Available integrations
Secrets backend integrations can be configured individually with each Astro Deployment by someone with Workspace Operator permissions. Using secrets to set Airflow connections requires knowledge of how to generate Airflow connections in URI or JSON format. See Import and export Airflow connections and variables for guidance on how to export your connections and variables based on where they are stored. Astro integrates with the following secrets backend tools:- AWS Secrets Manager
- AWS Systems Manager Parameter Store
- Azure Key Vault
- Google Cloud Secret Manager
- Hashicorp Vault
Remote execution integration
Airflow 3This feature is only available for Airflow 3.x Deployments.
How Airflow finds connections or variables
If you configure a secrets backend on Astro, you can still continue to define Airflow variables and connections as environment variables, with the Astro Environment Manager or in the Airflow UI. The order of precedence for connections is:- Secrets Backend
- Astro Environment Manager
- Environment Variables
- Airflow’s metadata database (Airflow UI)