Skip to main content
See All Integrations

Apache Airflow

Protect access to Apache Airflow workflows and administration as an upstream web application.

Standard protected service pattern

Categories
AI and Data, Upstream Applications

Overview

Apache Airflow is an open-source platform for developing, scheduling, and monitoring batch workflows. Its web server exposes the administration interface and APIs. Current deployments can also use WebSocket connections for live features.

Apache Airflow can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Apache Airflow. Apache Airflow remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Enable the Airflow proxy-header settings and preserve WebSocket upgrades. Do not overwrite Airflow cookie security or application authorization settings.

Example

A private Airflow web server runs in a Kubernetes cluster. Pomerium protects its HTTPS route for the data engineering group. Airflow keeps its own roles and permissions for DAG changes, connections, and administration.

Considerations

  • Trust forwarded headers only from the Pomerium route and configure Airflow proxy behavior for the public origin.
  • Airflow 3 API access uses its own JWT model. API automation cannot depend on an interactive browser redirect.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Protect access to Apache Superset dashboards and data exploration as an upstream web application.

  • Protect access to JupyterHub notebook environments as an upstream web application.

  • Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo