Document that connection secrets without conn_type remain supported#69780
Merged
henry3260 merged 3 commits intoJul 23, 2026
Conversation
henry3260
force-pushed
the
fix-connection-secret-validation
branch
3 times, most recently
from
July 13, 2026 12:21
2b0332f to
01a1b77
Compare
Contributor
|
Went through |
Lee-W
previously approved these changes
Jul 22, 2026
amoghrajesh
requested changes
Jul 22, 2026
henry3260
force-pushed
the
fix-connection-secret-validation
branch
from
July 22, 2026 09:36
01a1b77 to
8326268
Compare
Lee-W
approved these changes
Jul 23, 2026
amoghrajesh
reviewed
Jul 23, 2026
henry3260
force-pushed
the
fix-connection-secret-validation
branch
from
July 23, 2026 07:46
59749be to
db28d49
Compare
amoghrajesh
approved these changes
Jul 23, 2026
Prevent malformed JSON secrets from being reported as missing connections at runtime.
Review on the PR pointed out that rejecting JSON connection secrets without a conn_type would regress the Airflow 2 -> 3 migration compatibility deliberately established in apache#61728: secrets stored by Airflow 2-era backends (e.g. AWS Secrets Manager) commonly omit both conn_type and uri, and the worker-local secrets backend path must keep resolving them. Replace the rejection with a comment at the deserialization site and a regression test, so the compatibility guarantee is visible to future readers and enforced by CI. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Apply review suggestions: tighten the migration-compatibility comment and test docstring, and mark the compatibility path for removal once the minimum supported Airflow version in providers is 3.0.
henry3260
force-pushed
the
fix-connection-secret-validation
branch
from
July 23, 2026 09:08
db28d49 to
5455062
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Connection secrets in JSON format could omit
conn_type. Although the secrets backend deserialized those values, the Execution API requires a connection type and the task could ultimately receive a misleading “connection not found” error.This addresses the
conn_typeportion of related: #57864.What
conn_typeis missing, null, empty, or whitespace-only.ValueErrorbefore constructing an incomplete Connection.conn_typevalue.Was generative AI tooling used to co-author this PR?
{pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.