TaskSDK: Make secrets masking work when conns are loaded from secrets backends - #54574

Merged
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor
Aug 17, 2025
Merged

TaskSDK: Make secrets masking work when conns are loaded from secrets backends#54574
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor

Conversation

@ashb

@ashbashb commented Aug 16, 2025

Copy link
Copy Markdown
Member

If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.

This also captures and "mirrors" direct calls to mask_secret from user code
to the supervisor so that it can mask the output correctly.

Docs look like this

Screenshot 2025-08-17 at 16 46 22

Closes#54540

I was testing with this dag. In a follow up I'll add it to the sdk integration tests to ensure masking works fully end-to-end.

from __future__ importannotationsimportloggingfromairflowimportDAGfromairflow.providers.standard.operators.emptyimportEmptyOperatorfromairflow.providers.standard.operators.pythonimportPythonOperatorfromairflow.sdkimportVariablex=Variable.get("my_variable")
defmy_function(my_var: str) ->None:
logging.getLogger(__name__).info(my_var)
withDAG("test_dag") asdag:
start=EmptyOperator(task_id="start")
py_func=PythonOperator(task_id="py_func", python_callable=my_function, op_kwargs={"my_var": x})
end=EmptyOperator(task_id="end")
start>>py_func>>endif__name__=="__main__":
dag.test()

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@ashb

ashb commented Aug 16, 2025

Copy link
Copy Markdown
MemberAuthor

I think I've caused an infinite loop

@ashb

ashb commented Aug 17, 2025

Copy link
Copy Markdown
MemberAuthor

Ah no wasn't an infinite loop, was just not updating the dag processor handler

@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 9af3346 to 700acd1CompareAugust 17, 2025 16:16
… backends
If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.
This also captures and "mirrors" direct calls to `mask_secret` from user code
to the supervisor so that it can mask the output correctly.
@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 700acd1 to ce03d93CompareAugust 17, 2025 16:21
Comment threadtask-sdk/docs/api.rst
@ashbashb added the full tests needed We need to run full set of tests for this PR to merge label Aug 17, 2025
@ashbashb closed this Aug 17, 2025
@ashbashb reopened this Aug 17, 2025
@potiuk

Copy link
Copy Markdown
Member

Nice ! Good one @ashb the pull it so quicky

@ashb
ashb merged commit 1f4c55c into mainAug 17, 2025
179 checks passed
@ashb
ashb deleted the mask-secret-send-to-supervisor branch August 17, 2025 19:21
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-0-test. View the failure log Run details

StatusBranchResult
v3-0-testCommit Link

You can attempt to backport this manually by running:

cherry_picker 1f4c55c v3-0-test

This should apply the commit to the v3-0-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
un-avoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
kaxil pushed a commit that referenced this pull request Aug 18, 2025
kaxil pushed a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
@dshvedchenko

Copy link
Copy Markdown

after upgrading to airflow 3.0.5 operators/hooks failed with similar messages:

[2025-08-21, 07:05:11] INFO - Connection Retrieved 'snowflake_default': source="airflow.hooks.base"
[2025-08-21, 07:05:11] ERROR - Task failed with exception: source="task"
NotImplementedError: Objects of type <class 'pydantic_core._pydantic_core.SerializationIterator'> are not supported
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 918 in run
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 1213 in _execute_task
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/bases/operator.py", line 397 in wrapper
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 307 in execute
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 201 in get_db_hook
File "/usr/local/lib/python3.12/functools.py", line 998 in __get__
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 177 in _hook
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 166 in get_hook
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/definitions/connection.py", line 162 in extra_dejson
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/secrets_masker.py", line 130 in mask_secret
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 187 in send
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 145 in as_bytes
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 122 in _msgpack_enc_hook

@VladaZakharova

Copy link
Copy Markdown
Contributor

hi @dshvedchenko
Yes, the same problem with google-provider and all the operators and hooks
@ashb Can you please check? Can you please tell maybe there is now a new way to create connections or what?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Which hook is that coming from?

@VladaZakharova

Copy link
Copy Markdown
Contributor

All of them :)
when creating connection to run any hook I see the same error as @dshvedchenko
connection google_cloud_default

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

I think it depends on what fields are in the connection -- In my (admittedly simple) testing with http connection it worked fine.

Can you give me a connection to test with?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor
[2025-08-21, 09:36:10] INFO - conn.conn_id='test' conn.password=None conn=Connection(conn_id='test', conn_type='google_cloud_platform', description=None, host=None, schema=None, login=None, password=None, port=None, extra='{\n "project": null,\n "key_path": null,\n "keyfile_dict": null,\n "credential_config_file": null,\n "scope": null,\n "key_secret_name": null,\n "key_secret_project_id": null,\n "num_retries": 5,\n "impersonation_chain": null,\n "idp_issuer_url": null,\n "client_id": null,\n "client_secret": null,\n "idp_extra_parameters": null,\n "is_anonymous": false\n}'): chan="stdout": source="task"

@VladaZakharova

Copy link
Copy Markdown
Contributor

I was creating connection using:

AIRFLOW_CONN_GOOGLE_CLOUD_DEFAULT='{"conn_type": "google_cloud_default", "extra": {"key_path": "/files/airflow-breeze-config/keys/keys.json", "scope": "https://www.googleapis.com/auth/cloud-platform", "project": "project_id", "num_retries": 5}}'

the problem was originally with some of the triggered where we couldn't pass Enum values from tigggerer to worker (also needs to be reworked).
Now after this mask changes the problem is with creating the connection because of the changes made here #51699 :

def _msgpack_enc_hook(obj: Any) -> Any:
import pendulum
if isinstance(obj, pendulum.DateTime):
# convert the pendulm Datetime subclass into a raw datetime so that msgspec can use it's native
# encoding
return datetime(
obj.year, obj.month, obj.day, obj.hour, obj.minute, obj.second, obj.microsecond, tzinfo=obj.tzinfo
)
if isinstance(obj, Path):
return str(obj)
if isinstance(obj, BaseModel):
return obj.model_dump(exclude_unset=True)
# Raise a NotImplementedError for other types
raise NotImplementedError(f"Objects of type {type(obj)} are not supported")

We need I think more types here to support and it will solve the problem for everyone.

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Looks like this is an unsolved bug in pydantic pydantic/pydantic#9541 (and also impropper testing on our part)

@VladaZakharova

VladaZakharova commented Aug 21, 2025

Copy link
Copy Markdown
Contributor

Looks like yes, more complicated test cases would be good to have :)
are we planning to address this issue to make it work for providers? Looks like there will be more people coming with the same issue

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Nothing providers can do, it needs a change in Airflow core. For people hitting this, if you can't/don't want to downgrade you can apply a patch to your Airflow to work around it - instructions in #54769 (comment)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:task-sdkfull tests neededWe need to run full set of tests for this PR to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Secret masker often doesn't always mask values (user defined mask, or secrets backend)

5 participants

@ashb@potiuk@dshvedchenko@VladaZakharova@jscheffl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

TaskSDK: Make secrets masking work when conns are loaded from secrets backends - #54574

Merged
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor
Aug 17, 2025
Merged

TaskSDK: Make secrets masking work when conns are loaded from secrets backends#54574
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor

Conversation

@ashb

@ashbashb commented Aug 16, 2025

Copy link
Copy Markdown
Member

If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.

