We are using Airflow 2.0.1 with following settings:
- celery executor and 4 workers on 4 nodes.
- most of our tasks run some Hadoop applications launched via BashOperator
- using impersonation
- using just default queue
Firstly, we setup an own job that renewed the Kerberos tickets of run_as_user users. For about week it worked fine, then one of worker started to fail with missing Kerberos ticket. We could not find any changes between last successful run and the failing jobs; there was a valid ticket on the node; so we stopped the worker. Next day, we restarted the Airflow completely and missing Kerberos ticket was reported by all the workers. Temporarily, we are able to run the jobs with one worker when the kinit is run inside the DAGs and going to enable Kerberos according to https://airflow.apache.org/docs/apache-airflow/2.0.1/security/kerberos.html?highlight=kerberos.
The questions would be
- if anybody could describe in more detail, how the Airflow integration with Kerberos works
- why the ticket used from command line is not seen when we launch an application via BashOperator