You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache Airflow配置Google OAuth登录后提示无效登录求助

Apache Airflow 2.5.1 Docker部署下Google Workspace OAuth认证失败(提示invalid login)

我正在尝试通过Google Workspace对Docker部署的Apache Airflow(v2.5.1)做身份认证,已完成以下操作:

  • 配置了Google OAuth2客户端
  • 使用官方Docker Compose包部署Airflow
  • 参考Airflow官方文档配置Webserver OAuth授权

点击「使用Google登录」按钮后,能正常进入Google授权页面并完成授权,但跳转回localhost:8080后,系统持续提示「Invalid login. Please try again.」,无法进入Airflow主界面。

相关观察

  • 未配置安全管理器,不清楚其配置方法和用途
  • 重定向URL(.../oauth-authorized/google)配置正确,之前配错时Google直接无法完成登录流程
  • 未配置「认证后端」,仅在Airflow旧版本中找到相关配置项
  • Docker镜像已安装oauthlib 3.2.2库
  • 用OAuth调试工具测试OIDC流程,Google能正常颁发令牌,推测问题出在Airflow端

当前配置文件

webserver_config.py

from flask_appbuilder.security.manager import AUTH_OAUTH
import os

# OAUTH configuration for Airflow Web Server

# copied from default config
WTF_CSRF_ENABLED = True
WTF_CSRF_TIME_LIMIT = None

# oauth specific
AUTH_TYPE = AUTH_OAUTH
AUTH_ROLES_SYNC_AT_LOGIN = True  # Checks roles on every login
AUTH_USER_REGISTRATION = False
# FAB_SECURITY_MANAGER_CLASS = "your_module.your_security_manager_class"

OAUTH_PROVIDERS = [
    {
        "name": "google",
        "token_key": "access_token",
        "icon": "fa-google",
        "remote_app": {
            "api_base_url": "https://www.googleapis.com/oauth2/v2/",
            "client_kwargs": {"scope": "email profile"},
            "access_token_url": "https://accounts.google.com/o/oauth2/token",
            "authorize_url": "https://accounts.google.com/o/oauth2/auth",
            "request_token_url": None,
            "client_id": "123456789012-asdfkjhagsdfkjhgasdkfjhgasdfkjhgapps.googleusercontent.com",
            "client_secret": "wooooo",
        },
    }
]

docker-compose.yaml 相关片段

airflow-webserver:
    <<: *airflow-common
    # ... rest is unchanged ... 
    volumes:
      - ${AIRFLOW_PROJ_DIR:-./data/airflow}/dags:/opt/airflow/dags
      - ${AIRFLOW_PROJ_DIR:-./data/airflow}/logs:/opt/airflow/logs
      - ${AIRFLOW_PROJ_DIR:-./data/airflow}/plugins:/opt/airflow/plugins
      - ./webserver_config.py:/opt/airflow/webserver_config.py

问题排查与解决步骤

1. 启用用户自动注册(或提前创建对应用户)

你的配置中AUTH_USER_REGISTRATION = False,意味着只有Airflow中已存在的用户才能通过OAuth登录。如果你的Google账号邮箱未在Airflow中创建过用户,就会触发登录失败。

临时测试可先开启自动注册:

AUTH_USER_REGISTRATION = True
AUTH_USER_REGISTRATION_ROLE = "Admin"  # 或其他你需要的角色

生产环境建议关闭自动注册,提前在Airflow中创建好对应邮箱的用户。

2. 配置自定义安全管理器(处理Google用户信息映射)

Airflow依赖Flask-AppBuilder(FAB)处理OAuth,默认可能无法正确解析Google返回的用户信息,需自定义安全管理器指定字段映射:

  1. 在Airflow的plugins目录下创建security_manager.py:
from flask_appbuilder.security.manager import OAuthManager
from flask_appbuilder.security.sqla.manager import SecurityManager

class GoogleSecurityManager(SecurityManager, OAuthManager):
    def oauth_user_info(self, provider, response):
        if provider == "google":
            res = self.appbuilder.sm.oauth_remotes[provider].get("userinfo")
            return {
                "username": res.data["email"],
                "email": res.data["email"],
                "first_name": res.data["given_name"],
                "last_name": res.data["family_name"]
            }
        return {}
  1. 在webserver_config.py中添加配置:
FAB_SECURITY_MANAGER_CLASS = "security_manager.GoogleSecurityManager"

3. 调整OAuth端点配置

使用Google OpenID Connect标准端点,优化remote_app配置:

"remote_app": {
    "api_base_url": "https://www.googleapis.com/oauth2/v3/",
    "client_kwargs": {
        "scope": "openid email profile",
        "redirect_uri": "http://localhost:8080/oauth-authorized/google"  # 需和Google控制台配置一致
    },
    "access_token_url": "https://oauth2.googleapis.com/token",
    "authorize_url": "https://accounts.google.com/o/oauth2/v2/auth",
    "request_token_url": None,
    "client_id": "你的Client ID",
    "client_secret": "你的Client Secret",
}

添加openid scope可确保获取ID Token,帮助Airflow更好地验证用户身份。

4. 查看Webserver日志定位细节

启动Webserver后查看日志,获取具体错误信息:

docker logs -f airflow-webserver

日志中可能会显示用户信息解析失败、权限不足等问题,进一步定位根源。

内容的提问来源于stack exchange,提问作者flypenguin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 05:40:25