This also captures and "mirrors" direct calls to mask_secret from user code
to the supervisor so that it can mask the output correctly.

Docs look like this

Screenshot 2025-08-17 at 16 46 22

Closes#54540

I was testing with this dag. In a follow up I'll add it to the sdk integration tests to ensure masking works fully end-to-end.

from __future__ importannotationsimportloggingfromairflowimportDAGfromairflow.providers.standard.operators.emptyimportEmptyOperatorfromairflow.providers.standard.operators.pythonimportPythonOperatorfromairflow.sdkimportVariablex=Variable.get("my_variable")
defmy_function(my_var: str) ->None:
logging.getLogger(__name__).info(my_var)
withDAG("test_dag") asdag:
start=EmptyOperator(task_id="start")
py_func=PythonOperator(task_id="py_func", python_callable=my_function, op_kwargs={"my_var": x})
end=EmptyOperator(task_id="end")
start>>py_func>>endif__name__=="__main__":
dag.test()

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@ashb

ashb commented Aug 16, 2025

Copy link
Copy Markdown
MemberAuthor

I think I've caused an infinite loop

@ashb

ashb commented Aug 17, 2025

Copy link
Copy Markdown
MemberAuthor

Ah no wasn't an infinite loop, was just not updating the dag processor handler

@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 9af3346 to 700acd1CompareAugust 17, 2025 16:16
… backends
If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.
This also captures and "mirrors" direct calls to `mask_secret` from user code
to the supervisor so that it can mask the output correctly.
@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 700acd1 to ce03d93CompareAugust 17, 2025 16:21
Comment threadtask-sdk/docs/api.rst
@ashbashb added the full tests needed We need to run full set of tests for this PR to merge label Aug 17, 2025
@ashbashb closed this Aug 17, 2025
@ashbashb reopened this Aug 17, 2025
@potiuk

Copy link
Copy Markdown
Member

Nice ! Good one @ashb the pull it so quicky

@ashb
ashb merged commit 1f4c55c into mainAug 17, 2025
179 checks passed
@ashb
ashb deleted the mask-secret-send-to-supervisor branch August 17, 2025 19:21
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-0-test. View the failure log Run details

StatusBranchResult
v3-0-testCommit Link

You can attempt to backport this manually by running:

cherry_picker 1f4c55c v3-0-test

This should apply the commit to the v3-0-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
un-avoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
kaxil pushed a commit that referenced this pull request Aug 18, 2025
kaxil pushed a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
@dshvedchenko

Copy link
Copy Markdown

after upgrading to airflow 3.0.5 operators/hooks failed with similar messages:

[2025-08-21, 07:05:11] INFO - Connection Retrieved 'snowflake_default': source="airflow.hooks.base"
[2025-08-21, 07:05:11] ERROR - Task failed with exception: source="task"
NotImplementedError: Objects of type <class 'pydantic_core._pydantic_core.SerializationIterator'> are not supported
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 918 in run
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 1213 in _execute_task
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/bases/operator.py", line 397 in wrapper
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 307 in execute
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 201 in get_db_hook
File "/usr/local/lib/python3.12/functools.py", line 998 in __get__
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 177 in _hook
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 166 in get_hook
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/definitions/connection.py", line 162 in extra_dejson
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/secrets_masker.py", line 130 in mask_secret
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 187 in send
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 145 in as_bytes
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 122 in _msgpack_enc_hook

@VladaZakharova

Copy link
Copy Markdown
Contributor

hi @dshvedchenko
Yes, the same problem with google-provider and all the operators and hooks
@ashb Can you please check? Can you please tell maybe there is now a new way to create connections or what?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Which hook is that coming from?

@VladaZakharova

Copy link
Copy Markdown
Contributor

All of them :)
when creating connection to run any hook I see the same error as @dshvedchenko
connection google_cloud_default

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

I think it depends on what fields are in the connection -- In my (admittedly simple) testing with http connection it worked fine.

Can you give me a connection to test with?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor
[2025-08-21, 09:36:10] INFO - conn.conn_id='test' conn.password=None conn=Connection(conn_id='test', conn_type='google_cloud_platform', description=None, host=None, schema=None, login=None, password=None, port=None, extra='{\n "project": null,\n "key_path": null,\n "keyfile_dict": null,\n "credential_config_file": null,\n "scope": null,\n "key_secret_name": null,\n "key_secret_project_id": null,\n "num_retries": 5,\n "impersonation_chain": null,\n "idp_issuer_url": null,\n "client_id": null,\n "client_secret": null,\n "idp_extra_parameters": null,\n "is_anonymous": false\n}'): chan="stdout": source="task"

@VladaZakharova

Copy link
Copy Markdown
Contributor

I was creating connection using:

AIRFLOW_CONN_GOOGLE_CLOUD_DEFAULT='{"conn_type": "google_cloud_default", "extra": {"key_path": "/files/airflow-breeze-config/keys/keys.json", "scope": "https://www.googleapis.com/auth/cloud-platform", "project": "project_id", "num_retries": 5}}'

the problem was originally with some of the triggered where we couldn't pass Enum values from tigggerer to worker (also needs to be reworked).
Now after this mask changes the problem is with creating the connection because of the changes made here #51699 :

def _msgpack_enc_hook(obj: Any) -> Any:
import pendulum
if isinstance(obj, pendulum.DateTime):
# convert the pendulm Datetime subclass into a raw datetime so that msgspec can use it's native
# encoding
return datetime(
obj.year, obj.month, obj.day, obj.hour, obj.minute, obj.second, obj.microsecond, tzinfo=obj.tzinfo
)
if isinstance(obj, Path):
return str(obj)
if isinstance(obj, BaseModel):
return obj.model_dump(exclude_unset=True)
# Raise a NotImplementedError for other types
raise NotImplementedError(f"Objects of type {type(obj)} are not supported")

We need I think more types here to support and it will solve the problem for everyone.

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Looks like this is an unsolved bug in pydantic pydantic/pydantic#9541 (and also impropper testing on our part)

@VladaZakharova

VladaZakharova commented Aug 21, 2025

Copy link
Copy Markdown
Contributor

Looks like yes, more complicated test cases would be good to have :)
are we planning to address this issue to make it work for providers? Looks like there will be more people coming with the same issue

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Nothing providers can do, it needs a change in Airflow core. For people hitting this, if you can't/don't want to downgrade you can apply a patch to your Airflow to work around it - instructions in #54769 (comment)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:task-sdkfull tests neededWe need to run full set of tests for this PR to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Secret masker often doesn't always mask values (user defined mask, or secrets backend)

5 participants

@ashb@potiuk@dshvedchenko@VladaZakharova@jscheffl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

TaskSDK: Make secrets masking work when conns are loaded from secrets backends - #54574

Merged
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor
Aug 17, 2025
Merged

TaskSDK: Make secrets masking work when conns are loaded from secrets backends#54574
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor

Conversation

@ashb

@ashbashb commented Aug 16, 2025

Copy link
Copy Markdown
Member

If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.

