Airflow Summit 2026 is coming August 31 - September 2 in Austin, TX. Register now to secure your spot!

apache-airflow-providers-ssh

Changelog

Breaking changes

  • Bump minimum paramiko to 4.0.0; DSA/DSS private keys and ssh-dss host keys are no longer supported (#54079)

    Paramiko 4.0 removed DSS/DSA support; see paramiko changelog for upstream details. If you use a DSA private key in an SSH connection, generate a new key (for example ssh-keygen -t ed25519 or -t rsa), install the public key on the server, and point your Airflow connection at the new key file or private_key extra. If you pin the remote host with a host_key extra in ssh-dss form, obtain the server’s current RSA, ECDSA, or Ed25519 host key and replace the value. The same constraints apply to SFTP connections that rely on paramiko via the SSH provider.

5.0.4

Bug Fixes

  • Fix 'SSHRemoteJobOperator' orphaning the remote job on cancellation (#68644)

5.0.3

Bug Fixes

  • Reduce SSH connection churn in 'SSHRemoteJobOperator' under high fan-out (#68115)

5.0.2

Misc

  • Use contextlib.suppress instead of try-except-pass in providers (#66178)

5.0.1

Misc

  • Bump paramiko lower bound to >=3.5.1 due to adding Vespa provider (#63988)

5.0.0

Breaking changes

  • Replace 'sshtunnel' with native paramiko/asyncssh tunneling (#64299)

With this change we provide minimal backward compatibility shim, Rather than fully re-implementing SSHTunnelForwarder’s API surface. While most of the usages of the get_tunnel() method in the codebase should work without modifications - some of the more advanced use cases might require code changes, user need to inspect changes between the old SSHTunnelForwarder and SSHTunnel class if they used advanced featured of the forwarder.

The details and suggestion of the code changes are explained by the deprecation/ errors when the properties are used.

The SSHTunnel provides:

  • Context manager (enter/exit) - the recommended interface

  • .start()/.stop() - deprecated, emit AirflowProviderDeprecationWarning

  • .local_bind_port and .local_bind_address - preserved as properties

  • getattr - raises AttributeError with migration hint for

  • SSHTunnelForwarder-specific attributes (e.g., tunnel_is_up, ssh_host)

AsyncSSHTunnel is a thin wrapper that:

  • Manages the lifecycle (listener + SSH connection cleanup in aexit)

  • Exposes .local_bind_port via listener.get_port()

  • Handles cleanup on aenter failure (closes SSH connection if forward_local_port raises)

  • Follows the async with await hook.get_tunnel(…) pattern

  • Eager socket binding in constructor

Bug Fixes

  • Fix SSHHookAsync defaulting no_host_key_check to False unlike SSHHook (#64225)

Misc

  • Load hook metadata from YAML without importing Hook class (#63826)

4.3.3

Misc

  • Add Python 3.14 Support (#63520)

4.3.2

Misc

  • Bump minimum cryptography to 44.0.3 and paramiko to 3.4.0 (#62723)

4.3.1

Misc

  • Use common provider's get_async_connection in other providers (#56791)

4.3.0

Features

  • Add ''SSHRemoteJobOperator'' for resilient remote job execution (#60297)

Misc

  • New year means updated Copyright notices (#60344)

  • Migrate ssh provider to use airflow.sdk.configuration.conf (#59981)

4.2.1

Misc

  • Add backcompat for exceptions in providers (#58727)

4.2.0

Note

This release of provider is only available for Airflow 2.11+ as explained in the Apache Airflow providers support policy <https://github.com/apache/airflow/blob/main/PROVIDERS.rst#minimum-supported-version-of-airflow-for-community-managed-providers>_.

Misc

  • Move out some exceptions to TaskSDK (#54505)

  • Bump minimum Airflow version in providers to Airflow 2.11.0 (#58612)

  • Remove SDK reference for NOTSET in Airflow Core (#58258)

  • Fix lower bound dependency to common-compat provider (#58833)

4.1.6

Misc

  • Convert all airflow distributions to be compliant with ASF requirements (#58138)

Doc-only

  • [Doc] Fixing some typos and spelling errors (#57225)

  • Fixing some typos and spelling errors (#57186)

4.1.5

Bug Fixes

  • Pass required remote_host arg to SSHHook (#55664)

Misc

  • Migrate ssh provider to ''common.compat'' (#57004)

Doc-only

  • Remove placeholder Release Date in changelog and index files (#56056)

4.1.4

Misc

  • Switch all airflow logging to structlog (#52651)

