Secret manager plugin credential rotation behavior
0 reputation · 25 Mar 2025, 16:48 UTC
Context
DBeaver supports reading database credentials from HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault through marketplace plugins, enabling least-privilege access without local password storage. The master password encryption only protects locally stored credentials and does not apply to secrets fetched at runtime.
Gap
The documentation does not specify whether DBeaver automatically detects and refreshes credentials when the secret manager rotates them, or if a connection restart is required. Drivers that lack a JDBC changePassword method already fail on password expiration without a guided reset, so the behavior for externally sourced credentials is a practical concern.
Questions
- Does DBeaver re-fetch secrets from the external manager on each new connection attempt, or does it cache them for the session?
- When a secret is rotated in Vault or AWS Secrets Manager, must the user manually reconnect, or can DBeaver detect the change transparently?
- Is there a configuration option to set a TTL for cached external credentials?