This also captures and "mirrors" direct calls to mask_secret from user code
to the supervisor so that it can mask the output correctly.

Docs look like this

Screenshot 2025-08-17 at 16 46 22

Closes#54540

I was testing with this dag. In a follow up I'll add it to the sdk integration tests to ensure masking works fully end-to-end.

from __future__ importannotationsimportloggingfromairflowimportDAGfromairflow.providers.standard.operators.emptyimportEmptyOperatorfromairflow.providers.standard.operators.pythonimportPythonOperatorfromairflow.sdkimportVariablex=Variable.get("my_variable")
defmy_function(my_var: str) ->None:
logging.getLogger(__name__).info(my_var)
withDAG("test_dag") asdag:
start=EmptyOperator(task_id="start")
py_func=PythonOperator(task_id="py_func", python_callable=my_function, op_kwargs={"my_var": x})
end=EmptyOperator(task_id="end")
start>>py_func>>endif__name__=="__main__":
dag.test()

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@ashb

ashb commented Aug 16, 2025

Copy link
Copy Markdown
MemberAuthor

I think I've caused an infinite loop

@ashb

ashb commented Aug 17, 2025

Copy link
Copy Markdown
MemberAuthor

Ah no wasn't an infinite loop, was just not updating the dag processor handler

@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 9af3346 to 700acd1CompareAugust 17, 2025 16:16
… backends
If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.
This also captures and "mirrors" direct calls to `mask_secret` from user code
to the supervisor so that it can mask the output correctly.
@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 700acd1 to ce03d93CompareAugust 17, 2025 16:21
Comment threadtask-sdk/docs/api.rst
@ashbashb added the full tests needed We need to run full set of tests for this PR to merge label Aug 17, 2025
@ashbashb closed this Aug 17, 2025
@ashbashb reopened this Aug 17, 2025
@potiuk

Copy link
Copy Markdown
Member

Nice ! Good one @ashb the pull it so quicky

@ashb
ashb merged commit 1f4c55c into mainAug 17, 2025
179 checks passed
@ashb
ashb deleted the mask-secret-send-to-supervisor branch August 17, 2025 19:21
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-0-test. View the failure log Run details

StatusBranchResult
v3-0-testCommit Link

You can attempt to backport this manually by running:

cherry_picker 1f4c55c v3-0-test

This should apply the commit to the v3-0-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
un-avoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
kaxil pushed a commit that referenced this pull request Aug 18, 2025
kaxil pushed a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
@dshvedchenko

Copy link
Copy Markdown

after upgrading to airflow 3.0.5 operators/hooks failed with similar messages:

[2025-08-21, 07:05:11] INFO - Connection Retrieved 'snowflake_default': source="airflow.hooks.base"
[2025-08-21, 07:05:11] ERROR - Task failed with exception: source="task"
NotImplementedError: Objects of type <class 'pydantic_core._pydantic_core.SerializationIterator'> are not supported
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 918 in run
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 1213 in _execute_task
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/bases/operator.py", line 397 in wrapper
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 307 in execute
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 201 in get_db_hook
File "/usr/local/lib/python3.12/functools.py", line 998 in __get__
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 177 in _hook
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 166 in get_hook
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/definitions/connection.py", line 162 in extra_dejson
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/secrets_masker.py", line 130 in mask_secret
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 187 in send
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 145 in as_bytes
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 122 in _msgpack_enc_hook

@VladaZakharova

Copy link
Copy Markdown
Contributor

hi @dshvedchenko
Yes, the same problem with google-provider and all the operators and hooks
@ashb Can you please check? Can you please tell maybe there is now a new way to create connections or what?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Which hook is that coming from?

@VladaZakharova

Copy link
Copy Markdown
Contributor

All of them :)
when creating connection to run any hook I see the same error as @dshvedchenko
connection google_cloud_default

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

I think it depends on what fields are in the connection -- In my (admittedly simple) testing with http connection it worked fine.

Can you give me a connection to test with?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor
[2025-08-21, 09:36:10] INFO - conn.conn_id='test' conn.password=None conn=Connection(conn_id='test', conn_type='google_cloud_platform', description=None, host=None, schema=None, login=None, password=None, port=None, extra='{\n "project": null,\n "key_path": null,\n "keyfile_dict": null,\n "credential_config_file": null,\n "scope": null,\n "key_secret_name": null,\n "key_secret_project_id": null,\n "num_retries": 5,\n "impersonation_chain": null,\n "idp_issuer_url": null,\n "client_id": null,\n "client_secret": null,\n "idp_extra_parameters": null,\n "is_anonymous": false\n}'): chan="stdout": source="task"

@VladaZakharova

Copy link
Copy Markdown
Contributor

I was creating connection using:

AIRFLOW_CONN_GOOGLE_CLOUD_DEFAULT='{"conn_type": "google_cloud_default", "extra": {"key_path": "/files/airflow-breeze-config/keys/keys.json", "scope": "https://www.googleapis.com/auth/cloud-platform", "project": "project_id", "num_retries": 5}}'

the problem was originally with some of the triggered where we couldn't pass Enum values from tigggerer to worker (also needs to be reworked).
Now after this mask changes the problem is with creating the connection because of the changes made here #51699 :

def _msgpack_enc_hook(obj: Any) -> Any:
import pendulum
if isinstance(obj, pendulum.DateTime):
# convert the pendulm Datetime subclass into a raw datetime so that msgspec can use it's native
# encoding
return datetime(
obj.year, obj.month, obj.day, obj.hour, obj.minute, obj.second, obj.microsecond, tzinfo=obj.tzinfo
)
if isinstance(obj, Path):
return str(obj)
if isinstance(obj, BaseModel):
return obj.model_dump(exclude_unset=True)
# Raise a NotImplementedError for other types
raise NotImplementedError(f"Objects of type {type(obj)} are not supported")

We need I think more types here to support and it will solve the problem for everyone.

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Looks like this is an unsolved bug in pydantic pydantic/pydantic#9541 (and also impropper testing on our part)

@VladaZakharova

VladaZakharova commented Aug 21, 2025

Copy link
Copy Markdown
Contributor

Looks like yes, more complicated test cases would be good to have :)
are we planning to address this issue to make it work for providers? Looks like there will be more people coming with the same issue

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Nothing providers can do, it needs a change in Airflow core. For people hitting this, if you can't/don't want to downgrade you can apply a patch to your Airflow to work around it - instructions in #54769 (comment)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:task-sdkfull tests neededWe need to run full set of tests for this PR to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Secret masker often doesn't always mask values (user defined mask, or secrets backend)

5 participants

@ashb@potiuk@dshvedchenko@VladaZakharova@jscheffl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

TaskSDK: Make secrets masking work when conns are loaded from secrets backends - #54574

Merged
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor
Aug 17, 2025
Merged

TaskSDK: Make secrets masking work when conns are loaded from secrets backends#54574
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor

Conversation

@ashb

@ashbashb commented Aug 16, 2025

Copy link
Copy Markdown
Member

If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.

