This is an automated email from the ASF dual-hosted git repository.

gnodet pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new 471ad9363a38 CAMEL-24639: camel-http - document vault-backed 
credential rotation
471ad9363a38 is described below

commit 471ad9363a3890d542aec8015c3a40d2a5ce22fe
Author: Guillaume Nodet <[email protected]>
AuthorDate: Mon Sep 21 14:34:36 2026 +0200

    CAMEL-24639: camel-http - document vault-backed credential rotation
    
    Adds a documentation note in http-component.adoc explaining that 
vault-backed credentials are automatically picked up on context reload: 
DefaultContextReloadStrategy.reloadAllRoutes() clears the endpoint registry and 
rebuilds routes, so fresh endpoints are created with updated 
property-placeholder values. No SecretRotationAware implementation is needed 
for camel-http since Basic Auth is per-request and credentials flow into 
endpoints at creation time.
---
 .../resources/org/apache/camel/catalog/docs/http-component.adoc   | 8 ++++++++
 components/camel-http/src/main/docs/http-component.adoc           | 8 ++++++++
 .../modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc           | 1 +
 3 files changed, 17 insertions(+)

diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/http-component.adoc
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/http-component.adoc
index d8f448e0316c..ddca2c8f7c32 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/http-component.adoc
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/http-component.adoc
@@ -678,6 +678,14 @@ Camel only provides support for OAuth2 client credentials 
flow
 [IMPORTANT]
 Camel does not perform any validation in access token. It's up to the 
underlying service to validate it.
 
+=== Vault-backed credential rotation
+
+When using vault-backed property placeholders (e.g. 
`{{aws:mySecret/password}}`) with
+`DefaultContextReloadStrategy`, rotated credentials are picked up 
automatically because Camel rebuilds
+all routes and their endpoints from the updated component configuration after 
each reload event.
+No special configuration is needed for `camel-http`: the fresh endpoints 
created during the route
+restart carry the newly resolved credentials.
+
 === Advanced Usage
 
 If you need more control over the HTTP producer, you should use the
diff --git a/components/camel-http/src/main/docs/http-component.adoc 
b/components/camel-http/src/main/docs/http-component.adoc
index d8f448e0316c..ddca2c8f7c32 100644
--- a/components/camel-http/src/main/docs/http-component.adoc
+++ b/components/camel-http/src/main/docs/http-component.adoc
@@ -678,6 +678,14 @@ Camel only provides support for OAuth2 client credentials 
flow
 [IMPORTANT]
 Camel does not perform any validation in access token. It's up to the 
underlying service to validate it.
 
+=== Vault-backed credential rotation
+
+When using vault-backed property placeholders (e.g. 
`{{aws:mySecret/password}}`) with
+`DefaultContextReloadStrategy`, rotated credentials are picked up 
automatically because Camel rebuilds
+all routes and their endpoints from the updated component configuration after 
each reload event.
+No special configuration is needed for `camel-http`: the fresh endpoints 
created during the route
+restart carry the newly resolved credentials.
+
 === Advanced Usage
 
 If you need more control over the HTTP producer, you should use the
diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index 111908c48536..046c57203251 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -2364,3 +2364,4 @@ The `maxRetryTimeout` endpoint and component option is 
deprecated in both `camel
 it had no effect. The option is kept for backward compatibility of existing 
endpoint URIs but is marked
 deprecated and will be removed in a future release. Routes that set 
`maxRetryTimeout` can simply drop it;
 behaviour is unchanged.
+ 

Reply via email to