apupier commented on code in PR #26845:
URL: https://github.com/apache/camel/pull/26845#discussion_r4123391364


##########
catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/jdbc-component.adoc:
##########
@@ -336,3 +336,21 @@ from("timer://MoveNewCustomersEveryHour?period=3600000")
         .setBody(simple("insert into processed_customer 
values('${body[ID]}','${body[NAME]}')"))
         .to("jdbc:testdb");
 ----
+
+== Secret Rotation
+
+The JDBC component implements `SecretRotationAware`. When a secret rotation 
event is triggered
+(e.g. by a vault provider), the component evicts stale connections from its 
connection pools.
+This covers the component-level DataSource as well as any DataSources resolved 
by active endpoints
+(e.g. `jdbc:myDs`), with identity-based deduplication so each pool is evicted 
at most once.
+
+Currently only HikariCP pools are supported for active eviction via 
`softEvictConnections()`.
+Other pool implementations (including Quarkus Agroal) are not actively evicted 
— existing connections
+will be replaced as they expire or are validated by the pool.
+
+IMPORTANT: The eviction only closes existing connections — it does *not* 
update the pool's credentials.
+For pools configured with a static password (e.g. Spring Boot 
`spring.datasource.password`),
+the pool will re-open connections using the _old_ credentials.
+This feature works out of the box only with pools that resolve credentials 
dynamically,
+such as `HikariCredentialsProvider`, the AWS JDBC wrapper secrets plugin,
+or a custom `DataSource` that fetches credentials from a vault at connect time.

Review Comment:
   It also requires that jmx is activated for Hikari.
   
https://github.com/brettwooldridge/HikariCP/wiki/MBean-(JMX)-Monitoring-and-Management
   
   registerMbeans=true must be provided for Hikari



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to