This also captures and "mirrors" direct calls to mask_secret from user code
to the supervisor so that it can mask the output correctly.

Docs look like this

Screenshot 2025-08-17 at 16 46 22

Closes#54540

I was testing with this dag. In a follow up I'll add it to the sdk integration tests to ensure masking works fully end-to-end.

from __future__ importannotationsimportloggingfromairflowimportDAGfromairflow.providers.standard.operators.emptyimportEmptyOperatorfromairflow.providers.standard.operators.pythonimportPythonOperatorfromairflow.sdkimportVariablex=Variable.get("my_variable")
defmy_function(my_var: str) ->None:
logging.getLogger(__name__).info(my_var)
withDAG("test_dag") asdag:
start=EmptyOperator(task_id="start")
py_func=PythonOperator(task_id="py_func", python_callable=my_function, op_kwargs={"my_var": x})
end=EmptyOperator(task_id="end")
start>>py_func>>endif__name__=="__main__":
dag.test()

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@ashb

ashb commented Aug 16, 2025

Copy link
Copy Markdown
MemberAuthor

I think I've caused an infinite loop

@ashb

ashb commented Aug 17, 2025

Copy link
Copy Markdown
MemberAuthor

Ah no wasn't an infinite loop, was just not updating the dag processor handler

@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 9af3346 to 700acd1CompareAugust 17, 2025 16:16
… backends
If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.
This also captures and "mirrors" direct calls to `mask_secret` from user code
to the supervisor so that it can mask the output correctly.
@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 700acd1 to ce03d93CompareAugust 17, 2025 16:21
Comment threadtask-sdk/docs/api.rst
@ashbashb added the full tests needed We need to run full set of tests for this PR to merge label Aug 17, 2025
@ashbashb closed this Aug 17, 2025
@ashbashb reopened this Aug 17, 2025
@potiuk

Copy link
Copy Markdown
Member

Nice ! Good one @ashb the pull it so quicky

@ashb
ashb merged commit 1f4c55c into mainAug 17, 2025
179 checks passed
@ashb
ashb deleted the mask-secret-send-to-supervisor branch August 17, 2025 19:21
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-0-test. View the failure log Run details

StatusBranchResult
v3-0-testCommit Link

You can attempt to backport this manually by running:

cherry_picker 1f4c55c v3-0-test

This should apply the commit to the v3-0-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
un-avoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
kaxil pushed a commit that referenced this pull request Aug 18, 2025
kaxil pushed a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
@dshvedchenko

Copy link
Copy Markdown

after upgrading to airflow 3.0.5 operators/hooks failed with similar messages:

[2025-08-21, 07:05:11] INFO - Connection Retrieved 'snowflake_default': source="airflow.hooks.base"
[2025-08-21, 07:05:11] ERROR - Task failed with exception: source="task"
NotImplementedError: Objects of type <class 'pydantic_core._pydantic_core.SerializationIterator'> are not supported
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 918 in run
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 1213 in _execute_task
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/bases/operator.py", line 397 in wrapper
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 307 in execute
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 201 in get_db_hook
File "/usr/local/lib/python3.12/functools.py", line 998 in __get__
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 177 in _hook
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 166 in get_hook
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/definitions/connection.py", line 162 in extra_dejson
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/secrets_masker.py", line 130 in mask_secret
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 187 in send
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 145 in as_bytes
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 122 in _msgpack_enc_hook

@VladaZakharova

Copy link
Copy Markdown
Contributor

hi @dshvedchenko
Yes, the same problem with google-provider and all the operators and hooks
@ashb Can you please check? Can you please tell maybe there is now a new way to create connections or what?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Which hook is that coming from?

@VladaZakharova

Copy link
Copy Markdown
Contributor

All of them :)
when creating connection to run any hook I see the same error as @dshvedchenko
connection google_cloud_default

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

I think it depends on what fields are in the connection -- In my (admittedly simple) testing with http connection it worked fine.

Can you give me a connection to test with?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor
[2025-08-21, 09:36:10] INFO - conn.conn_id='test' conn.password=None conn=Connection(conn_id='test', conn_type='google_cloud_platform', description=None, host=None, schema=None, login=None, password=None, port=None, extra='{\n "project": null,\n "key_path": null,\n "keyfile_dict": null,\n "credential_config_file": null,\n "scope": null,\n "key_secret_name": null,\n "key_secret_project_id": null,\n "num_retries": 5,\n "impersonation_chain": null,\n "idp_issuer_url": null,\n "client_id": null,\n "client_secret": null,\n "idp_extra_parameters": null,\n "is_anonymous": false\n}'): chan="stdout": source="task"

@VladaZakharova

Copy link
Copy Markdown
Contributor

I was creating connection using:

AIRFLOW_CONN_GOOGLE_CLOUD_DEFAULT='{"conn_type": "google_cloud_default", "extra": {"key_path": "/files/airflow-breeze-config/keys/keys.json", "scope": "https://www.googleapis.com/auth/cloud-platform", "project": "project_id", "num_retries": 5}}'

the problem was originally with some of the triggered where we couldn't pass Enum values from tigggerer to worker (also needs to be reworked).
Now after this mask changes the problem is with creating the connection because of the changes made here #51699 :

def _msgpack_enc_hook(obj: Any) -> Any:
import pendulum
if isinstance(obj, pendulum.DateTime):
# convert the pendulm Datetime subclass into a raw datetime so that msgspec can use it's native
# encoding
return datetime(
obj.year, obj.month, obj.day, obj.hour, obj.minute, obj.second, obj.microsecond, tzinfo=obj.tzinfo
)
if isinstance(obj, Path):
return str(obj)
if isinstance(obj, BaseModel):
return obj.model_dump(exclude_unset=True)
# Raise a NotImplementedError for other types
raise NotImplementedError(f"Objects of type {type(obj)} are not supported")

We need I think more types here to support and it will solve the problem for everyone.

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Looks like this is an unsolved bug in pydantic pydantic/pydantic#9541 (and also impropper testing on our part)

@VladaZakharova

VladaZakharova commented Aug 21, 2025

Copy link
Copy Markdown
Contributor

Looks like yes, more complicated test cases would be good to have :)
are we planning to address this issue to make it work for providers? Looks like there will be more people coming with the same issue

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Nothing providers can do, it needs a change in Airflow core. For people hitting this, if you can't/don't want to downgrade you can apply a patch to your Airflow to work around it - instructions in #54769 (comment)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:task-sdkfull tests neededWe need to run full set of tests for this PR to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Secret masker often doesn't always mask values (user defined mask, or secrets backend)

5 participants

@ashb@potiuk@dshvedchenko@VladaZakharova@jscheffl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

TaskSDK: Make secrets masking work when conns are loaded from secrets backends - #54574

Merged
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor
Aug 17, 2025
Merged

TaskSDK: Make secrets masking work when conns are loaded from secrets backends#54574
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor

Conversation

@ashb

@ashbashb commented Aug 16, 2025

Copy link
Copy Markdown
Member

If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.

This also captures and "mirrors" direct calls to mask_secret from user code
to the supervisor so that it can mask the output correctly.

