apache / apache/airflow

Gitsync fails to read new credentials when using ESO Github token generator

Open
#63,253 2 comments 0 reactions 0 assignees View on GitHub
area:providers kind:feature needs-triage provider:git
Dominant language
Python
Stars
46.9k
Forks
17.8k
Avg merge
2d 9h
Merged PRs (30d)
472

Description

### Description

We use Github for our git repos.

To provide access from airflow we use External Secrets Operator to manage this using GithubAccessToken that uses a github app to create the access token.
This token only lives for 1 hour maximum.
Because of this lifespan, The gitsync container needs to re-read the secret to have the new token.
Unfortunately it seems that gitsync doesn't support re-reading the secret while it's running.

This causes it to fail the sync, exit and restarts.
Thankfully it will restart fine and syncs again.

### Use case/motivation

Gitsync project have released a new feature https://github.com/kubernetes/git-sync/pull/976 that allows for reading a file that contains the password and re-read it at each sync loop

Env vars are only set at startup time so won't detect a change, therefor the secret will have to be mounted inside the container which I think should allow for accepting token rotations?

### Related issues

_No response_

### Are you willing to submit a PR?

- [ ] Yes I am willing to submit a PR!

### Code of Conduct

- [x] I agree to follow this project's [Code of Conduct](https://github.com/apache/airflow/blob/main/CODE_OF_CONDUCT.md)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.