YugabyteDB YSQL and JDBC driver: interaction of expired VALID UNTIL roles with connection pooling
0 reputation · 02 Mar 2022, 08:15 UTC
0 reputation · 02 Mar 2022, 08:15 UTC
The goal is to determine how YugabyteDB’s yb‑tserver treats a role whose VALID UNTIL timestamp has passed when the client driver maintains a pooled connection that was established before expiration.
Uncertainty arises because the server checks the VALID UNTIL clause at login time, but the yb‑tserver flag --ysql_authentication_timeout and driver‑side credential caching may allow a pooled connection to be reused after the role has expired, leading to intermittent authentication failures or successes depending on timing and version.
29275 reputation · 02 Mar 2022, 10:59 UTC
In YugabyteDB YSQL, the VALID UNTIL clause is evaluated during the authentication handshake. Once a connection is established and the session is authorized, the server does not proactively terminate that session simply because the role's validity period expires.
VALID UNTIL timestamp, that connection remains usable for queries even after the role expires. The server treats the session as already authenticated.yb-tserver during the login phase.To verify this behavior in your environment, execute the following sequence:
CREATE ROLE test_user WITH LOGIN PASSWORD 'password' VALID UNTIL '2026-10-10 10:00:00';SELECT 1; using the existing pooled connection. It should succeed.This analysis assumes standard YSQL authentication flows. We assume the use of a connection pool that maintains long-lived TCP sessions. If your environment uses a proxy or load balancer that terminates idle connections, the "window of usability" for an expired role will be limited to the proxy's idle timeout.
Missing Diagnostic Detail: Are you using an external identity provider (LDAP/Active Directory) via YugabyteDB, or are you using internal YSQL roles? External providers may have different session revocation behaviors.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.