Skip to content

Conversation

@sdaberdaku
Copy link
Contributor

@sdaberdaku sdaberdaku commented Mar 7, 2025


Summary

This PR introduces a configurable AWS region parameter for Vault authentication via AWS IAM in the HashiCorp provider. Previously, the airflow.providers.hashicorp._internal_client.vault_client._VaultClient._auth_aws_iam() method did not pass a region parameter to hvac.api.auth_methods.Aws.iam_login(), causing authentication failures when Vault was configured with an STS endpoint outside us-east-1.

Changes Introduced

  • Added a region parameter to VaultBackend, VaultHook, and _VaultClient, allowing users to specify the AWS region for STS authentication.
  • If region is not explicitly provided, it defaults to the region configured in boto3 (e.g., via environment variables or instance metadata).
  • Passed the region parameter to iam_login() in hvac.
  • Updated tests to validate region configuration.
  • Passed the role_id parameter to iam_login() even when not using key_id and secret_id for authentication. If not passed to iam_login(), the login endpoint looks for a role bearing the name of the AMI ID of the EC2 instance that is trying to login if using the ec2 auth method, or the "friendly name" (i.e., role name or username) of the IAM principal authenticated. If the name does not match the Vault role, login fails.

Related Issue

closes: #47470

^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in newsfragments.

@boring-cyborg boring-cyborg bot added area:providers area:secrets provider:hashicorp Hashicorp provider related issues labels Mar 7, 2025
@boring-cyborg
Copy link

boring-cyborg bot commented Mar 7, 2025

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide (https://github.com/apache/airflow/blob/main/contributing-docs/README.rst)
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our pre-commits will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example DAG that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

@sdaberdaku sdaberdaku marked this pull request as ready for review March 7, 2025 14:26
@potiuk potiuk merged commit 1d70f95 into apache:main Mar 7, 2025
60 checks passed
@boring-cyborg
Copy link

boring-cyborg bot commented Mar 7, 2025

Awesome work, congrats on your first merged pull request! You are invited to check our Issue Tracker for additional contributions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vault secrets backend fails AWS IAM Authentication if Vault is configured with STS region other than us-east-1

2 participants