Skip to content

Keep sync-perm going when a Dag has bad access_control - #71798

Open
Lothnic wants to merge 1 commit into
apache:mainfrom
Lothnic:fix-sync-perm-bad-access-control
Open

Keep sync-perm going when a Dag has bad access_control#71798
Lothnic wants to merge 1 commit into
apache:mainfrom
Lothnic:fix-sync-perm-bad-access-control

Conversation

@Lothnic

@Lothnic Lothnic commented Aug 18, 2026

Copy link
Copy Markdown

airflow sync-perm --include-dags iterates every Dag and syncs its access_control. A single Dag referencing a non-existent role (or an invalid resource/action) raised FabException mid-loop, aborting the whole run and leaving every remaining Dag without its permissions synced.

This catches FabException per-Dag in create_dag_specific_permissions, logs the misconfigured Dag, and continues with the rest — so one bad Dag can no longer block permission sync for all the good ones. The per-Dag parse path (_sync_dag_perms in collection.py) is deliberately left untouched, so a bad access_control still surfaces as that Dag's import error.

closes: #71795


Was generative AI tooling used to co-author this PR?
  • Yes

Generated-by: an AI coding assistant following the guidelines

A single Dag whose access_control references a non-existent role (or an
invalid resource/action) made airflow sync-perm --include-dags abort
partway through, leaving every remaining Dag without its permissions
synced. Skip the misconfigured Dag and continue with the rest so one bad
Dag can no longer block permission sync for all good ones.
Copilot AI lite review requested due to automatic review settings August 18, 2026 20:00
@Lothnic
Lothnic requested a review from vincbeck as a code owner August 18, 2026 20:00
@boring-cyborg

boring-cyborg Bot commented Aug 18, 2026

Copy link
Copy Markdown

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example Dag that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

airflow sync-perm --include-dags can fail due to a single misconfigured DAG

3 participants