Kubernetes中Apache Airflow Helm Chart无法连接私有GitHub仓库求助
Hey there! Let's work through why your gitSync setup isn't connecting to your private GitHub repo. I've run into similar headaches when setting up Airflow on K8s, so here are the key checks to run:
1. Verify Secret Reference in values.yaml
First, make sure you've actually linked your git-credentials secret in your Airflow Helm values. You need to add this line under the gitSync section—this is easy to miss but critical:
gitSync: enabled: true secretName: git-credentials # Don't skip this! # ... your existing gitSync configs
Without this line, Airflow won't know to pull credentials from your secret, so it'll try accessing the repo anonymously.
2. Validate Base64 Encoding
Double-check that your encoded credentials are correct—extra newlines or spaces during encoding are a common culprit. Run these commands to decode and confirm:
# Decode username echo "bXluYW1l" | base64 --decode # Decode password/token echo "bXl0b2tlbg==" | base64 --decode
Ensure the output matches your actual GitHub username and access credentials. Important: If you have 2FA enabled on your GitHub account, your regular password won't work—you must use a Personal Access Token (PAT) with the repo scope instead.
3. Check GitHub Repo Permissions
Confirm your credentials have read access to the private repo:
- If using a PAT, verify it was created with the
reposcope (under the "repo" category in PAT settings). - If using a password, ensure 2FA is disabled (or switch to a PAT, since GitHub discourages password use with 2FA).
4. Inspect Environment Variables in Airflow Pods
Check if the GIT_SYNC credentials are being injected into your Airflow pods correctly. Exec into a worker or webserver pod and run:
kubectl exec -it <your-airflow-pod-name> -- env | grep GIT_SYNC
You should see both GIT_SYNC_USERNAME and GIT_SYNC_PASSWORD listed with their correct decoded values. If they're missing, double-check that your secret's namespace (default in your config) matches the namespace where Airflow is deployed.
5. Check gitSync Sidecar Logs
The most direct way to find the root cause is to look at the gitSync sidecar container logs. Run this command to fetch them:
kubectl logs <your-airflow-pod-name> -c git-sync
Look for error messages like:
authentication failed: Credentials are incorrect or lack repo access.repository not found: Repo URL is wrong, or credentials don't have permission to view it.fatal: unable to access 'https://github.com/...': Network issues or invalid URL formatting.
6. Confirm Repo URL Accuracy
Double-check your repo URL in the gitSync config—small typos break everything! Ensure it's exactly the HTTPS URL of your private repo (including the .git suffix), and that the case matches (GitHub repo names are case-sensitive).
内容的提问来源于stack exchange,提问作者J.C Guzman

