according to Cloud Composer documentation here, Airflow RBAC functionality is not supported.
I'm wondering if there is another way to enable DAG Level Access Control for users visiting the Airflow UI in Cloud Composer.
Thanks!
Marco
according to Cloud Composer documentation here, Airflow RBAC functionality is not supported.
I'm wondering if there is another way to enable DAG Level Access Control for users visiting the Airflow UI in Cloud Composer.
Thanks!
Marco
According to the documentation, you can use Cloud Identity and Access Management (Cloud IAM) for access control. Cloud IAM provides identity management for multiple Google cloud products and it operates at Google Cloud project.
You can manage roles in your project using Cloud console, gcloud command line, the REST API or the client libraries. Google provides a tutorial "Granting, changing, and revoking access to resources", where it describes how to grant specific roles to team members in Cloud IAM.
As an example below you can see how to grant a editor role to a user using gcloud:
$ gcloud projects add-iam-policy-binding example-project-id-1 \
--member='user:test-user@gmail.com' --role='roles/editor'
In case you have any doubts about the command line interface, you can also check the documentation for further clarification.
I have unofficial way to enable it
1.goto composer bucket (GCS)
2.download and edit airflow.cfg
[webserver]
.
.
.
authenticate = True
auth_backend = airflow.contrib.auth.backends.password_auth
filter_by_owner = True
3.upload it back
*!!! Read me !!! It'll restore when
1.change node number
2.overide configulution in GUI*