YugabyteDB YSQL and JDBC driver: interaction of expired VALID UNTIL roles with connection pooling
29.5K reputation · 02 Mar 2022, 08:15 UTC
Integration of YugabyteDB YSQL authentication with JDBC connection pooling
The goal is to determine how YugabyteDB’s yb‑tserver treats a role whose VALID UNTIL timestamp has passed when the client driver maintains a pooled connection that was established before expiration.
Uncertainty arises because the server checks the VALID UNTIL clause at login time, but the yb‑tserver flag --ysql_authentication_timeout and driver‑side credential caching may allow a pooled connection to be reused after the role has expired, leading to intermittent authentication failures or successes depending on timing and version.
- Does the yb‑tserver reject a pooled connection immediately after the role’s VALID UNTIL expires, or does it allow the connection to remain usable until it is returned to the pool and re‑validated?
- How does the --ysql_authentication_timeout setting influence the window in which an expired role can still be used by a pooled connection?
- Do major JDBC drivers (e.g., PostgreSQL, YugabyteDB‑specific) cache credentials in a way that could bypass the server’s expiration check for existing pooled connections?