
Apache Airflow
Protect access to Apache Airflow workflows and administration as an upstream web application.
Overview
Apache Airflow is an open-source platform for developing, scheduling, and monitoring batch workflows. Its web server exposes the administration interface and APIs. Current deployments can also use WebSocket connections for live features.
Apache Airflow can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Apache Airflow. Apache Airflow remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Enable the Airflow proxy-header settings and preserve WebSocket upgrades. Do not overwrite Airflow cookie security or application authorization settings.
Example
A private Airflow web server runs in a Kubernetes cluster. Pomerium protects its HTTPS route for the data engineering group. Airflow keeps its own roles and permissions for DAG changes, connections, and administration.
Considerations
- Trust forwarded headers only from the Pomerium route and configure Airflow proxy behavior for the public origin.
- Airflow 3 API access uses its own JWT model. API automation cannot depend on an interactive browser redirect.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
Sources and official resources
- Apache AirflowOfficial website
- Run Airflow behind a proxyOfficial documentation
- Airflow API securityPrimary source
- Apache Airflow source repositoryOfficial repository
- Pomerium HTTP and WebSocket routingPomerium documentation
- Pomerium route timeoutsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
