DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
| Note |
|---|
Work in progress. Feedback welcome. |
Introduction
JIRA:
| Jira | ||||||
|---|---|---|---|---|---|---|
|
...
The goal of this document is to address these issues.
Design
UI
The idea is to add a new endpoint called /dags, which is parallel to the /admin UI. This UI will use the same template as the existing DAGs UI in /admin. It will not, however, have any other tabs (Data Profiling, Browse, Admin).
...
And perhaps a couple others that I'm missing. The point is that we'd limit the access in the /dags view pretty severely. We'll create a /dags route with: /dags, /dags/refresh, /dags/tree, etc.
Roles
We will introduce three levels of access:
- dag_viewer: Can see everything associated with a given DAG.
- dag_editor: Can edit the status of tasks in a DAG.
- dag_executor: Can click the 'Run' button on a task to have it triggered immediately. Only works for CeleryExecutor.
Groups
We will add the concept of groups. Users can be a member of a group. Both groups and members can be assigned DAG access permissions.
Implementation
Airflow already uses Flask-Login, so we can use this as the login mechanism. Airflow already has LDAP and Kerberos backends (as well as a GitHub backend).
...