gnodet commented on code in PR #26845:
URL: https://github.com/apache/camel/pull/26845#discussion_r4123543821


##########
catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/jdbc-component.adoc:
##########
@@ -336,3 +336,21 @@ from("timer://MoveNewCustomersEveryHour?period=3600000")
         .setBody(simple("insert into processed_customer 
values('${body[ID]}','${body[NAME]}')"))
         .to("jdbc:testdb");
 ----
+
+== Secret Rotation
+
+The JDBC component implements `SecretRotationAware`. When a secret rotation 
event is triggered
+(e.g. by a vault provider), the component evicts stale connections from its 
connection pools.
+This covers the component-level DataSource as well as any DataSources resolved 
by active endpoints
+(e.g. `jdbc:myDs`), with identity-based deduplication so each pool is evicted 
at most once.
+
+Currently only HikariCP pools are supported for active eviction via 
`softEvictConnections()`.
+Other pool implementations (including Quarkus Agroal) are not actively evicted 
— existing connections
+will be replaced as they expire or are validated by the pool.
+
+IMPORTANT: The eviction only closes existing connections — it does *not* 
update the pool's credentials.
+For pools configured with a static password (e.g. Spring Boot 
`spring.datasource.password`),
+the pool will re-open connections using the _old_ credentials.
+This feature works out of the box only with pools that resolve credentials 
dynamically,
+such as `HikariCredentialsProvider`, the AWS JDBC wrapper secrets plugin,
+or a custom `DataSource` that fetches credentials from a vault at connect time.

Review Comment:
   Addressed in 79ad28d2cea7. Added clarification to the docs that JMX 
registration (`registerMbeans=true`) is **not** required — the code calls 
`getHikariPoolMXBean()` directly via reflection, not through JMX.
   
   Also added a NOTE about GraalVM native mode: the reflected classes 
(`HikariDataSource`, `HikariPoolMXBean`) and their methods need to be 
registered for reflection in native builds.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to