Miretpl commented on code in PR #73399:
URL: https://github.com/apache/airflow/pull/73399#discussion_r4066587402


##########
providers/cncf/kubernetes/src/airflow/providers/cncf/kubernetes/hooks/kubernetes.py:
##########
@@ -1059,14 +1060,28 @@ async def _get_field(self, field_name):
 
     @contextlib.asynccontextmanager
     async def get_conn(self) -> AsyncGenerator[async_client.ApiClient, None]:
-        kube_client = None
+        await self._load_config()
+        if self._config_loaded:
+            # Reuse one client per hook: each construction runs 
ssl.create_default_context()
+            # on the event loop and opens a new connection pool. Owners 
release it via
+            # close(); triggers do so in cleanup().
+            if self._cached_kube_client is None:
+                self._cached_kube_client = 
_TimeoutAsyncK8sApiClient(configuration=self.client_configuration)
+            yield self._cached_kube_client
+            return
+        # Exec-based auth rotates short-lived tokens by reloading the config on

Review Comment:
   This change might also affect the non-exec-based configurations. These 
tokens will also have an expiry time, and for long-running workloads, it might 
be reached. As I think that for async workloads this optimisation (SSL) is 
needed, I also think that we should not introduce a regression in reliability 
and stability because of that.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to