4.1.3

Misc

  • Limit paramiko to '< 4.0.0' till we remove DSS support (#54078)

4.1.2

Misc

  • Add Python 3.13 support for Airflow. (#46891)

  • Remove type ignore across codebase after mypy upgrade (#53243)

  • Cleanup type ignores in ssh provider where possible (#53257)

  • Remove upper-binding for "python-requires" (#52980)

  • Temporarily switch to use >=,< pattern instead of '~=' (#52967)

  • Move all BaseHook usages in providers to version_compat in ssh (#52780)

4.1.1

Misc

  • Move 'BaseHook' implementation to task SDK (#51873)

  • Provider Migration: Replace 'BaseOperator' to Task SDK for 'ssh' (#52558)

  • Drop support for Python 3.9 (#52072)

4.1.0

Note

This release of provider is only available for Airflow 2.10+ as explained in the Apache Airflow providers support policy <https://github.com/apache/airflow/blob/main/PROVIDERS.rst#minimum-supported-version-of-airflow-for-community-managed-providers>_.

Misc

  • Bump min Airflow version in providers to 2.10 (#49843)

4.0.1

Bug Fixes

  • Make command for replacing newlines with literals '\n' in 'SSHOperator'connection MacOs/Linux compatible (#47491)

Misc

  • Upgrade flit to 3.11.0 (#46938)

4.0.0

Note

This release of provider is only available for Airflow 2.9+ as explained in the Apache Airflow providers support policy.

Breaking changes

Warning

All deprecated classes, parameters and features have been removed from the SSH provider package. The following breaking changes were introduced:

  • Hooks
    • Remove attribute timeout from airflow.providers.ssh.hooks.ssh.SSHHook. Use parameter conn_timeout instead.

    • The context manager of SSHHook is deprecated. Please use get_conn() as a context manager instead.

    • SSHHook.create_tunnel() is deprecated, Please use get_tunnel() instead. But please note that the order of the parameters have changed.

  • operators
    • The deprecated get_hook() method is removed in airflow.providers.ssh.operators.ssh.SSHOperator. Please use hook attribute instead.

    • Deprecated exec_ssh_client_command() method on SSHOperator is removed, call ssh_hook.exec_ssh_client_command() instead

  • Remove Provider Deprecations in SSH (#44544)

Features

  • Add host_proxy_cmd parameter to SSHHook and SFTPHook (#44565)

Misc

  • Bump minimum Airflow version in providers to Airflow 2.9.0 (#44956)

  • Remove XCom pickling (#43905)

3.14.0

Features

  • SSHHook expose auth_timeout parameter (#43048)

3.13.1

Bug Fixes

  • SSHHook: check if existing connection is still alive (#41061)

3.13.0

Note

This release of provider is only available for Airflow 2.8+ as explained in the Apache Airflow providers support policy.

Misc

  • Bump minimum Airflow version in providers to Airflow 2.8.0 (#41396)

3.12.0

Features

  • Add on kill to ssh (#40377)

3.11.2

Misc

  • implement per-provider tests with lowest-direct dependency resolution (#39946)

3.11.1

Misc

  • Faster 'airflow_version' imports (#39552)

  • Simplify 'airflow_version' imports (#39497)

3.11.0

Note

This release of provider is only available for Airflow 2.7+ as explained in the Apache Airflow providers support policy.

Misc

  • Bump minimum Airflow version in providers to Airflow 2.7.0 (#39240)

3.10.1

Misc

  • feat: Switch all class, functions, methods deprecations to decorators (#36876)

3.10.0

Features

  • Add skip_on_exit_code to SSHOperator (#36303)

Bug Fixes

  • Allow SSHOperator.skip_on_exit_code to be zero (#36358)

  • Follow BaseHook connection fields method signature in child classes (#36086)

Misc

  • Review and mark found potential SSH security issues by bandit (#36162)

3.9.0

Note

This release of provider is only available for Airflow 2.6+ as explained in the Apache Airflow providers support policy.

Misc

  • Bump minimum Airflow version in providers to Airflow 2.6.0 (#36017)

3.8.1

Misc

  • Consolidate stacklevel in ssh operator warning (#35151)

3.8.0

Note

This release of provider is only available for Airflow 2.5+ as explained in the Apache Airflow providers support policy.

