gnodet commented on code in PR #26845:
URL: https://github.com/apache/camel/pull/26845#discussion_r4123505499
##########
catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/jdbc-component.adoc:
##########
@@ -336,3 +336,21 @@ from("timer://MoveNewCustomersEveryHour?period=3600000")
.setBody(simple("insert into processed_customer
values('${body[ID]}','${body[NAME]}')"))
.to("jdbc:testdb");
----
+
+== Secret Rotation
+
+The JDBC component implements `SecretRotationAware`. When a secret rotation
event is triggered
+(e.g. by a vault provider), the component evicts stale connections from its
connection pools.
+This covers the component-level DataSource as well as any DataSources resolved
by active endpoints
+(e.g. `jdbc:myDs`), with identity-based deduplication so each pool is evicted
at most once.
+
+Currently only HikariCP pools are supported for active eviction via
`softEvictConnections()`.
+Other pool implementations (including Quarkus Agroal) are not actively evicted
— existing connections
+will be replaced as they expire or are validated by the pool.
+
+IMPORTANT: The eviction only closes existing connections — it does *not*
update the pool's credentials.
+For pools configured with a static password (e.g. Spring Boot
`spring.datasource.password`),
+the pool will re-open connections using the _old_ credentials.
+This feature works out of the box only with pools that resolve credentials
dynamically,
+such as `HikariCredentialsProvider`, the AWS JDBC wrapper secrets plugin,
+or a custom `DataSource` that fetches credentials from a vault at connect time.
Review Comment:
Actually `registerMbeans=true` is not required here. That setting controls
whether HikariCP registers a JMX MBean in the platform MBeanServer for external
monitoring tools.
Our code doesn't use JMX at all — it calls `getHikariPoolMXBean()` directly
on the `HikariDataSource` instance via reflection. That method simply returns
the internal `HikariPool` field (which implements `HikariPoolMXBean`),
regardless of whether JMX registration is enabled. See
[HikariDataSource.java#getHikariPoolMXBean()](https://github.com/brettwooldridge/HikariCP/blob/dev/src/main/java/com/zaxxer/hikari/HikariDataSource.java#L285)
— it just does `return pool;`.
The only case where it returns `null` is when the pool hasn't been started
yet (lazy init with no-arg constructor before the first `getConnection()`
call), which we already handle with a DEBUG log.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]