Apache Airflow / Astronomer
Managed (Astronomer, MWAA, Cloud Composer) or self-hosted.
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Airflow URL | Webserver URL for API access. |
| Authentication | Varies: basic auth, LDAP, OAuth/OIDC, or IAM (MWAA). |
| Scope | DAG definitions, task instances, connections metadata. |
Network considerations
Astronomer: HTTPS to deployment URL. No VPN needed.
MWAA (AWS): VPC-based. Requires VPC peering or public web server access (if enabled).
Cloud Composer (GCP): HTTPS to Airflow web UI. IAM-controlled.
Self-hosted: Standard networking: VPN, port 8080 (default webserver).
Credential and auth management
Astronomer: Deployment API token. Scoped to specific deployment.
MWAA: IAM auth. Flume’s AWS role needs airflow:CreateWebLoginToken.
Cloud Composer: IAM. GCP service account with composer.environments.get.
Self-hosted: Create a dedicated Airflow user with “Viewer” role. Basic auth or LDAP.
DAG code access: For full lineage, also access the DAG code repo directly (see Code Repos).
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET /api/v1/dags?limit=1 | Returns a DAG |
| DAG listing | GET /api/v1/dags | Lists all DAGs |
| DAG runs | GET /api/v1/dags/<id>/dagRuns?limit=1 | Returns recent run |
| Connections | GET /api/v1/connections (may be restricted) | Lists connection IDs (not secrets) |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.