GIT Connection

The GIT connection type enables the GIT Integrations.

Authenticating to GIT

Authenticate to GIT using GitPython. The hook supports both HTTPS (token-based) and SSH (key-based) authentication.

Default Connection IDs

Hooks and bundles related to GIT use git_default by default.

Configuring the Connection

Repository URL

The URL of the git repository, e.g. git@github.com:apache/airflow.git for SSH or https://github.com/apache/airflow.git for HTTPS. This can also be passed directly to the hook via the repo_url parameter.

A user:password@ embedded in an http(s) repository URL is stripped out before use and treated as the username/access token; the explicit fields below take precedence over it when both are present.

Username or Access Token name (optional)

The username for HTTPS authentication or the token name. Defaults to user if not specified.

Access Token (optional)

The access token for HTTPS authentication. The connection’s username and token are never written into the repository URL or the bundle’s git config; instead they are handed to git through a credential helper scoped to the repository’s host (credential.<scheme>://<host>[:port].helper). Token authentication over http(s) requires git version 2.31 or higher.

Extra (optional)

Specify the extra parameters as a JSON dictionary. The following keys are supported:

SSH key authentication:

  • key_file: Path to an SSH private key file to use for authentication.

  • private_key: An inline SSH private key string. When provided, the hook writes it to a temporary file and uses it for the SSH connection. Mutually exclusive with key_file.

  • private_key_passphrase: Passphrase for the private key (works with both key_file and private_key). Uses SSH_ASKPASS to provide the passphrase non-interactively.

SSH connection options:

  • strict_host_key_checking: Controls SSH strict host key checking. Accepts yes, no, accept-new, off or ask. Defaults to accept-new, which trusts a server’s host key on first use and then verifies it on every later connection (so a changed key — a possible man-in-the-middle — is rejected). Set to yes to require the host key to be present in known_hosts up front, or no to disable verification entirely (not recommended).

    Warning

    A future major release of the Git provider will change this default to yes. Deployments that rely on the default should configure known_hosts_file (or set strict_host_key_checking explicitly) now to avoid disruption when that happens.

  • known_hosts_file: Path to a custom SSH known-hosts file. When strict_host_key_checking is no and this is not set, /dev/null is used.

  • ssh_config_file: Path to a custom SSH config file (passed as ssh -F).

  • host_proxy_cmd: SSH ProxyCommand string for connecting through a bastion or jump host (e.g. ssh -W %h:%p bastion.example.com).

  • ssh_port: Non-default SSH port number.

Example with key file:

{
    "key_file": "/path/to/id_rsa",
    "strict_host_key_checking": "accept-new"
}

Example with inline private key and passphrase:

{
    "private_key": "<content of your PEM-encoded private key>",
    "private_key_passphrase": "my-passphrase"
}

Example with bastion host and custom port:

{
    "key_file": "/path/to/id_rsa",
    "host_proxy_cmd": "ssh -W %h:%p bastion.example.com",
    "ssh_port": "2222",
    "strict_host_key_checking": "yes",
    "known_hosts_file": "/path/to/known_hosts"
}

GitHub App authentication:

In order to use GitHub App authentication the github extra needs to be installed:

pip install 'apache-airflow-providers-git[github]'
  • github_app_id: The App ID of your GitHub App. Note that the GitHub App Client ID can also be used.

  • github_installation_id: The installation ID of your GitHub app.

  • key_file: Path to a PEM-encoded private key file for your GitHub App.

  • private_key: An inline PEM-encoded private key string. When provided, the hook writes it to a temporary file and uses it for the GitHub App connection. Mutually exclusive with key_file.

Example with key file:

{
    "github_app_id": "1234567",
    "github_installation_id": "67890",
    "key_file": "/path/to/private-key.pem"
}

Example with inline private key:

{
    "github_app_id": "1234567",
    "github_installation_id": "67890",
    "private_key": "<content of your PEM-encoded private key>"
}

Was this entry helpful?