Misc

  • Bump min airflow version of providers (#34728)

  • add warn stacklevel=2 to ssh hook (#34527)

3.7.3

Misc

  • Use literal dict instead of calling dict() in providers (#33761)

  • E731: replace lambda by a def method in Airflow providers (#33757)

3.7.2

Misc

  • Use str.splitlines() to split lines in providers (#33593)

  • Simplify conditions on len() in other providers (#33569)

3.7.1

Note

This release dropped support for Python 3.7

Misc

  • Remove Python 3.7 support (#30963)

3.7.0

Note

This release of provider is only available for Airflow 2.4+ as explained in the Apache Airflow providers support policy.

Misc

  • Bump minimum Airflow version in providers (#30917)

3.6.0

Features

  • SSHOperator - Restore ability to override SSHHook cmd_timeout (#30190)

3.5.0

Features

  • SSH Provider: Add cmd_timeout to ssh connection extra (#29347)

3.4.0

Features

  • Add .bash and other extensions to SSHOperator template_ext (#28617)

  • Add test_connection method for SSHHook (#28184)

  • SSH task exit code added to XCOM as 'ssh_exit' key (#27370)

Misc

  • Remove outdated compat imports/code from providers (#28507)

  • [misc] Get rid of 'pass' statement in conditions (#27775)

3.3.0

Note

This release of provider is only available for Airflow 2.3+ as explained in the Apache Airflow providers support policy.

Misc

  • Move min airflow version to 2.3.0 for all providers (#27196)

Features

  • Added docs regarding templated field (#27301)

  • Added environment to templated SSHOperator fields (#26824)

  • Apply log formatter on every output line in SSHOperator (#27442)

Bug Fixes

  • A few docs fixups (#26788)

  • SSHOperator ignores cmd_timeout (#27182) (#27184)

3.2.0

Features

  • feat: load host keys to save new host key (#25979)

3.1.0

Features

  • Less verbose logging in ssh operator (#24915)

  • Convert sftp hook to use paramiko instead of pysftp (#24512)

Bug Fixes

  • Update providers to use functools compat for ''cached_property'' (#24582)

3.0.0

Breaking changes

Note

This release of provider is only available for Airflow 2.2+ as explained in the Apache Airflow providers support policy.

Features

  • Add disabled_algorithms as an extra parameter for SSH connections (#24090)

Bug Fixes

  • fixing SSHHook bug when using allow_host_key_change param (#24116)

2.4.4

Bug Fixes

  • Add exception to catch single line private keys (#23043)

2.4.3

Bug Fixes

  • Fix mistakenly added install_requires for all providers (#22382)

2.4.2

Misc

  • Add Trove classifiers in PyPI (Framework :: Apache Airflow :: Provider)

2.4.1

Misc

  • Support for Python 3.10

2.4.0

Features

  • Add a retry with wait interval for SSH operator (#14489)

  • Add banner_timeout feature to SSH Hook/Operator (#21262)

  • Add a retry with wait interval for SSH operator #14489 (#19981)

  • Delay the creation of ssh proxy until get_conn() (#20474) (#20474)

2.3.0

Features

  • Refactor SSHOperator so a subclass can run many commands (#10874) (#17378)

  • update minimum version of sshtunnel to 0.3.2 (#18684)

  • Correctly handle get_pty attribute if command passed as XComArg or template (#19323)

2.2.0

Features

  • [Airflow 16364] Add conn_timeout and cmd_timeout params to SSHOperator; add conn_timeout param to SSHHook (#17236)

2.1.1

Misc

  • Optimise connection importing for Airflow 2.2.0

2.1.0

Features

  • Add support for non-RSA type key for SFTP hook (#16314)

Bug Fixes

  • SSHHook: Using correct hostname for host_key when using non-default ssh port (#15964)

  • Correctly load openssh-gerenated private keys in SSHHook (#16756)

2.0.0

Breaking changes

  • Auto-apply apply_default decorator (#15667)

Warning

Due to apply_default decorator removal, this version of the provider requires Airflow 2.1.0+. If your Airflow version is < 2.1.0, and you want to install this provider version, first upgrade Airflow to at least version 2.1.0. Otherwise your Airflow package version will be upgraded automatically and you will have to manually run airflow upgrade db to complete the migration.

Bug Fixes

  • Display explicit error in case UID has no actual username (#15212)

1.3.0

Features

  • A bunch of template_fields_renderers additions (#15130)

1.2.0

Features

  • Added support for DSS, ECDSA, and Ed25519 private keys in SSHHook (#12467)

1.1.0

Updated documentation and readme files.

Features

  • [AIRFLOW-7044] Host key can be specified via SSH connection extras. (#12944)

1.0.0

Initial version of the provider.

Was this entry helpful?