across Hybrid and Multi-Cloud Environments

With Remote Execution, you can also run agents in multiple regions or cloud environments at the same time. This means if one environment goes down, another can automatically pick up the work—without any manual failover or disruption. It’s a simple way to improve reliability, support disaster recovery, and keep workflows running smoothly, even in the face of outages or unexpected issues.

3. Scale Execution Resources Without Overhead

You can scale execution resources dynamically based on workload demand—without the hassle of over-provisioning. Whether you're running memory-intensive tasks, leveraging GPUs, or just handling seasonal spikes, Remote Execution lets you match compute to workload efficiently and cost-effectively.

4. Maintain Centralized Visibility and Control

Even when tasks run in distributed environments, you can manage everything from a single Astro interface. Monitor agent health, task execution, and system performance in real time—while maintaining centralized governance and oversight.


Built on Airflow 3.0 Innovation

Remote Execution is powered by the all-new Astro Executor for Airflow 3.0, delivering superior reliability over the Celery Executor without the cold-start issues that come with Kubernetes Executor. As the driving force behind Apache Airflow—contributing 55% of the code—Astronomer is uniquely positioned to bring this innovation to market.

Astro is the only managed service offering Day 0 support for Airflow 3.0, giving you access to its powerful capabilities:

  • DAG Versioning: Track and manage changes to your workflows.
  • Enhanced Task Flow: Run tasks more efficiently with improved scheduling.
  • Modern UI: A more intuitive, responsive interface.

With Astro, you stay current with the latest Airflow releases, gaining early access to new features and improvements—while benefiting from a fully managed, enterprise-grade orchestration experience.


Getting Started

If you're looking to run Airflow securely in your own environment—without giving up the benefits of a managed service—Remote Execution on Astro is built to help.

  • Balance security with flexibility
  • Run workloads close to your data
  • Stay in control while offloading orchestration

Request a demo | Download the full security whitepaper

Get the full technical breakdown of Astro’s architecture, security controls, and compliance model.

Build, run, & observe
your data workflows.
All in one place.

Try Astro today and get up to $500 in free credits during your 14-day trial.