ccoliu commented on PR #74085: URL: https://github.com/apache/airflow/pull/74085#issuecomment-5989999358
Thanks for the review, agreed. To answer your question: no, the hook can't verify it. Encryption below the application layer (e.g. an Istio mTLS sidecar) is transparent to the client, which only sees a plain `http` connection. That's why it's opt-in and the operator has to enable it explicitly. I've pushed an update that: - logs a warning each time a connection with `allow_insecure_auth` enabled is created, stating that the HTTPS requirement is disabled and credentials may be sent in cleartext if the transport isn't protected, and - adds a `.. warning::` block to the connection docs saying the same, including that Airflow cannot verify the lower-layer encryption. The tests also assert the warning is logged only when the option is enabled. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
