ccoliu commented on PR #74085:
URL: https://github.com/apache/airflow/pull/74085#issuecomment-5989999358

   Thanks for the review, agreed. To answer your question: no, the hook can't 
verify it. Encryption below the application layer (e.g. an Istio mTLS sidecar) 
is transparent to the client, which only sees a plain `http` connection. That's 
why it's opt-in and the operator has to enable it explicitly.
   
   I've pushed an update that:
   
   - logs a warning each time a connection with `allow_insecure_auth` enabled 
is created, stating that the HTTPS requirement is disabled and credentials may 
be sent in cleartext if the transport isn't protected, and
   - adds a `.. warning::` block to the connection docs saying the same, 
including that Airflow cannot verify the lower-layer encryption.
   
   The tests also assert the warning is logged only when the option is enabled.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to