kaxil commented on code in PR #73374:
URL: https://github.com/apache/airflow/pull/73374#discussion_r4070529510
##########
providers/common/sql/src/airflow/providers/common/sql/datafusion/engine.py:
##########
@@ -196,6 +196,47 @@ def _fetch_extra_configs(keys: list[str]) -> dict[str,
Any]:
key_path = os.environ.get("GOOGLE_APPLICATION_CREDENTIALS")
credentials = self._remove_none_values({"key_path": key_path,
"keyfile_dict": keyfile_dict})
+ case "wasb":
+ extra_dejson = conn.extra_dejson
+ for unsupported_field in (
+ "connection_string",
+ "managed_identity_client_id",
+ "workload_identity_tenant_id",
+ ):
+ if extra_dejson.get(unsupported_field):
+ raise ValueError(
+ f"Connection field {unsupported_field!r} is not
supported for DataFusion "
+ "Azure Blob Storage access; only
tenant_id+login+password (service "
+ "principal), sas_token,
shared_access_key/account_key/password, or ambient "
+ "credentials (AZURE_* environment variables,
managed identity, workload "
+ "identity, or az login) are used."
+ )
+ credentials = {"account": conn.login}
Review Comment:
`account` comes from `conn.login` in every branch, but WasbHook resolves the
storage account from `conn.host` first and only falls back to `login`
(`parse_blob_account_url(conn.host, conn.login)` in `hooks/wasb.py`). In the
service-principal branch below, `login` is the client_id, so the same GUID goes
out as both `account` and `client_id` and the store targets
`https://<client-id>.blob.core.windows.net`. The other side of it: a connection
that keeps the account in `host` and authenticates with a key or SAS and an
empty `login` ends up with no `account` at all, and the binding silently falls
back to `AZURE_STORAGE_ACCOUNT_NAME`.
Could this take the account from `host` when it is set (the first label of
the netloc, as `parse_blob_account_url` does) and only then fall back to
`login`? `test_get_credentials_azure_with_service_principal` currently pins
`"account": "client-id"`, and the docs section should say where the account
name comes from in that mode.
##########
providers/common/sql/src/airflow/providers/common/sql/datafusion/object_storage_provider.py:
##########
@@ -107,6 +107,37 @@ def get_scheme(self) -> str:
return "gs://"
+class AzureObjectStorageProvider(ObjectStorageProvider):
+ """Azure Object Storage Provider using DataFusion's MicrosoftAzure."""
+
+ @property
+ def get_storage_type(self) -> StorageType:
+ """Return the storage type."""
+ return StorageType.AZURE
+
+ def create_object_store(self, path: str, connection_config:
ConnectionConfig | None = None):
+ """Create an Azure object store using DataFusion's MicrosoftAzure."""
+ if connection_config is None:
+ raise ValueError(f"connection_config must be provided for
{self.get_storage_type}")
Review Comment:
The S3 and GCS providers format this with `.value`. Without it,
`f"{StorageType.AZURE}"` renders as `azure` on 3.10 but as `StorageType.AZURE`
on 3.12 and 3.13, where `__format__` on mixed-in enums changed.
`test_azure_provider_requires_connection_config` matches on `for azure`, so it
passes on the 3.10 job this PR ran but fails on the 3.12/3.13 legs of the full
matrix.
##########
providers/common/sql/src/airflow/providers/common/sql/config.py:
##########
@@ -117,6 +118,8 @@ def _extract_storage_type(self) -> StorageType | None:
return StorageType.S3
if self.uri.startswith("gs://"):
return StorageType.GCS
+ if self.uri.startswith("az://"):
Review Comment:
Is accepting only `az://` deliberate for now? `object_store`'s Azure builder
also parses `abfs://` and `abfss://` (the `"az" | "abfs" | "abfss"` arm in
`src/azure/builder.rs`), and
`abfss://[email protected]/path` is the form most ADLS
docs hand out. If `az://` only is the intended scope, the docs section should
say so, since the failure mode users see is `Unsupported storage type for URI`.
##########
providers/common/sql/src/airflow/providers/common/sql/datafusion/engine.py:
##########
@@ -196,6 +196,47 @@ def _fetch_extra_configs(keys: list[str]) -> dict[str,
Any]:
key_path = os.environ.get("GOOGLE_APPLICATION_CREDENTIALS")
credentials = self._remove_none_values({"key_path": key_path,
"keyfile_dict": keyfile_dict})
+ case "wasb":
+ extra_dejson = conn.extra_dejson
+ for unsupported_field in (
+ "connection_string",
+ "managed_identity_client_id",
+ "workload_identity_tenant_id",
+ ):
+ if extra_dejson.get(unsupported_field):
+ raise ValueError(
+ f"Connection field {unsupported_field!r} is not
supported for DataFusion "
+ "Azure Blob Storage access; only
tenant_id+login+password (service "
+ "principal), sas_token,
shared_access_key/account_key/password, or ambient "
+ "credentials (AZURE_* environment variables,
managed identity, workload "
+ "identity, or az login) are used."
+ )
+ credentials = {"account": conn.login}
+ tenant_id = extra_dejson.get("tenant_id")
+ sas_token = extra_dejson.get("sas_token")
+ if tenant_id and conn.login and conn.password:
+ # client_id/client_secret/tenant_id must all be set
together, or not at all --
+ # DataFusion's binding panics on a partial combination.
+ credentials.update(
+ {"client_id": conn.login, "client_secret":
conn.password, "tenant_id": tenant_id}
+ )
+ elif sas_token:
+ if sas_token.startswith("http"):
+ raise ValueError(
+ "A URL-form `sas_token` is not supported for
DataFusion Azure Blob Storage "
+ "access; provide the SAS token as a query string
instead."
+ )
+ from urllib.parse import parse_qsl
Review Comment:
`urllib.parse` is stdlib, so this can live with the module imports at the
top.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]