Skip to content

Comments

Google secret backend impersonalization feature#27705

Closed
makiwino wants to merge 2 commits intoapache:mainfrom
makiwino:google-secret-backend-impersonalization-feature
Closed

Google secret backend impersonalization feature#27705
makiwino wants to merge 2 commits intoapache:mainfrom
makiwino:google-secret-backend-impersonalization-feature

Conversation

@makiwino
Copy link

This feature enables to use impersonation_chain in kwargs in env variables setting Google secret manager backend.
Example of the use of new feature:

AIRFLOW__SECRETS__BACKEND=airflow.providers.google.cloud.secrets.secret_manager.CloudSecretManagerBackend
AIRFLOW__SECRETS__BACKEND_KWARGS='{"impersonation_chain":"service_account@project_id.iam.gserviceaccount.com","project_id":"project_id","connections_prefix": "airflow-connections", "variables_prefix": "airflow-variables"}'

Why this change is needed?
Our Airflow deployment service account and team developers accounts share one main team serviceaccount via serviceAccountTokenCreator permission. This team serviceaccount has accesses to particular services like BQ, GCS, Google secrets. While BQ and GCS operators has impersonalisation_chain arg, google secret manager backend doesnt support this feautre. Using this new feature all approaches are aligned and it is possible to follow this good pattern.


^ Add meaningful description above

Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in newsfragments.

@makiwino makiwino requested a review from turbaszek as a code owner November 16, 2022 08:32
@boring-cyborg boring-cyborg bot added area:providers area:secrets provider:google Google (including GCP) related issues labels Nov 16, 2022
@boring-cyborg
Copy link

boring-cyborg bot commented Nov 16, 2022

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contribution Guide (https://github.com/apache/airflow/blob/main/CONTRIBUTING.rst)
Here are some useful points:

  • Pay attention to the quality of your code (flake8, mypy and type annotations). Our pre-commits will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example DAG that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

@potiuk potiuk force-pushed the google-secret-backend-impersonalization-feature branch from ebbc6de to c379f80 Compare November 17, 2022 17:59
@potiuk
Copy link
Member

potiuk commented Nov 17, 2022

We need unit tests for that I thinnk

@github-actions
Copy link

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed in 5 days if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale Stale PRs per the .github/workflows/stale.yml policy file label Jan 18, 2023
@github-actions github-actions bot closed this Jan 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:providers area:secrets pending-response provider:google Google (including GCP) related issues stale Stale PRs per the .github/workflows/stale.yml policy file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants