如何在Airflow Connections中添加MinIO连接?测试报错求排查
问题背景
尝试通过Airflow GUI配置运行中的MinIO实例连接(环境已隔离,暂不考虑凭证暴露),Airflow与MinIO均在同一Docker网络中,测试连接时出现错误:
'ClientError' error occurred while testing connection: An error occurred (InvalidClientTokenId) when calling the GetCallerIdentity operation: The security token included in the request is invalid.
配置界面说明:选择Amazon S3类型连接,填写了Host、Login(MinIO Access Key)、Password(MinIO Secret Key)等基础字段。
遗漏的关键配置项
强制指定MinIO端点及禁用STS校验
Airflow默认会尝试用AWS STS服务校验身份,但MinIO默认不支持该服务,且必须指定专属端点。需在连接的Extra字段中补充完整配置(覆盖基础字段的优先级更高):{ "aws_access_key_id": "你的MinIO Access Key", "aws_secret_access_key": "你的MinIO Secret Key", "endpoint_url": "http://minio容器名称:9000", "region_name": "us-east-1", "verify": false, "use_ssl": false }注意:
endpoint_url必须使用Docker网络内的MinIO容器名(或容器IP)+端口,不能用localhost,否则Airflow容器会指向自身而非MinIO实例。检查MinIO权限策略
确保所用的MinIO Access Key拥有sts:GetCallerIdentity权限,可临时给该账号分配管理员权限测试,或添加自定义策略:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["sts:GetCallerIdentity"], "Resource": ["*"] } ] }确认连接类型与字段对应
连接类型必须选择Amazon S3(MinIO兼容S3协议),Login字段对应MinIO的Access Key,Password对应Secret Key,但Extra中的配置会覆盖这两个字段,建议直接在Extra中完整配置避免冲突。
后续实现Data-Aware Scheduling
连接测试通过后,可使用Airflow的S3KeySensor监听MinIO存储桶的文件上传事件,触发DAG运行:
from airflow import DAG from airflow.providers.amazon.aws.sensors.s3_key import S3KeySensor from datetime import datetime with DAG( dag_id='minio_file_trigger_dag', start_date=datetime(2024, 1, 1), schedule_interval=None, catchup=False ) as dag: watch_new_file = S3KeySensor( task_id='watch_minio_bucket', bucket_name='你的存储桶名称', bucket_key='待监听路径/*', # 支持通配符匹配文件 aws_conn_id='你的MinIO连接ID', poke_interval=30, # 每30秒检查一次 timeout=3600 # 超时时间1小时 ) # 后续任务逻辑...
内容的提问来源于stack exchange,提问作者Roland Deschain

