Andrea Cosentino created CAMEL-24638:
----------------------------------------
Summary: camel-jdbc/camel-sql: implement SecretRotationAware to
rebuild the pool on rotation
Key: CAMEL-24638
URL: https://issues.apache.org/jira/browse/CAMEL-24638
Project: Camel
Issue Type: Sub-task
Components: camel-jdbc, camel-sql
Reporter: Andrea Cosentino
Sub-task of CAMEL-24636.
Adopt the {{SecretRotationAware}} SPI in camel-jdbc and camel-sql.
Both components resolve a {{DataSource}} bean from the registry
({{JdbcComponent}} looks it up by name or by type, {{SqlComponent}} holds one
directly). The {{DataSource}} is created once by Spring Boot, Quarkus or Camel
Main with the credentials valid at startup, and clearing the endpoint registry
during a context reload does not recreate it.
The result is that a connection pool such as HikariCP goes on handing out
connections authenticated with a revoked password, and new connections opened
by the pool fail once the old credential is retired.
On {{onSecretRotation}} the components should refresh the credentials the pool
uses and evict the existing connections so that the pool re-authenticates.
Where the underlying pool exposes a credential-update API this should be
preferred over recreating the {{DataSource}}, since the bean may be shared with
non-Camel code.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)