Page MenuHomeDevCentral

D3273.id8403.diff
No OneTemporary

D3273.id8403.diff

diff --git a/pillar/paas/docker/dwellers/airflow.sls b/pillar/paas/docker/dwellers/airflow.sls
--- a/pillar/paas/docker/dwellers/airflow.sls
+++ b/pillar/paas/docker/dwellers/airflow.sls
@@ -57,6 +57,12 @@
admin_account: nasqueron/airflow/admin_account
fernet_key: nasqueron/airflow/fernet
postgresql: dbserver/cluster-A/users/airflow
+ vault: nasqueron/airflow/vault
+ vault:
+ url: https://172.27.27.7:8200
+ auth_type: approle
+ mount_point: apps
+ connections_path: airflow/connections
sentry:
realm: nasqueron
project_id: 4
diff --git a/roles/paas-docker/containers/airflow.sls b/roles/paas-docker/containers/airflow.sls
--- a/roles/paas-docker/containers/airflow.sls
+++ b/roles/paas-docker/containers/airflow.sls
@@ -78,6 +78,10 @@
{% set postgresql_dsn = salt["credentials.get_dsn"](realm_args["services"]["postgresql"], realm_args["credentials"]["postgresql"]) %}
+{% set secret_backend_args = realm_args["vault"] }
+{% set secret_backend_args["role_id"] = salt["credentials.get_username"](realm_args["credentials"]["vault"]) %}
+{% set secret_backend_args["secret_id"] = salt["credentials.get_password"](realm_args["credentials"]["vault"]) %}
+
{{ instance }}:
docker_container.running:
- detach: True
@@ -101,6 +105,9 @@
- AIRFLOW__DATABASE__SQL_ALCHEMY_CONN: postgresql+psycopg2://{{ postgresql_dsn }}/airflow
+ - AIRFLOW__SECRETS__BACKEND: airflow.providers.hashicorp.secrets.vault.VaultBackend
+ - AIRFLOW__SECRETS__BACKEND__KWARGS: {{ secret_backend_args | tojson }}
+
- AIRFLOW__SENTRY__SENTRY_ON: "True"
- AIRFLOW__SENTRY__SENTRY_DSN: {{ salt["credentials.get_sentry_dsn"](realm_args["sentry"]) }}
{% if "app_port" in container %}

File Metadata

Mime Type
text/plain
Expires
Mon, Sep 30, 20:23 (21 h, 48 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
2166940
Default Alt Text
D3273.id8403.diff (1 KB)

Event Timeline