Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adds secret env_var #3048

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

thomasjpfan
Copy link
Member

@thomasjpfan thomasjpfan commented Jan 10, 2025

Tracking issue

Related to flyteorg/flyte#6141 (comment)
Requires flyteorg/flyte#6160

Why are the changes needed?

This PR adds an env_var to the Secrets IDL, which has the follow behavior:

If mount_requirement is ENV_VAR, then we set an environment variable named env_name to the value of the secret.
If mount_requirement is FILE, then we set an environment variable named env_name to the path of the mounted secret.

What changes were proposed in this pull request?

This PR adds env_name to the Secrets IDL. This makes it easy to configure a secret in a Flyte task. For example, one can easily set a hugging face secret:

@task(secret_requests=[Secret(..., env_var="HF_TOKEN", mount_requirement=Secret.MountType.ENV_VAR)
def hello():
    ...

Or for secrets that require a file:

@task(secret_requests=[Secret(..., env_var="HF_TOKEN_PATH", mount_requirement=Secret.MountType.FILE)
def hello():
    ...

How was this patch tested?

I ran the following to try the two different modes:

from flytekit import task, Secret, ImageSpec
from typing import Optional
import os

image = ImageSpec(
    apt_packages=["git"],
    packages=[
        "git+https://github.com/thomasjpfan/flytekit.git@8814da92a8578dbad07550486a5aaced5785d7a5",
    ],
    registry="localhost:30000",
    commands=[
        "uv pip install git+https://github.com/thomasjpfan/flyte.git@25a7d9c100f571a9ce394e802d50ef8861eae7a4#subdirectory=flyteidl"
    ],
)



@task(
    container_image=image,
    secret_requests=[
        Secret(
            key="token",
            group="my-fun-group",
            mount_requirement=Secret.MountType.ENV_VAR,
            env_var="HELLO_WORLD",
        )
    ],
)
def get_secret_env_var() -> Optional[str]:
    return os.getenv("HELLO_WORLD")


@task(
    container_image=image,
    secret_requests=[
        Secret(
            key="token",
            group="my-fun-group",
            mount_requirement=Secret.MountType.FILE,
            env_var="HELLO_WORLD",
        )
    ],
)
def get_secret_file() -> str:
    with open(os.getenv("HELLO_WORLD"), "r") as f:
        return f.read()

Docs link

Summary by Bito

Enhanced Secret class in flytekit by renaming env_name to env_var parameter for improved clarity and consistency. The parameter enables direct secret value access through environment variables when mount_requirement is ENV_VAR, and provides file path access when set to FILE. Updates include changes to class definition, documentation, and protobuf conversion methods for more intuitive secret management configuration.

Unit tests added: False

Estimated effort to review (1-5, lower is better): 1

Signed-off-by: Thomas J. Fan <[email protected]>
@flyte-bot
Copy link
Contributor

flyte-bot commented Jan 10, 2025

Code Review Agent Run #f2a7e1

Actionable Suggestions - 0
Review Details
  • Files reviewed - 1 · Commit Range: 615499e..615499e
    • flytekit/models/security.py
  • Files skipped - 0
  • Tools
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful

AI Code Review powered by Bito Logo

@flyte-bot
Copy link
Contributor

flyte-bot commented Jan 10, 2025

Changelist by Bito

This pull request implements the following key changes.

Key Change Files Impacted
Feature Improvement - Enhanced Secret Configuration with Custom Environment Variables

security.py - Added env_var field to Secret class for customizable environment variable naming

Copy link

codecov bot commented Jan 10, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 78.54%. Comparing base (dfa8f04) to head (615499e).

Additional details and impacted files
@@             Coverage Diff             @@
##           master    #3048       +/-   ##
===========================================
+ Coverage   47.23%   78.54%   +31.30%     
===========================================
  Files         202      246       +44     
  Lines       21355    23238     +1883     
  Branches     2744     2744               
===========================================
+ Hits        10088    18253     +8165     
+ Misses      10776     4236     -6540     
- Partials      491      749      +258     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@cosmicBboy
Copy link
Contributor

lgtm, tests will pass in this PR once this is merged right? flyteorg/flyte#6160

@thomasjpfan
Copy link
Member Author

lgtm, tests will pass in this PR once this is merged right? flyteorg/flyte#6160

Yea and when a new flyteidl version is released.

Signed-off-by: Thomas J. Fan <[email protected]>
@thomasjpfan thomasjpfan changed the title Adds secret env_name Adds secret env_var Jan 16, 2025
@flyte-bot
Copy link
Contributor

flyte-bot commented Jan 16, 2025

Code Review Agent Run #7c9e36

Actionable Suggestions - 0
Review Details
  • Files reviewed - 1 · Commit Range: 615499e..8814da9
    • flytekit/models/security.py
  • Files skipped - 0
  • Tools
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful

AI Code Review powered by Bito Logo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants