xvega commented on code in PR #73399:
URL: https://github.com/apache/airflow/pull/73399#discussion_r4168918970
##########
providers/cncf/kubernetes/src/airflow/providers/cncf/kubernetes/hooks/kubernetes.py:
##########
@@ -1059,14 +1060,28 @@ async def _get_field(self, field_name):
@contextlib.asynccontextmanager
async def get_conn(self) -> AsyncGenerator[async_client.ApiClient, None]:
- kube_client = None
+ await self._load_config()
+ if self._config_loaded:
+ # Reuse one client per hook: each construction runs
ssl.create_default_context()
+ # on the event loop and opens a new connection pool. Owners
release it via
+ # close(); triggers do so in cleanup().
+ if self._cached_kube_client is None:
+ self._cached_kube_client =
_TimeoutAsyncK8sApiClient(configuration=self.client_configuration)
+ yield self._cached_kube_client
+ return
+ # Exec-based auth rotates short-lived tokens by reloading the config on
Review Comment:
Addressed. The config is now reloaded on every call, so the cached client
always sends the current token only the SSL context and connection pool are
reused. Added regression tests for rotated kubeconfig tokens and an expired gcp
auth-provider token.
Note: on current main the config is only loaded once per hook (since
#65212), so a static token is already frozen for the trigger's whole lifetime
today, this PR actually makes token handling fresher than main. The only thing
still cached is TLS cert material, same limitation as discussed in
[apache/airflow#71349](https://github.com/apache/airflow/pull/71349).
Also renamed `_config_loaded` to `_client_cacheable`: the config isn't
cached anymore, the flag now only marks whether the client can be reused.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]