Airflow reverse proxy and DAG segregation

Viewed 90

I have a problem to solve.

  • I want to have intranet Airflow instance, where users will not have to enter the same credentials all over again when navigating in the internal network.
  • So the idea is to have a reverse proxy Nginx for user authentication.

This looks good and seems to be quite easy to setup, like stated here: https://airflow.apache.org/docs/1.10.2/integration.html#reverse-proxy

However, I want to have DAG level access control for user access restrictions, i.e. some of the DAGs should not be visible for certain groups/roles of users.

So the question is the following, how can I possibly pass the username of the authenticated users (what is trying to access Airflow UI) from reverse proxy to Airflow, so the DAG access_control property would work?

Does anyone have any experience to share? Thanks.

0 Answers
Related