GitHub user keemgdeok added a comment to the discussion: FAB multi-team 
migration

For an existing FAB/SSO deployment, I'd evaluate the new auth model in staging 
before committing to a migration. The [Airflow 3.3.2 multi-team 
docs](https://airflow.apache.org/docs/apache-airflow/3.3.2/core-concepts/multi-team.html#auth-manager)
 list Simple Auth Manager for development and Keycloak as compatible options. 
Multi-Team itself is still in preview, and the [Keycloak auth 
manager](https://airflow.apache.org/docs/apache-airflow-providers-keycloak/stable/auth-manager/index.html)
 is also marked experimental.

The user model is the main migration work: FAB stores its users and 
authorization entities in Airflow's database; Keycloak manages users, roles, 
groups and permissions externally. Its [team permission 
model](https://airflow.apache.org/docs/apache-airflow-providers-keycloak/stable/auth-manager/manage/permissions.html#managing-teams-with-keycloak)
 combines team-group membership with role membership. I'd explicitly map the 
existing SSO identities and FAB permissions to that model, then test two teams 
through both the UI and public API, including access that must be denied. 
Changing `auth_manager` alone shouldn't be treated as that mapping.

Lack of multi-team compatibility doesn't by itself establish that FAB is being 
removed: the [current FAB provider 
docs](https://airflow.apache.org/docs/apache-airflow-providers-fab/stable/auth-manager/index.html)
 still document its SSO setup. A long-term FAB support or removal timeline 
still needs clarification from the maintainers.

GitHub link: 
https://github.com/apache/airflow/discussions/71242#discussioncomment-18737281

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]

Reply via email to