latent.mlflow.request_header_provider¶
Authenticate MLflow REST calls to a Cloudflare Access protected tracking server.
Cloudflare Access (self-hosted apps) accepts a user identity JWT via the
cf-access-token request header. This MLflow RequestHeaderProvider plugin
injects that token on every tracking REST call, so a remote server behind Access
works with a plain MLFLOW_TRACKING_URI=https://... — no service token and no
port-forward. Artifact uploads are unaffected: they go straight to the object
store (e.g. S3) using the caller's own cloud credentials.
Auto-discovered via the mlflow.request_header_provider entry point. It is
fail-open: for an https tracking URI it mints a token with
cloudflared access token (run cloudflared access login <uri> first), and
any failure yields no header rather than raising — so non-Cloudflare servers and
local (sqlite) runs are unaffected. Set LATENT_MLFLOW_CF_ACCESS_TOKEN to
supply a pre-minted token in CI.
Usage:
cloudflared access login "$MLFLOW_TRACKING_URI"
export MLFLOW_TRACKING_URI=https://
Classes¶
CloudflareAccessRequestHeaderProvider¶
Injects a Cloudflare Access cf-access-token header for https servers.
Functions¶
cloudflared_token¶
Return a Cloudflare Access token for app_url via cloudflared, or None.
None means cloudflared is missing, the URL isn't http(s), or there's no valid
session (run cloudflared access login <app_url>). Never raises.