gnodet commented on code in PR #26845:
URL: https://github.com/apache/camel/pull/26845#discussion_r4125044710
##########
catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/docs/jdbc-component.adoc:
##########
@@ -336,3 +336,21 @@ from("timer://MoveNewCustomersEveryHour?period=3600000")
.setBody(simple("insert into processed_customer
values('${body[ID]}','${body[NAME]}')"))
.to("jdbc:testdb");
----
+
+== Secret Rotation
+
+The JDBC component implements `SecretRotationAware`. When a secret rotation
event is triggered
+(e.g. by a vault provider), the component evicts stale connections from its
connection pools.
+This covers the component-level DataSource as well as any DataSources resolved
by active endpoints
+(e.g. `jdbc:myDs`), with identity-based deduplication so each pool is evicted
at most once.
+
+Currently only HikariCP pools are supported for active eviction via
`softEvictConnections()`.
+Other pool implementations (including Quarkus Agroal) are not actively evicted
— existing connections
+will be replaced as they expire or are validated by the pool.
+
+IMPORTANT: The eviction only closes existing connections — it does *not*
update the pool's credentials.
+For pools configured with a static password (e.g. Spring Boot
`spring.datasource.password`),
+the pool will re-open connections using the _old_ credentials.
+This feature works out of the box only with pools that resolve credentials
dynamically,
+such as `HikariCredentialsProvider`, the AWS JDBC wrapper secrets plugin,
+or a custom `DataSource` that fetches credentials from a vault at connect time.
Review Comment:
Additionally, the docs now reflect both HikariCP and Agroal support (updated
in 2b58bfc57c3d). The GraalVM native reflection NOTE also lists the Agroal
classes that need registration.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]