Repository navigation
MySql SSL Mode #24675
Description
Activity
Thanks for opening your first issue here! Be sure to follow the issue template!
- addedkind:featureFeature RequestsFeature Requestsand removedkind:bugThis is a clearly a bugThis is a clearly a bug
on Jun 27, 2022 Feel free to propose PR
assigned
Reacted by Aditya Malikfixed in #27717
Hello!
I'm deploying Apache Airflow using the Helm chart (version 2.10.5).
and I'm using Azure MySQL as an external MetaDB and have the following configuration in my values.yaml file:data:
metadataConnection:
user: XXXX
pass: XXXX
protocol: mysql
host: XXXX
port: 3306
db: airflow
sslmode: requireSo far, everything works fine, and the sslmode: require setting is applied without issues.
However, when Azure MySQL's require_secure_transport is set to ON, I encounter the following error:Error: sqlalchemy.exc.OperationalError: (MySQLdb.OperationalError) (3159, 'Connections using insecure transport are prohibited while --require_secure_transport=ON.')
If require_secure_transport is set to OFF, the connection works normally. But I need to connect when require_secure_transport is ON.
Question: Is there a way to successfully connect Apache Airflow to Azure MySQL when require_secure_transport is ON?
Any help would be greatly appreciated!
Apache Airflow Provider(s)
mysql
Versions of Apache Airflow Providers
any
Apache Airflow version
2.3.2 (latest released)
Operating System
debian
Deployment
Other Docker-based deployment
Deployment details
No response
What happened
If you pass an ssl-mode paramerter in a mysql connection using mysqldb client. That parameter does not get passed through to the mysqldb client.
What you think should happen instead
The parameter should be passed through, so that the client actually connects with the desired SSL mode.
How to reproduce
Add a connection with the extra parameter ssl-mode: "DISABLED". Use MySQLdb client. Connect to a mysql db which has ssl mode disabled. See that the parameter actually is not passed through.
Anything else
Parameter should be passed through here:
https://github.com/apache/airflow/blob/main/airflow/providers/mysql/hooks/mysql.py#L119
mysqldb offers the option:
https://mysqlclient.readthedocs.io/user_guide.html ---> ssl-mode
or
https://dev.mysql.com/doc/dev/connector-python/8.0/tutorials/getting_started.html --> ssl-mode
accepted params are: REQUIRED, DISABLED, VERIFY_CA, VERIFY_IDENTITY
Are you willing to submit PR?
Code of Conduct