GitHub user keemgdeok added a comment to the discussion: FAB multi-team migration
For an existing FAB/SSO deployment, I'd evaluate the new auth model in staging before committing to a migration. The [Airflow 3.3.2 multi-team docs](https://airflow.apache.org/docs/apache-airflow/3.3.2/core-concepts/multi-team.html#auth-manager) list Simple Auth Manager for development and Keycloak as compatible options. Multi-Team itself is still in preview, and the [Keycloak auth manager](https://airflow.apache.org/docs/apache-airflow-providers-keycloak/stable/auth-manager/index.html) is also marked experimental. The user model is the main migration work: FAB stores its users and authorization entities in Airflow's database; Keycloak manages users, roles, groups and permissions externally. Its [team permission model](https://airflow.apache.org/docs/apache-airflow-providers-keycloak/stable/auth-manager/manage/permissions.html#managing-teams-with-keycloak) combines team-group membership with role membership. I'd explicitly map the existing SSO identities and FAB permissions to that model, then test two teams through both the UI and public API, including access that must be denied. Changing `auth_manager` alone shouldn't be treated as that mapping. Lack of multi-team compatibility doesn't by itself establish that FAB is being removed: the [current FAB provider docs](https://airflow.apache.org/docs/apache-airflow-providers-fab/stable/auth-manager/index.html) still document its SSO setup. A long-term FAB support or removal timeline still needs clarification from the maintainers. GitHub link: https://github.com/apache/airflow/discussions/71242#discussioncomment-18737281 ---- This is an automatically sent email for [email protected]. To unsubscribe, please send an email to: [email protected]
