Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Web based Cognito authentication for Nucleus Airflow UI #123

Open
ramesh-maddegoda opened this issue Oct 3, 2024 · 8 comments
Open

Web based Cognito authentication for Nucleus Airflow UI #123

ramesh-maddegoda opened this issue Oct 3, 2024 · 8 comments

Comments

@ramesh-maddegoda
Copy link
Contributor

ramesh-maddegoda commented Oct 3, 2024

💡 Description

As a part of the ticket Setup role based authentication and authorization for Airflow UI with Cognito, an ALB based approach to enable Cognito authentication for Nucleus Airflow UI was implemented. However, the ALB based approach only worked sometimes and currently there is an Amazon support ticket Case 172781777100323 to troubleshoot it. At the moment, a python script is used to get a web token URL to access Airflow UI.

This ticket is created to focus on resolving this ALB related problem and eventually implement web based Cognito authentication for Nucleus Airflow UI.

⚔️ Parent Epic / Related Tickets

Related: Setup role based authentication and authorization for Airflow UI with Cognito

@ramesh-maddegoda ramesh-maddegoda self-assigned this Oct 3, 2024
@github-project-automation github-project-automation bot moved this to Release Backlog in B15.1 Oct 3, 2024
@ramesh-maddegoda ramesh-maddegoda changed the title web based Cognito authentication for Nucleus Airflow UI Web based Cognito authentication for Nucleus Airflow UI Oct 3, 2024
@tloubrieu-jpl
Copy link
Member

Ramesh needs the access log of the EC2 application load balancer to be set to investigate an issue with the web authentication for nucleus. Rmesh will send a ticket to MCP if it does not go through.

@ramesh-maddegoda
Copy link
Contributor Author

It seems, there is a permission issues in MCP. I created the ticket GSD-4269

@tloubrieu-jpl
Copy link
Member

The MCP ticket has been assigned to someone who is going to help investigate the issue.

@tloubrieu-jpl
Copy link
Member

@ramesh-maddegoda was able to unblock this issue by having the log enabled. He will move forward now with this task.

@jordanpadams jordanpadams added enhancement New feature or request theme and removed task labels Oct 31, 2024
@jordanpadams jordanpadams moved this from Release Backlog to Blocked in B15.1 Oct 31, 2024
@jordanpadams jordanpadams added Epic p.must-have and removed enhancement New feature or request labels Oct 31, 2024
@tloubrieu-jpl
Copy link
Member

The AWS ticket is escalated to the Cognito team.

@tloubrieu-jpl
Copy link
Member

Network rules (NACL) must be updated for that to work.

@jordanpadams
Copy link
Member

📆 10/2024 status: in work on schedule

@tloubrieu-jpl
Copy link
Member

@ramesh-maddegoda made tests which show that the network is properly configured. He is now investigating possible issues with the Gognito UI redirect URLs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Blocked
Development

No branches or pull requests

3 participants