Docs look like this

Screenshot 2025-08-17 at 16 46 22

Closes#54540

I was testing with this dag. In a follow up I'll add it to the sdk integration tests to ensure masking works fully end-to-end.

from __future__ importannotationsimportloggingfromairflowimportDAGfromairflow.providers.standard.operators.emptyimportEmptyOperatorfromairflow.providers.standard.operators.pythonimportPythonOperatorfromairflow.sdkimportVariablex=Variable.get("my_variable")
defmy_function(my_var: str) ->None:
logging.getLogger(__name__).info(my_var)
withDAG("test_dag") asdag:
start=EmptyOperator(task_id="start")
py_func=PythonOperator(task_id="py_func", python_callable=my_function, op_kwargs={"my_var": x})
end=EmptyOperator(task_id="end")
start>>py_func>>endif__name__=="__main__":
dag.test()

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@ashb

ashb commented Aug 16, 2025

Copy link
Copy Markdown
MemberAuthor

I think I've caused an infinite loop

@ashb

ashb commented Aug 17, 2025

Copy link
Copy Markdown
MemberAuthor

Ah no wasn't an infinite loop, was just not updating the dag processor handler

@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 9af3346 to 700acd1CompareAugust 17, 2025 16:16
… backends
If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.
This also captures and "mirrors" direct calls to `mask_secret` from user code
to the supervisor so that it can mask the output correctly.
@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 700acd1 to ce03d93CompareAugust 17, 2025 16:21
Comment threadtask-sdk/docs/api.rst
@ashbashb added the full tests needed We need to run full set of tests for this PR to merge label Aug 17, 2025
@ashbashb closed this Aug 17, 2025
@ashbashb reopened this Aug 17, 2025
@potiuk

Copy link
Copy Markdown
Member

Nice ! Good one @ashb the pull it so quicky

@ashb
ashb merged commit 1f4c55c into mainAug 17, 2025
179 checks passed
@ashb
ashb deleted the mask-secret-send-to-supervisor branch August 17, 2025 19:21
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-0-test. View the failure log Run details

StatusBranchResult
v3-0-testCommit Link

You can attempt to backport this manually by running:

cherry_picker 1f4c55c v3-0-test

This should apply the commit to the v3-0-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
un-avoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
kaxil pushed a commit that referenced this pull request Aug 18, 2025
kaxil pushed a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
@dshvedchenko

Copy link
Copy Markdown

after upgrading to airflow 3.0.5 operators/hooks failed with similar messages:

[2025-08-21, 07:05:11] INFO - Connection Retrieved 'snowflake_default': source="airflow.hooks.base"
[2025-08-21, 07:05:11] ERROR - Task failed with exception: source="task"
NotImplementedError: Objects of type <class 'pydantic_core._pydantic_core.SerializationIterator'> are not supported
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 918 in run
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 1213 in _execute_task
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/bases/operator.py", line 397 in wrapper
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 307 in execute
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 201 in get_db_hook
File "/usr/local/lib/python3.12/functools.py", line 998 in __get__
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 177 in _hook
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 166 in get_hook
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/definitions/connection.py", line 162 in extra_dejson
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/secrets_masker.py", line 130 in mask_secret
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 187 in send
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 145 in as_bytes
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 122 in _msgpack_enc_hook

@VladaZakharova

Copy link
Copy Markdown
Contributor

hi @dshvedchenko
Yes, the same problem with google-provider and all the operators and hooks
@ashb Can you please check? Can you please tell maybe there is now a new way to create connections or what?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Which hook is that coming from?

@VladaZakharova

Copy link
Copy Markdown
Contributor

All of them :)
when creating connection to run any hook I see the same error as @dshvedchenko
connection google_cloud_default

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

I think it depends on what fields are in the connection -- In my (admittedly simple) testing with http connection it worked fine.

Can you give me a connection to test with?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor
[2025-08-21, 09:36:10] INFO - conn.conn_id='test' conn.password=None conn=Connection(conn_id='test', conn_type='google_cloud_platform', description=None, host=None, schema=None, login=None, password=None, port=None, extra='{\n "project": null,\n "key_path": null,\n "keyfile_dict": null,\n "credential_config_file": null,\n "scope": null,\n "key_secret_name": null,\n "key_secret_project_id": null,\n "num_retries": 5,\n "impersonation_chain": null,\n "idp_issuer_url": null,\n "client_id": null,\n "client_secret": null,\n "idp_extra_parameters": null,\n "is_anonymous": false\n}'): chan="stdout": source="task"

@VladaZakharova

Copy link
Copy Markdown
Contributor

I was creating connection using:

AIRFLOW_CONN_GOOGLE_CLOUD_DEFAULT='{"conn_type": "google_cloud_default", "extra": {"key_path": "/files/airflow-breeze-config/keys/keys.json", "scope": "https://www.googleapis.com/auth/cloud-platform", "project": "project_id", "num_retries": 5}}'

the problem was originally with some of the triggered where we couldn't pass Enum values from tigggerer to worker (also needs to be reworked).
Now after this mask changes the problem is with creating the connection because of the changes made here #51699 :

def _msgpack_enc_hook(obj: Any) -> Any:
import pendulum
if isinstance(obj, pendulum.DateTime):
# convert the pendulm Datetime subclass into a raw datetime so that msgspec can use it's native
# encoding
return datetime(
obj.year, obj.month, obj.day, obj.hour, obj.minute, obj.second, obj.microsecond, tzinfo=obj.tzinfo
)
if isinstance(obj, Path):
return str(obj)
if isinstance(obj, BaseModel):
return obj.model_dump(exclude_unset=True)
# Raise a NotImplementedError for other types
raise NotImplementedError(f"Objects of type {type(obj)} are not supported")

We need I think more types here to support and it will solve the problem for everyone.

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Looks like this is an unsolved bug in pydantic pydantic/pydantic#9541 (and also impropper testing on our part)

@VladaZakharova

VladaZakharova commented Aug 21, 2025

Copy link
Copy Markdown
Contributor

Looks like yes, more complicated test cases would be good to have :)
are we planning to address this issue to make it work for providers? Looks like there will be more people coming with the same issue

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Nothing providers can do, it needs a change in Airflow core. For people hitting this, if you can't/don't want to downgrade you can apply a patch to your Airflow to work around it - instructions in #54769 (comment)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:task-sdkfull tests neededWe need to run full set of tests for this PR to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Secret masker often doesn't always mask values (user defined mask, or secrets backend)

5 participants

@ashb@potiuk@dshvedchenko@VladaZakharova@jscheffl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

TaskSDK: Make secrets masking work when conns are loaded from secrets backends - #54574

Merged
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor
Aug 17, 2025
Merged

TaskSDK: Make secrets masking work when conns are loaded from secrets backends#54574
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor

Conversation

@ashb

@ashbashb commented Aug 16, 2025

Copy link
Copy Markdown
Member

If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.

This also captures and "mirrors" direct calls to mask_secret from user code
to the supervisor so that it can mask the output correctly.

