Repository navigation
Replace sshtunnel with native paramiko/asyncssh tunneling - #64299
Merged
Merged
Conversation
2 of 3 tasks
Dev-iL
marked this pull request as ready for review
March 28, 2026 05:56
Dev-iL
requested review from
ashb,
gopidesupavan,
jason810496 and
potiuk
as code owners
March 28, 2026 05:56
Dev-iL
force-pushed
the
2603/ssh
branch
2 times, most recently
from
March 29, 2026 14:36
d363413 to
f3fa038
Compare
potiuk
approved these changes
Apr 4, 2026
Member
|
Nice! |
1 task done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes: #64258
Summary
sshtunneldependency (broken on Python 3.14) from the SSH providerSSHTunnel) and asyncssh-based async tunneling (AsyncSSHTunnel)SSHHookAsync.get_tunnel()as a new async tunnel capabilitySSHTunnelForwarderusersMotivation
The
sshtunnelpackage has not been updated since 2021 and uses syntax that causes an import-timeSyntaxErroron Python 3.14. Sincesshtunnelis fundamentally a thin wrapper around paramiko'sTransport.open_channel('direct-tcpip', ...), we can replace it with a direct paramiko implementation that:SSHHook.get_conn()for tunnel connections, inheriting all auth/proxy configurationDesign Decisions
Reuse
get_conn()instead of creating a separate SSH connectionBefore:
SSHTunnelForwarderestablished its own SSH connection with separately assembled credentials (ssh_username,ssh_password,ssh_pkey,ssh_proxy, etc.), duplicating the logic inget_conn().After:
SSHTunnelreceives an already-connectedparamiko.SSHClientfromget_conn(). This means all authentication methods (password, key file, private key, ECDSA, proxy commands, host key verification) are automatically inherited without duplication.Trade-off: The tunnel now shares the SSH connection with other operations. This is acceptable because SSH multiplexes channels over a single transport, and this is how
ssh -Lworks natively.Select-loop in a daemon thread (not thread-per-connection)
The sync
SSHTunneluses a single daemon thread running aselect()loop that multiplexes all forwarded connections. This avoids spawning a thread per connection (whichsshtunneldid internally) and keeps resource usage predictable.A socket-pair (
socketpair()) is used as a self-pipe to wake theselect()loop cleanly on shutdown, avoiding the need for polling timeouts or signal-based approaches.Minimal backward compatibility shim
Rather than fully reimplementing
SSHTunnelForwarder's API surface, we provide:__enter__/__exit__) - the recommended interface.start()/.stop()- deprecated, emitAirflowProviderDeprecationWarning.local_bind_portand.local_bind_address- preserved as properties__getattr__- raisesAttributeErrorwith migration hint forSSHTunnelForwarder-specific attributes (e.g.,tunnel_is_up,ssh_host)This covers the known usage patterns without maintaining dead code. No external providers or common user code accesses
SSHTunnelForwarder-specific attributes beyond context manager +local_bind_port.AsyncSSHTunnel as a thin asyncssh wrapper
asyncsshalready providesforward_local_port()which handles all the forwarding internally.AsyncSSHTunnelis a thin wrapper that:__aexit__).local_bind_portvialistener.get_port()__aenter__failure (closes SSH connection ifforward_local_portraises)async with await hook.get_tunnel(...)patternEager socket binding in constructor
SSHTunnel.__init__binds the local socket immediately (before__enter__), so.local_bind_portis available right after construction. This matchesSSHTunnelForwarder's behavior where the port was known before calling.start(). The socket is cleaned up properly even if construction fails (try/except on bind/listen).Changes
New files
providers/ssh/src/airflow/providers/ssh/tunnel.py-SSHTunnel(sync, paramiko) andAsyncSSHTunnel(async, asyncssh) classes with full docstrings and migration guidanceModified files
providers/ssh/src/airflow/providers/ssh/hooks/ssh.pySSHHook.get_tunnel()now returnsSSHTunnelviaget_conn()from sshtunnel import SSHTunnelForwarderSSHHookAsync.get_tunnel()returningAsyncSSHTunnelproviders/ssh/pyproject.toml- Removedsshtunnel>=0.3.2dependencyproviders/ssh/tests/unit/ssh/hooks/test_ssh.pyparamiko.SSHClient+SSHTunnelinstead ofSSHTunnelForwarderTestSSHTunnelclass with 7 tests: deprecation warnings,__getattr__migration hints, ephemeral/explicit port binding, context manager lifecycleproviders/ssh/tests/unit/ssh/hooks/test_ssh_async.pydocker-tests/tests/docker_tests/test_prod_image.py- Removedsshtunnelfrom expected package importsdevel-common/src/docs/utils/conf_constants.py- Removedsshtunnelfrom third-party autodoc allowlistdocs/spelling_wordlist.txt- Replacedsshtunnel/SSHTunnelForwarderwithSSHTunnelWas generative AI tooling used to co-author this PR?
Generated-by: Claude Opus 4.6 following the guidelines
{pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.