-
Notifications
You must be signed in to change notification settings - Fork 14.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix trigger kwarg encryption migration #39246
Merged
jedcunningham
merged 4 commits into
apache:main
from
astronomer:fix_trigger_encryption_migration
Apr 25, 2024
Merged
Fix trigger kwarg encryption migration #39246
jedcunningham
merged 4 commits into
apache:main
from
astronomer:fix_trigger_encryption_migration
Apr 25, 2024
+72
−52
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
jedcunningham
requested review from
dstandish,
hussein-awala and
potiuk
as code owners
April 25, 2024 05:31
boring-cyborg
bot
added
area:db-migrations
PRs with DB migration
area:Triggerer
kind:documentation
labels
Apr 25, 2024
jedcunningham
commented
Apr 25, 2024
Lee-W
reviewed
Apr 25, 2024
Lee-W
force-pushed
the
fix_trigger_encryption_migration
branch
from
April 25, 2024 07:20
ae7f1f4
to
466fda0
Compare
Do the encryption in the migration itself, and fix support for offline migrations as well. The offline up migration won't actually encrypt the trigger kwargs as there isn't a safe way to accomplish that, so the decryption processes checks and short circuits if it isn't encrypted. The offline down migration will now print out a warning that the offline migration will fail if there are any running triggers. I think this is the best we can do for that scenario (and folks willing to do offline migrations will hopefully be able to understand the situation). This also solves the "encrypting the already encrypted kwargs" bug in 2.9.0.
Lee-W
force-pushed
the
fix_trigger_encryption_migration
branch
from
April 25, 2024 07:21
466fda0
to
f2fd7a8
Compare
uranusjr
approved these changes
Apr 25, 2024
Lee-W
approved these changes
Apr 25, 2024
We've tested the matrix of postges/mysql/sqlite and online/offline migrations. Didn't find any issues 👍. I think this should be good. I'd like to get 1 more approval on this before we merge it though. |
dstandish
reviewed
Apr 25, 2024
2 tasks
dstandish
reviewed
Apr 25, 2024
dstandish
approved these changes
Apr 25, 2024
jedcunningham
added a commit
that referenced
this pull request
Apr 26, 2024
Do the encryption in the migration itself, and fix support for offline migrations as well. The offline up migration won't actually encrypt the trigger kwargs as there isn't a safe way to accomplish that, so the decryption processes checks and short circuits if it isn't encrypted. The offline down migration will now print out a warning that the offline migration will fail if there are any running triggers. I think this is the best we can do for that scenario (and folks willing to do offline migrations will hopefully be able to understand the situation). This also solves the "encrypting the already encrypted kwargs" bug in 2.9.0. (cherry picked from commit adeb7f7)
56 tasks
RodrigoGanancia
pushed a commit
to RodrigoGanancia/airflow
that referenced
this pull request
May 10, 2024
Do the encryption in the migration itself, and fix support for offline migrations as well. The offline up migration won't actually encrypt the trigger kwargs as there isn't a safe way to accomplish that, so the decryption processes checks and short circuits if it isn't encrypted. The offline down migration will now print out a warning that the offline migration will fail if there are any running triggers. I think this is the best we can do for that scenario (and folks willing to do offline migrations will hopefully be able to understand the situation). This also solves the "encrypting the already encrypted kwargs" bug in 2.9.0.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
area:db-migrations
PRs with DB migration
area:Triggerer
kind:documentation
type:bug-fix
Changelog: Bug Fixes
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes: #38836
Alternative to #38876
Do the encryption in the migration itself, and fix support for offline migrations as well.
The offline up migration won't actually encrypt the trigger kwargs as there isn't a safe way to accomplish that, so the decryption processes checks and short circuits if it isn't encrypted.
The offline down migration will now print out a warning that the offline migration will fail if there are any running triggers. I think this is the best we can do for that scenario (and folks willing to do offline migrations will hopefully be able to understand the situation).
This also solves the "encrypting the already encrypted kwargs" bug in 2.9.0.