kaxil commented on code in PR #73374:
URL: https://github.com/apache/airflow/pull/73374#discussion_r4070529510


##########
providers/common/sql/src/airflow/providers/common/sql/datafusion/engine.py:
##########
@@ -196,6 +196,47 @@ def _fetch_extra_configs(keys: list[str]) -> dict[str, 
Any]:
                     key_path = os.environ.get("GOOGLE_APPLICATION_CREDENTIALS")
                 credentials = self._remove_none_values({"key_path": key_path, 
"keyfile_dict": keyfile_dict})
 
+            case "wasb":
+                extra_dejson = conn.extra_dejson
+                for unsupported_field in (
+                    "connection_string",
+                    "managed_identity_client_id",
+                    "workload_identity_tenant_id",
+                ):
+                    if extra_dejson.get(unsupported_field):
+                        raise ValueError(
+                            f"Connection field {unsupported_field!r} is not 
supported for DataFusion "
+                            "Azure Blob Storage access; only 
tenant_id+login+password (service "
+                            "principal), sas_token, 
shared_access_key/account_key/password, or ambient "
+                            "credentials (AZURE_* environment variables, 
managed identity, workload "
+                            "identity, or az login) are used."
+                        )
+                credentials = {"account": conn.login}

Review Comment:
   `account` comes from `conn.login` in every branch, but WasbHook resolves the 
storage account from `conn.host` first and only falls back to `login` 
(`parse_blob_account_url(conn.host, conn.login)` in `hooks/wasb.py`). In the 
service-principal branch below, `login` is the client_id, so the same GUID goes 
out as both `account` and `client_id` and the store targets 
`https://<client-id>.blob.core.windows.net`. The other side of it: a connection 
that keeps the account in `host` and authenticates with a key or SAS and an 
empty `login` ends up with no `account` at all, and the binding silently falls 
back to `AZURE_STORAGE_ACCOUNT_NAME`.
   
   Could this take the account from `host` when it is set (the first label of 
the netloc, as `parse_blob_account_url` does) and only then fall back to 
`login`? `test_get_credentials_azure_with_service_principal` currently pins 
`"account": "client-id"`, and the docs section should say where the account 
name comes from in that mode.



##########
providers/common/sql/src/airflow/providers/common/sql/datafusion/object_storage_provider.py:
##########
@@ -107,6 +107,37 @@ def get_scheme(self) -> str:
         return "gs://"
 
 
+class AzureObjectStorageProvider(ObjectStorageProvider):
+    """Azure Object Storage Provider using DataFusion's MicrosoftAzure."""
+
+    @property
+    def get_storage_type(self) -> StorageType:
+        """Return the storage type."""
+        return StorageType.AZURE
+
+    def create_object_store(self, path: str, connection_config: 
ConnectionConfig | None = None):
+        """Create an Azure object store using DataFusion's MicrosoftAzure."""
+        if connection_config is None:
+            raise ValueError(f"connection_config must be provided for 
{self.get_storage_type}")

Review Comment:
   The S3 and GCS providers format this with `.value`. Without it, 
`f"{StorageType.AZURE}"` renders as `azure` on 3.10 but as `StorageType.AZURE` 
on 3.12 and 3.13, where `__format__` on mixed-in enums changed. 
`test_azure_provider_requires_connection_config` matches on `for azure`, so it 
passes on the 3.10 job this PR ran but fails on the 3.12/3.13 legs of the full 
matrix.



##########
providers/common/sql/src/airflow/providers/common/sql/config.py:
##########
@@ -117,6 +118,8 @@ def _extract_storage_type(self) -> StorageType | None:
             return StorageType.S3
         if self.uri.startswith("gs://"):
             return StorageType.GCS
+        if self.uri.startswith("az://"):

Review Comment:
   Is accepting only `az://` deliberate for now? `object_store`'s Azure builder 
also parses `abfs://` and `abfss://` (the `"az" | "abfs" | "abfss"` arm in 
`src/azure/builder.rs`), and 
`abfss://[email protected]/path` is the form most ADLS 
docs hand out. If `az://` only is the intended scope, the docs section should 
say so, since the failure mode users see is `Unsupported storage type for URI`.



##########
providers/common/sql/src/airflow/providers/common/sql/datafusion/engine.py:
##########
@@ -196,6 +196,47 @@ def _fetch_extra_configs(keys: list[str]) -> dict[str, 
Any]:
                     key_path = os.environ.get("GOOGLE_APPLICATION_CREDENTIALS")
                 credentials = self._remove_none_values({"key_path": key_path, 
"keyfile_dict": keyfile_dict})
 
+            case "wasb":
+                extra_dejson = conn.extra_dejson
+                for unsupported_field in (
+                    "connection_string",
+                    "managed_identity_client_id",
+                    "workload_identity_tenant_id",
+                ):
+                    if extra_dejson.get(unsupported_field):
+                        raise ValueError(
+                            f"Connection field {unsupported_field!r} is not 
supported for DataFusion "
+                            "Azure Blob Storage access; only 
tenant_id+login+password (service "
+                            "principal), sas_token, 
shared_access_key/account_key/password, or ambient "
+                            "credentials (AZURE_* environment variables, 
managed identity, workload "
+                            "identity, or az login) are used."
+                        )
+                credentials = {"account": conn.login}
+                tenant_id = extra_dejson.get("tenant_id")
+                sas_token = extra_dejson.get("sas_token")
+                if tenant_id and conn.login and conn.password:
+                    # client_id/client_secret/tenant_id must all be set 
together, or not at all --
+                    # DataFusion's binding panics on a partial combination.
+                    credentials.update(
+                        {"client_id": conn.login, "client_secret": 
conn.password, "tenant_id": tenant_id}
+                    )
+                elif sas_token:
+                    if sas_token.startswith("http"):
+                        raise ValueError(
+                            "A URL-form `sas_token` is not supported for 
DataFusion Azure Blob Storage "
+                            "access; provide the SAS token as a query string 
instead."
+                        )
+                    from urllib.parse import parse_qsl

Review Comment:
   `urllib.parse` is stdlib, so this can live with the module imports at the 
top.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to