Docs look like this

Screenshot 2025-08-17 at 16 46 22

Closes#54540

I was testing with this dag. In a follow up I'll add it to the sdk integration tests to ensure masking works fully end-to-end.

from __future__ importannotationsimportloggingfromairflowimportDAGfromairflow.providers.standard.operators.emptyimportEmptyOperatorfromairflow.providers.standard.operators.pythonimportPythonOperatorfromairflow.sdkimportVariablex=Variable.get("my_variable")
defmy_function(my_var: str) ->None:
logging.getLogger(__name__).info(my_var)
withDAG("test_dag") asdag:
start=EmptyOperator(task_id="start")
py_func=PythonOperator(task_id="py_func", python_callable=my_function, op_kwargs={"my_var": x})
end=EmptyOperator(task_id="end")
start>>py_func>>endif__name__=="__main__":
dag.test()

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@ashb

ashb commented Aug 16, 2025

Copy link
Copy Markdown
MemberAuthor

I think I've caused an infinite loop

@ashb

ashb commented Aug 17, 2025

Copy link
Copy Markdown
MemberAuthor

Ah no wasn't an infinite loop, was just not updating the dag processor handler

@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 9af3346 to 700acd1CompareAugust 17, 2025 16:16
… backends
If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.
This also captures and "mirrors" direct calls to `mask_secret` from user code
to the supervisor so that it can mask the output correctly.
@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 700acd1 to ce03d93CompareAugust 17, 2025 16:21
Comment threadtask-sdk/docs/api.rst
@ashbashb added the full tests needed We need to run full set of tests for this PR to merge label Aug 17, 2025
@ashbashb closed this Aug 17, 2025
@ashbashb reopened this Aug 17, 2025
@potiuk

Copy link
Copy Markdown
Member

Nice ! Good one @ashb the pull it so quicky

@ashb
ashb merged commit 1f4c55c into mainAug 17, 2025
179 checks passed
@ashb
ashb deleted the mask-secret-send-to-supervisor branch August 17, 2025 19:21
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-0-test. View the failure log Run details

StatusBranchResult
v3-0-testCommit Link

You can attempt to backport this manually by running:

cherry_picker 1f4c55c v3-0-test

This should apply the commit to the v3-0-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
un-avoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
kaxil pushed a commit that referenced this pull request Aug 18, 2025
kaxil pushed a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
@dshvedchenko

Copy link
Copy Markdown

after upgrading to airflow 3.0.5 operators/hooks failed with similar messages:

[2025-08-21, 07:05:11] INFO - Connection Retrieved 'snowflake_default': source="airflow.hooks.base"
[2025-08-21, 07:05:11] ERROR - Task failed with exception: source="task"
NotImplementedError: Objects of type <class 'pydantic_core._pydantic_core.SerializationIterator'> are not supported
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 918 in run
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 1213 in _execute_task
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/bases/operator.py", line 397 in wrapper
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 307 in execute
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 201 in get_db_hook
File "/usr/local/lib/python3.12/functools.py", line 998 in __get__
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 177 in _hook
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 166 in get_hook
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/definitions/connection.py", line 162 in extra_dejson
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/secrets_masker.py", line 130 in mask_secret
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 187 in send
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 145 in as_bytes
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 122 in _msgpack_enc_hook

@VladaZakharova

Copy link
Copy Markdown
Contributor

hi @dshvedchenko
Yes, the same problem with google-provider and all the operators and hooks
@ashb Can you please check? Can you please tell maybe there is now a new way to create connections or what?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Which hook is that coming from?

@VladaZakharova

Copy link
Copy Markdown
Contributor

All of them :)
when creating connection to run any hook I see the same error as @dshvedchenko
connection google_cloud_default

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

I think it depends on what fields are in the connection -- In my (admittedly simple) testing with http connection it worked fine.

Can you give me a connection to test with?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor
[2025-08-21, 09:36:10] INFO - conn.conn_id='test' conn.password=None conn=Connection(conn_id='test', conn_type='google_cloud_platform', description=None, host=None, schema=None, login=None, password=None, port=None, extra='{\n "project": null,\n "key_path": null,\n "keyfile_dict": null,\n "credential_config_file": null,\n "scope": null,\n "key_secret_name": null,\n "key_secret_project_id": null,\n "num_retries": 5,\n "impersonation_chain": null,\n "idp_issuer_url": null,\n "client_id": null,\n "client_secret": null,\n "idp_extra_parameters": null,\n "is_anonymous": false\n}'): chan="stdout": source="task"

@VladaZakharova

Copy link
Copy Markdown
Contributor

I was creating connection using:

AIRFLOW_CONN_GOOGLE_CLOUD_DEFAULT='{"conn_type": "google_cloud_default", "extra": {"key_path": "/files/airflow-breeze-config/keys/keys.json", "scope": "https://www.googleapis.com/auth/cloud-platform", "project": "project_id", "num_retries": 5}}'

the problem was originally with some of the triggered where we couldn't pass Enum values from tigggerer to worker (also needs to be reworked).
Now after this mask changes the problem is with creating the connection because of the changes made here #51699 :

def _msgpack_enc_hook(obj: Any) -> Any:
import pendulum
if isinstance(obj, pendulum.DateTime):
# convert the pendulm Datetime subclass into a raw datetime so that msgspec can use it's native
# encoding
return datetime(
obj.year, obj.month, obj.day, obj.hour, obj.minute, obj.second, obj.microsecond, tzinfo=obj.tzinfo
)
if isinstance(obj, Path):
return str(obj)
if isinstance(obj, BaseModel):
return obj.model_dump(exclude_unset=True)
# Raise a NotImplementedError for other types
raise NotImplementedError(f"Objects of type {type(obj)} are not supported")

We need I think more types here to support and it will solve the problem for everyone.

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Looks like this is an unsolved bug in pydantic pydantic/pydantic#9541 (and also impropper testing on our part)

@VladaZakharova

VladaZakharova commented Aug 21, 2025

Copy link
Copy Markdown
Contributor

Looks like yes, more complicated test cases would be good to have :)
are we planning to address this issue to make it work for providers? Looks like there will be more people coming with the same issue

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Nothing providers can do, it needs a change in Airflow core. For people hitting this, if you can't/don't want to downgrade you can apply a patch to your Airflow to work around it - instructions in #54769 (comment)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:task-sdkfull tests neededWe need to run full set of tests for this PR to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Secret masker often doesn't always mask values (user defined mask, or secrets backend)

5 participants

@ashb@potiuk@dshvedchenko@VladaZakharova@jscheffl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

TaskSDK: Make secrets masking work when conns are loaded from secrets backends - #54574

Merged
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor
Aug 17, 2025
Merged

TaskSDK: Make secrets masking work when conns are loaded from secrets backends#54574
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor

Conversation

@ashb

@ashbashb commented Aug 16, 2025

Copy link
Copy Markdown
Member

If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.

This also captures and "mirrors" direct calls to mask_secret from user code
to the supervisor so that it can mask the output correctly.

