Akeyless Secrets Backend¶
Use Akeyless as the secrets backend for Apache Airflow to source Connections, Variables, and Configuration options directly from the Akeyless Vault Platform.
Configuration¶
Add to airflow.cfg:
[secrets]
backend = airflow.providers.akeyless.secrets.akeyless.AkeylessBackend
backend_kwargs = {
"connections_path": "/airflow/connections",
"variables_path": "/airflow/variables",
"config_path": "/airflow/config",
"api_url": "https://api.akeyless.io",
"access_id": "p-xxxxxxxxx",
"access_key": "your-access-key",
"access_type": "api_key"
}
Or via environment variable:
export AIRFLOW__SECRETS__BACKEND="airflow.providers.akeyless.secrets.akeyless.AkeylessBackend"
export AIRFLOW__SECRETS__BACKEND_KWARGS='{"connections_path": "/airflow/connections", ...}'
Secret Naming Convention¶
Secrets are resolved by joining <base_path>/<key>:
Type |
Example lookup path |
|---|---|
Connection |
|
Variable |
|
Config |
|
Storing Connections¶
Connections can be stored in three formats:
URI string:
postgresql://user:password@host:5432/dbname
JSON dict with ``conn_uri``:
{"conn_uri": "postgresql://user:password@host:5432/dbname"}
JSON dict with individual fields:
{
"conn_type": "postgres",
"host": "db.example.com",
"login": "admin",
"password": "secret",
"schema": "mydb",
"port": 5432
}
Authentication Methods¶
The secrets backend supports the following authentication types:
|
Description |
|---|---|
|
Authenticate with Access ID + Access Key. The default method. |
|
Use a pre-existing Universal Identity token. |
|
Authenticate using the host’s AWS IAM role. Ideal for Amazon MWAA, EC2, ECS, and EKS workloads. No static credentials required. |
|
Authenticate using GCP workload identity. Ideal for Google Managed Service for Apache Airflow (formerly Cloud Composer) and GCE/GKE workloads. |
|
Authenticate using Azure AD identity. Ideal for Azure-hosted workloads. |
Cloud-based auth types (aws_iam, gcp, azure_ad) require the
optional akeyless_cloud_id package:
pip install apache-airflow-providers-akeyless[cloud_id]
Using with Amazon MWAA¶
On Amazon MWAA you can leverage the environment’s IAM execution role to authenticate with Akeyless – no static API keys needed.
Add to your
requirements.txt(uploaded to S3):apache-airflow-providers-akeyless[cloud_id]
In the MWAA console, add these Airflow configuration options:
secrets.backendairflow.providers.akeyless.secrets.akeyless.AkeylessBackendsecrets.backend_kwargs{"api_url": "https://api.akeyless.io", "access_id": "p-xxxxxxxxx", "access_type": "aws_iam"}Ensure the MWAA VPC has outbound HTTPS access to your Akeyless API endpoint (
api.akeyless.ioor your Akeyless Gateway).Create an Akeyless
aws_iamAuth Method associated with the MWAA execution role ARN.
Using with Google Managed Service for Apache Airflow¶
[secrets]
backend = airflow.providers.akeyless.secrets.akeyless.AkeylessBackend
backend_kwargs = {
"api_url": "https://api.akeyless.io",
"access_id": "p-xxxxxxxxx",
"access_type": "gcp",
"gcp_audience": "akeyless.io"
}
Parameters¶
Parameter |
Default |
Description |
|---|---|---|
|
|
Akeyless folder path for connections. Set to None to disable. |
|
|
Akeyless folder path for variables. Set to None to disable. |
|
|
Akeyless folder path for configuration. Set to None to disable. |
|
|
Separator between base path and key name. |
|
|
Akeyless API endpoint. |
|
Akeyless Access ID. |
|
|
Akeyless Access Key (for |
|
|
|
Authentication method ( |
|
GCP audience string (only for |
|
|
Azure AD Object ID (only for |
|
|
|
Seconds to cache the API token before re-authenticating. |