如何在Airflow Helm Chart中添加[Secrets]连接配置
使用Airflow Helm Chart配置HashiCorp Vault Secrets后端
你不需要单独创建ConfigMap,Airflow Helm Chart支持直接通过values.yaml中的airflow.config字段覆盖airflow.cfg的配置项,这是最可靠的方式。
核心配置步骤
在你的Helm values文件中添加以下内容:
airflow: # 覆盖airflow.cfg中的secrets配置段 config: secrets: backend: "airflow.providers.hashicorp.secrets.vault.VaultBackend" # 注意用单引号包裹JSON字符串,避免YAML解析冲突 backend_kwargs: '{"connections_path": "connections", "variables_path": "variables", "mount_point": "airflow", "url": "http://127.0.0.1:8200"}' # 确保安装HashiCorp Provider(如果未预装) extraPipPackages: - apache-airflow-providers-hashicorp>=3.0.0
应用配置
如果是已部署的Airflow实例,执行升级命令:
helm upgrade airflow apache-airflow/airflow -f your-values.yaml
如果是新部署,直接用该values文件安装即可。
补充:Vault认证配置(以Token为例)
如果你的Vault需要token认证,先创建Kubernetes Secret存储token:
kubectl create secret generic vault-token-secret --from-literal=token=your-vault-authentication-token
然后在values.yaml中添加Secret注入和更新backend_kwargs:
airflow: secrets: # 将Vault token注入为环境变量VAULT_TOKEN - name: vault-token secretName: vault-token-secret key: token envName: VAULT_TOKEN config: secrets: backend: "airflow.providers.hashicorp.secrets.vault.VaultBackend" backend_kwargs: '{"connections_path": "connections", "variables_path": "variables", "mount_point": "airflow", "url": "http://127.0.0.1:8200", "token": "${VAULT_TOKEN}"}'
内容的提问来源于stack exchange,提问作者BlackButton
相关产品推荐
相关产品推荐