Docs look like this

Screenshot 2025-08-17 at 16 46 22

Closes#54540

I was testing with this dag. In a follow up I'll add it to the sdk integration tests to ensure masking works fully end-to-end.

from __future__ importannotationsimportloggingfromairflowimportDAGfromairflow.providers.standard.operators.emptyimportEmptyOperatorfromairflow.providers.standard.operators.pythonimportPythonOperatorfromairflow.sdkimportVariablex=Variable.get("my_variable")
defmy_function(my_var: str) ->None:
logging.getLogger(__name__).info(my_var)
withDAG("test_dag") asdag:
start=EmptyOperator(task_id="start")
py_func=PythonOperator(task_id="py_func", python_callable=my_function, op_kwargs={"my_var": x})
end=EmptyOperator(task_id="end")
start>>py_func>>endif__name__=="__main__":
dag.test()

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@ashb

ashb commented Aug 16, 2025

Copy link
Copy Markdown
MemberAuthor

I think I've caused an infinite loop

@ashb

ashb commented Aug 17, 2025

Copy link
Copy Markdown
MemberAuthor

Ah no wasn't an infinite loop, was just not updating the dag processor handler

@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 9af3346 to 700acd1CompareAugust 17, 2025 16:16
… backends
If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.
This also captures and "mirrors" direct calls to `mask_secret` from user code
to the supervisor so that it can mask the output correctly.
@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 700acd1 to ce03d93CompareAugust 17, 2025 16:21
Comment threadtask-sdk/docs/api.rst
@ashbashb added the full tests needed We need to run full set of tests for this PR to merge label Aug 17, 2025
@ashbashb closed this Aug 17, 2025
@ashbashb reopened this Aug 17, 2025
@potiuk

Copy link
Copy Markdown
Member

Nice ! Good one @ashb the pull it so quicky

@ashb
ashb merged commit 1f4c55c into mainAug 17, 2025
179 checks passed
@ashb
ashb deleted the mask-secret-send-to-supervisor branch August 17, 2025 19:21
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-0-test. View the failure log Run details

StatusBranchResult
v3-0-testCommit Link

You can attempt to backport this manually by running:

cherry_picker 1f4c55c v3-0-test

This should apply the commit to the v3-0-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
un-avoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
kaxil pushed a commit that referenced this pull request Aug 18, 2025
kaxil pushed a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
@dshvedchenko

Copy link
Copy Markdown

after upgrading to airflow 3.0.5 operators/hooks failed with similar messages:

[2025-08-21, 07:05:11] INFO - Connection Retrieved 'snowflake_default': source="airflow.hooks.base"
[2025-08-21, 07:05:11] ERROR - Task failed with exception: source="task"
NotImplementedError: Objects of type <class 'pydantic_core._pydantic_core.SerializationIterator'> are not supported
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 918 in run
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 1213 in _execute_task
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/bases/operator.py", line 397 in wrapper
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 307 in execute
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 201 in get_db_hook
File "/usr/local/lib/python3.12/functools.py", line 998 in __get__
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 177 in _hook
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 166 in get_hook
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/definitions/connection.py", line 162 in extra_dejson
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/secrets_masker.py", line 130 in mask_secret
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 187 in send
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 145 in as_bytes
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 122 in _msgpack_enc_hook

@VladaZakharova

Copy link
Copy Markdown
Contributor

hi @dshvedchenko
Yes, the same problem with google-provider and all the operators and hooks
@ashb Can you please check? Can you please tell maybe there is now a new way to create connections or what?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Which hook is that coming from?

@VladaZakharova

Copy link
Copy Markdown
Contributor

All of them :)
when creating connection to run any hook I see the same error as @dshvedchenko
connection google_cloud_default

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

I think it depends on what fields are in the connection -- In my (admittedly simple) testing with http connection it worked fine.

Can you give me a connection to test with?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor
[2025-08-21, 09:36:10] INFO - conn.conn_id='test' conn.password=None conn=Connection(conn_id='test', conn_type='google_cloud_platform', description=None, host=None, schema=None, login=None, password=None, port=None, extra='{\n "project": null,\n "key_path": null,\n "keyfile_dict": null,\n "credential_config_file": null,\n "scope": null,\n "key_secret_name": null,\n "key_secret_project_id": null,\n "num_retries": 5,\n "impersonation_chain": null,\n "idp_issuer_url": null,\n "client_id": null,\n "client_secret": null,\n "idp_extra_parameters": null,\n "is_anonymous": false\n}'): chan="stdout": source="task"

@VladaZakharova

Copy link
Copy Markdown
Contributor

I was creating connection using:

AIRFLOW_CONN_GOOGLE_CLOUD_DEFAULT='{"conn_type": "google_cloud_default", "extra": {"key_path": "/files/airflow-breeze-config/keys/keys.json", "scope": "https://www.googleapis.com/auth/cloud-platform", "project": "project_id", "num_retries": 5}}'

the problem was originally with some of the triggered where we couldn't pass Enum values from tigggerer to worker (also needs to be reworked).
Now after this mask changes the problem is with creating the connection because of the changes made here #51699 :

def _msgpack_enc_hook(obj: Any) -> Any:
import pendulum
if isinstance(obj, pendulum.DateTime):
# convert the pendulm Datetime subclass into a raw datetime so that msgspec can use it's native
# encoding
return datetime(
obj.year, obj.month, obj.day, obj.hour, obj.minute, obj.second, obj.microsecond, tzinfo=obj.tzinfo
)
if isinstance(obj, Path):
return str(obj)
if isinstance(obj, BaseModel):
return obj.model_dump(exclude_unset=True)
# Raise a NotImplementedError for other types
raise NotImplementedError(f"Objects of type {type(obj)} are not supported")

We need I think more types here to support and it will solve the problem for everyone.

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Looks like this is an unsolved bug in pydantic pydantic/pydantic#9541 (and also impropper testing on our part)

@VladaZakharova

VladaZakharova commented Aug 21, 2025

Copy link
Copy Markdown
Contributor

Looks like yes, more complicated test cases would be good to have :)
are we planning to address this issue to make it work for providers? Looks like there will be more people coming with the same issue

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Nothing providers can do, it needs a change in Airflow core. For people hitting this, if you can't/don't want to downgrade you can apply a patch to your Airflow to work around it - instructions in #54769 (comment)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:task-sdkfull tests neededWe need to run full set of tests for this PR to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Secret masker often doesn't always mask values (user defined mask, or secrets backend)

5 participants

@ashb@potiuk@dshvedchenko@VladaZakharova@jscheffl
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

TaskSDK: Make secrets masking work when conns are loaded from secrets backends - #54574

Merged
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor
Aug 17, 2025
Merged

TaskSDK: Make secrets masking work when conns are loaded from secrets backends#54574
ashb merged 1 commit into
mainfrom
mask-secret-send-to-supervisor

Conversation

@ashb

@ashbashb commented Aug 16, 2025

Copy link
Copy Markdown
Member

If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.

This also captures and "mirrors" direct calls to mask_secret from user code
to the supervisor so that it can mask the output correctly.

