Skip to content

Implement bulk authorization methods in KeycloakAuthManager - #70647

Open
abhishekmauryaKsolves wants to merge 6 commits into
apache:mainfrom
abhishekmauryaKsolves:feat-70582-keycloak-batch-auth
Open

Implement bulk authorization methods in KeycloakAuthManager#70647
abhishekmauryaKsolves wants to merge 6 commits into
apache:mainfrom
abhishekmauryaKsolves:feat-70582-keycloak-batch-auth

Conversation

@abhishekmauryaKsolves

Copy link
Copy Markdown

Closes #70582

Implements the missing batch/filter authorization methods in
KeycloakAuthManager, following the existing pattern used by
filter_authorized_dag_ids (parallel HTTP calls via ThreadPoolExecutor,
with caching via single_flight).

  • batch_is_authorized_connection
  • batch_is_authorized_dag
  • batch_is_authorized_pool
  • batch_is_authorized_variable
  • filter_authorized_connections
  • filter_authorized_pools
  • filter_authorized_variables

Tests added covering normal filtering, empty input, all-denied, and
cache-hit scenarios for each new filter method.


^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in newsfragments.

Implements batch_is_authorized_connection, batch_is_authorized_dag,
batch_is_authorized_pool, batch_is_authorized_variable,
filter_authorized_connections, filter_authorized_pools, and
filter_authorized_variables in KeycloakAuthManager to reduce the
number of HTTP calls made to Keycloak for authorization checks,
following the existing pattern used by filter_authorized_dag_ids.

Closes apache#70582
@boring-cyborg

boring-cyborg Bot commented Jul 28, 2026

Copy link
Copy Markdown

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example Dag that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

Comment thread providers/keycloak/newsfragments/70582.feature.rst Outdated
@stephen-bracken

Copy link
Copy Markdown
Contributor

This implementation matches the implementation in filter_authorized_dag_ids, which is good for consistency, but I think we should utilise the _is_batch_authorized method to streamline the checks here, and avoid calling keycloak N times for N resources

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Implement bulk authorization methods in KeycloakAuthManager

3 participants