You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 11 Next »

Status

StateVote
Discussion Thread
Vote Threadhttps://lists.apache.org/thread/qg4s7fbflgtbk5t0sdw1g1zvmjrb046v
Vote Result Thread
Progress Tracking (PR/GitHub Project/Issue Label)
Date Created

31.08.2025

Version Released
AuthorsBuğra Öztürk 

Motivation

Providing the same functionality from the API interface is available via airflowctl. This makes most of the airflow CLI commands redundant, causing duplicate efforts as well as exposing the database directly to the user, making the system insecure, and allowing interaction with database entries without any Role-Based Access Control (RBAC).

Actions were previously defined in AIP-81: Enhanced Security in CLI via Integration of API.

  • Local (Process/Administrative) Commands: Process-based commands, allowing users to manage deployments, interact with the DB shell, and perform other administrative functions.
  • Remote Commands: Any command that can be supported or provided by the Public (Core) API.

This proposal reduces maintenance effort by reallocating development focus from the airflow CLI to airflowctl for Remote Commands. This will result in faster delivery of features, reduce code duplication, and strengthen the Airflow Public (Core) API as the single source of truth. Providing functionalities from a secure channel using authentication methods and RBAC.

Main goal is 

Considerations

At a high level:

  • Limit the development of airflow CLI commands for Remote commands.
  • Deprecate airflow CLI commands that overlap with airflowctl.
  • Provide warnings to users suggesting migration to airflowctl, with a deprecation period.
  • Ensure functional parity: deprecations will only happen once equivalent features exist in airflowctl.
  • Maintain a transition process (via a PR template, see below) to map CLI commands to airflowctl.
  • Catch up with additional features in the airflow CLI that were not implemented in airflowctl when AIP-81 was introduced.
  • Provide migration tooling and mapping `airflow <command> ↔ airflowctl <command>`

What change do you propose to make?

We propose limiting the development of the airflow CLI for Remote commands and instead migrating these commands to a new dedicated tool. airflowctl, which interfaces exclusively with the Airflow Public (Core) API.

  • All Remote commands in the airflow CLI will have a deprecation warning directing users to airflowctl.
  • Equivalent functionality will be implemented in airflowctl to ensure no loss of capability.

  • New Remote features will only be added to airflowctl (and the API), not to the airflow CLI.

  • Local administrative commands (e.g., database shell, process management) will continue to exist in the airflow CLI.

There will be two sides to this AIP. One is creating a tool to help users migrate to airflowctl more easily without many changes. Second is adding a deprecation warning to the Airflow CLI commands. To add a deprecation warning, we will implement the same/mostly the same (Some API limitations could be there) feature. 

In the diagram, you can see the main aim of the AIP. Managing the tooling and adding a deprecation warning while ensuring airflowctl has the command can be managed within different projects.

Diagram 1: Migration Tool

Diagram 2: Deprecation Process

Airflow CLI State

The airflow CLI continues functioning and development mainly for admin tasks, such as running components and low-level database management tasks. We will stop developing and include a deprecation warning for any feature that can be provided from the API.

What problem does it solve?

The aim is to help users to migrate to API based CLI solution of Apache Airflow while preventing duplicate implementation effort from the time we include a deprecation warning for any CLI command.

Why is it needed?

It is to enforce the vision to use the API as the single source of truth for all Remote commands. Additionally, it aims to simplify maintenance by removing duplicate code paths. 

Tooling is needed because of easier migrations. The automations over Airflow CLI should be easier to detect. With the tool, we need to output as much automation as possible while giving proper guidance or replacing them where possible. We cannot fully automate the authentication and running the command, but the command itself can be easily replaced with the new tooling via proper mapping.

Are there any downsides to this change?

  • Migration effort: Users and automation relying on airflow CLI Remote commands will need to update scripts and tooling to use airflowctl.

  • Learning curve: Users familiar with the airflow CLI must adapt to a new tool airflowctl.

  • Transition complexity: Ensuring full parity between airflow CLI and airflowctl during deprecation will require careful tracking (hence the PR template and mapping table).

  • Short-term overhead: Contributors must first ensure API parity before the CLI deprecation warning, which may initially slow down some changes for a small portion. 

Which users are affected by the change?

Any user has been using the Airflow CLI with remote commands (any command can be provided from API/airflowctl).

Administrator commands won't be impacted.

How are users affected by the change? (e.g. DB upgrade required?)

What is the level of migration effort (manual and automated) needed for the users to adapt to the breaking changes? (especially in the context of Airflow 3)

Tooling will decrease the migration effort a lot. Only the part that needs to be considered as a manual step is storing their credentials (username:password ) secure for their automated user and authenticate before executing any command, similar to acquiring the token before calling the API.

What defines this AIP as "done"?

We need to ensure tooling is in place to help users to migrate and show guidelines. We will add clear documentation on what is moving and how the replacement will work. We will add a deprecation warning to all Remote commands in the airflow CLI. We will wait three minor (example: from 3. x.x  to 3.x+3.x Airflow versions have gone through the deprecation warning cycle before the full switch.

Full Switch: The airflow CLI commands won't be listed, but will be redirected to airflowctl commands. We will then discuss how the removal process will be and executed on airflow CLI.


  • No labels