xvega commented on code in PR #73399:
URL: https://github.com/apache/airflow/pull/73399#discussion_r4168918970


##########
providers/cncf/kubernetes/src/airflow/providers/cncf/kubernetes/hooks/kubernetes.py:
##########
@@ -1059,14 +1060,28 @@ async def _get_field(self, field_name):
 
     @contextlib.asynccontextmanager
     async def get_conn(self) -> AsyncGenerator[async_client.ApiClient, None]:
-        kube_client = None
+        await self._load_config()
+        if self._config_loaded:
+            # Reuse one client per hook: each construction runs 
ssl.create_default_context()
+            # on the event loop and opens a new connection pool. Owners 
release it via
+            # close(); triggers do so in cleanup().
+            if self._cached_kube_client is None:
+                self._cached_kube_client = 
_TimeoutAsyncK8sApiClient(configuration=self.client_configuration)
+            yield self._cached_kube_client
+            return
+        # Exec-based auth rotates short-lived tokens by reloading the config on

Review Comment:
   Addressed. The config is now reloaded on every call, so the cached client 
always sends the current token only the SSL context and connection pool are 
reused. Added regression tests for rotated kubeconfig tokens and an expired gcp 
auth-provider token.
   
   Note this is fresher than main: since #65212 the config is loaded once per 
hook, so a static token is already frozen for the trigger's lifetime today. The 
only thing still cached is TLS cert material, same limitation as discussed in 
[apache/airflow#71349](https://github.com/apache/airflow/pull/71349).
   
   Also renamed `_config_loaded` to `_client_cacheable`: the config isn't 
cached anymore, the flag now only marks whether the client can be reused.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to