Docs look like this

Screenshot 2025-08-17 at 16 46 22

Closes#54540

I was testing with this dag. In a follow up I'll add it to the sdk integration tests to ensure masking works fully end-to-end.

from __future__ importannotationsimportloggingfromairflowimportDAGfromairflow.providers.standard.operators.emptyimportEmptyOperatorfromairflow.providers.standard.operators.pythonimportPythonOperatorfromairflow.sdkimportVariablex=Variable.get("my_variable")
defmy_function(my_var: str) ->None:
logging.getLogger(__name__).info(my_var)
withDAG("test_dag") asdag:
start=EmptyOperator(task_id="start")
py_func=PythonOperator(task_id="py_func", python_callable=my_function, op_kwargs={"my_var": x})
end=EmptyOperator(task_id="end")
start>>py_func>>endif__name__=="__main__":
dag.test()

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@ashb

ashb commented Aug 16, 2025

Copy link
Copy Markdown
MemberAuthor

I think I've caused an infinite loop

@ashb

ashb commented Aug 17, 2025

Copy link
Copy Markdown
MemberAuthor

Ah no wasn't an infinite loop, was just not updating the dag processor handler

@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 9af3346 to 700acd1CompareAugust 17, 2025 16:16
… backends
If the connection is loaded from a secrets backend (be it something like
Hashicorp Vault, or even just as simple as env vars!) the mask will only be
applied to the subprocess, so won't catch much of the output. To fix this we
send a message to the Supervisor process of the value to redact.
This also captures and "mirrors" direct calls to `mask_secret` from user code
to the supervisor so that it can mask the output correctly.
@ashb
ashbforce-pushed the mask-secret-send-to-supervisor branch from 700acd1 to ce03d93CompareAugust 17, 2025 16:21
Comment threadtask-sdk/docs/api.rst
@ashbashb added the full tests needed We need to run full set of tests for this PR to merge label Aug 17, 2025
@ashbashb closed this Aug 17, 2025
@ashbashb reopened this Aug 17, 2025
@potiuk

Copy link
Copy Markdown
Member

Nice ! Good one @ashb the pull it so quicky

@ashb
ashb merged commit 1f4c55c into mainAug 17, 2025
179 checks passed
@ashb
ashb deleted the mask-secret-send-to-supervisor branch August 17, 2025 19:21
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-0-test. View the failure log Run details

StatusBranchResult
v3-0-testCommit Link

You can attempt to backport this manually by running:

cherry_picker 1f4c55c v3-0-test

This should apply the commit to the v3-0-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
un-avoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
ashb added a commit that referenced this pull request Aug 18, 2025
ashb added a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
kaxil pushed a commit that referenced this pull request Aug 18, 2025
kaxil pushed a commit that referenced this pull request Aug 18, 2025
…ers (#54612)
Somewhat annoyingly it has to be `sync_to_async(mask_secret)` but that is
unavoidable unfortunately.
Similar to #54574, but for the trigger.
(cherry picked from commit a2bd625)
@dshvedchenko

Copy link
Copy Markdown

after upgrading to airflow 3.0.5 operators/hooks failed with similar messages:

[2025-08-21, 07:05:11] INFO - Connection Retrieved 'snowflake_default': source="airflow.hooks.base"
[2025-08-21, 07:05:11] ERROR - Task failed with exception: source="task"
NotImplementedError: Objects of type <class 'pydantic_core._pydantic_core.SerializationIterator'> are not supported
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 918 in run
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/task_runner.py", line 1213 in _execute_task
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/bases/operator.py", line 397 in wrapper
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 307 in execute
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 201 in get_db_hook
File "/usr/local/lib/python3.12/functools.py", line 998 in __get__
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 177 in _hook
File "/usr/local/lib/python3.12/site-packages/airflow/providers/common/sql/operators/sql.py", line 166 in get_hook
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/definitions/connection.py", line 162 in extra_dejson
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/secrets_masker.py", line 130 in mask_secret
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 187 in send
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 145 in as_bytes
File "/usr/local/lib/python3.12/site-packages/airflow/sdk/execution_time/comms.py", line 122 in _msgpack_enc_hook

@VladaZakharova

Copy link
Copy Markdown
Contributor

hi @dshvedchenko
Yes, the same problem with google-provider and all the operators and hooks
@ashb Can you please check? Can you please tell maybe there is now a new way to create connections or what?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Which hook is that coming from?

@VladaZakharova

Copy link
Copy Markdown
Contributor

All of them :)
when creating connection to run any hook I see the same error as @dshvedchenko
connection google_cloud_default

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

I think it depends on what fields are in the connection -- In my (admittedly simple) testing with http connection it worked fine.

Can you give me a connection to test with?

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor
[2025-08-21, 09:36:10] INFO - conn.conn_id='test' conn.password=None conn=Connection(conn_id='test', conn_type='google_cloud_platform', description=None, host=None, schema=None, login=None, password=None, port=None, extra='{\n "project": null,\n "key_path": null,\n "keyfile_dict": null,\n "credential_config_file": null,\n "scope": null,\n "key_secret_name": null,\n "key_secret_project_id": null,\n "num_retries": 5,\n "impersonation_chain": null,\n "idp_issuer_url": null,\n "client_id": null,\n "client_secret": null,\n "idp_extra_parameters": null,\n "is_anonymous": false\n}'): chan="stdout": source="task"

@VladaZakharova

Copy link
Copy Markdown
Contributor

I was creating connection using:

AIRFLOW_CONN_GOOGLE_CLOUD_DEFAULT='{"conn_type": "google_cloud_default", "extra": {"key_path": "/files/airflow-breeze-config/keys/keys.json", "scope": "https://www.googleapis.com/auth/cloud-platform", "project": "project_id", "num_retries": 5}}'

the problem was originally with some of the triggered where we couldn't pass Enum values from tigggerer to worker (also needs to be reworked).
Now after this mask changes the problem is with creating the connection because of the changes made here #51699 :

def _msgpack_enc_hook(obj: Any) -> Any:
import pendulum
if isinstance(obj, pendulum.DateTime):
# convert the pendulm Datetime subclass into a raw datetime so that msgspec can use it's native
# encoding
return datetime(
obj.year, obj.month, obj.day, obj.hour, obj.minute, obj.second, obj.microsecond, tzinfo=obj.tzinfo
)
if isinstance(obj, Path):
return str(obj)
if isinstance(obj, BaseModel):
return obj.model_dump(exclude_unset=True)
# Raise a NotImplementedError for other types
raise NotImplementedError(f"Objects of type {type(obj)} are not supported")

We need I think more types here to support and it will solve the problem for everyone.

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Looks like this is an unsolved bug in pydantic pydantic/pydantic#9541 (and also impropper testing on our part)

@VladaZakharova

VladaZakharova commented Aug 21, 2025

Copy link
Copy Markdown
Contributor

Looks like yes, more complicated test cases would be good to have :)
are we planning to address this issue to make it work for providers? Looks like there will be more people coming with the same issue

@ashb

ashb commented Aug 21, 2025

Copy link
Copy Markdown
MemberAuthor

Nothing providers can do, it needs a change in Airflow core. For people hitting this, if you can't/don't want to downgrade you can apply a patch to your Airflow to work around it - instructions in #54769 (comment)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:task-sdkfull tests neededWe need to run full set of tests for this PR to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Secret masker often doesn't always mask values (user defined mask, or secrets backend)

5 participants

@ashb@potiuk@dshvedchenko@VladaZakharova@jscheffl