Work in progress. Feedback welcome. |
JIRA:
Several Airflow users have a need for more rigorous security in Airflow. Part of this involves authentication (authn) and authorization (authz) in Airflow's UI. The current security problems with Airflow's UI are:
The goal of this document is to address these issues.
The idea is to add a new endpoint called /dags, which is parallel to the /admin UI. This UI will use the same template as the existing DAGs UI in /admin. It will not, however, have any other tabs (Data Profiling, Browse, Admin).
![Airflow > DAGs UI [ARCHIVED] > dags-ui.png](/confluence/download/attachments/62696998/dags-ui.png?version=1&modificationDate=1463423436000&api=v2)
We will need to lock down several pages in the Airflow view class. The pages that are exposed would be:
And perhaps a couple others that I'm missing. The point is that we'd limit the access in the /dags view pretty severely.
We will introduce three levels of access:
We will add the concept of groups. Users can be a member of a group. Both groups and members can be assigned DAG access permissions.
Airflow already uses Flask-Login, so we can use this as the login mechanism. Airflow already has LDAP and Kerberos backends (as well as a GitHub backend).
We will need to: