GIT Connection¶
The GIT connection type enables the GIT Integrations.
Authenticating to GIT¶
Authenticate to GIT using GitPython. The hook supports both HTTPS (token-based) and SSH (key-based) authentication.
Default Connection IDs¶
Hooks and bundles related to GIT use git_default by default.
Configuring the Connection¶
- Repository URL
The URL of the git repository, e.g.
git@github.com:apache/airflow.gitfor SSH orhttps://github.com/apache/airflow.gitfor HTTPS. This can also be passed directly to the hook via therepo_urlparameter.A
user:password@embedded in anhttp(s)repository URL is stripped out before use and treated as the username/access token; the explicit fields below take precedence over it when both are present.- Username or Access Token name (optional)
The username for HTTPS authentication or the token name. Defaults to
userif not specified.- Access Token (optional)
The access token for HTTPS authentication. The connection’s username and token are never written into the repository URL or the bundle’s git config; instead they are handed to git through a credential helper scoped to the repository’s host (
credential.<scheme>://<host>[:port].helper). Token authentication over http(s) requires git version 2.31 or higher.- Extra (optional)
Specify the extra parameters as a JSON dictionary. The following keys are supported:
SSH key authentication:
key_file: Path to an SSH private key file to use for authentication.private_key: An inline SSH private key string. When provided, the hook writes it to a temporary file and uses it for the SSH connection. Mutually exclusive withkey_file.private_key_passphrase: Passphrase for the private key (works with bothkey_fileandprivate_key). UsesSSH_ASKPASSto provide the passphrase non-interactively.
SSH connection options:
strict_host_key_checking: Controls SSH strict host key checking. Acceptsyes,no,accept-new,offorask. Defaults toaccept-new, which trusts a server’s host key on first use and then verifies it on every later connection (so a changed key — a possible man-in-the-middle — is rejected). Set toyesto require the host key to be present inknown_hostsup front, ornoto disable verification entirely (not recommended).Warning
A future major release of the Git provider will change this default to
yes. Deployments that rely on the default should configureknown_hosts_file(or setstrict_host_key_checkingexplicitly) now to avoid disruption when that happens.known_hosts_file: Path to a custom SSH known-hosts file. Whenstrict_host_key_checkingisnoand this is not set,/dev/nullis used.ssh_config_file: Path to a custom SSH config file (passed asssh -F).host_proxy_cmd: SSH ProxyCommand string for connecting through a bastion or jump host (e.g.ssh -W %h:%p bastion.example.com).ssh_port: Non-default SSH port number.
Example with key file:
{ "key_file": "/path/to/id_rsa", "strict_host_key_checking": "accept-new" }
Example with inline private key and passphrase:
{ "private_key": "<content of your PEM-encoded private key>", "private_key_passphrase": "my-passphrase" }
Example with bastion host and custom port:
{ "key_file": "/path/to/id_rsa", "host_proxy_cmd": "ssh -W %h:%p bastion.example.com", "ssh_port": "2222", "strict_host_key_checking": "yes", "known_hosts_file": "/path/to/known_hosts" }
GitHub App authentication:
In order to use GitHub App authentication the
githubextra needs to be installed:pip install 'apache-airflow-providers-git[github]'
github_app_id: The App ID of your GitHub App. Note that the GitHub App Client ID can also be used.github_installation_id: The installation ID of your GitHub app.key_file: Path to a PEM-encoded private key file for your GitHub App.private_key: An inline PEM-encoded private key string. When provided, the hook writes it to a temporary file and uses it for the GitHub App connection. Mutually exclusive withkey_file.
Example with key file:
{ "github_app_id": "1234567", "github_installation_id": "67890", "key_file": "/path/to/private-key.pem" }
Example with inline private key:
{ "github_app_id": "1234567", "github_installation_id": "67890", "private_key": "<content of your PEM-encoded private key>" }