Skip to content

Support runtime refresh of the DB username (not just password) for rotating dynamic credentials #12193

Description

@Roxyrob

Is your feature request related to a problem?

Temporal can refresh the DB password at runtime (cfg.PasswordCommand → a refreshable DSN),
but the username is fixed in static config. Credential systems that rotate both fields
per lease — HashiCorp Vault's database secrets engine (per-lease users like entity:serv-xxxx) —
therefore cannot be used without a pod restart on every rotation. This is the sibling of #9156:
both need credentials re-resolved at runtime, but #9156 rotates a token (password-like) while
this rotates the username too.

What already exists (main)

  • common/persistence/sql/sqlplugin/db_handle.go — DatabaseHandle.connect func() (*sqlx.DB, error)
    is re-invoked on every reconnect(force); ConvertError triggers reconnect(true) on
    needsRefresh(err) and on connection errors (ErrBadConn, EOF,
    ECONNRESET/ECONNABORTED/ECONNREFUSED). Combined with MaxConnLifetime, connections are
    periodically rebuilt and the connect callback re-runs.
  • common/persistence/sql/sqlplugin/postgresql/session/session.go — createConnection already
    supports a refreshable DSN via cfg.PasswordCommand → CreateRefreshableConnection(buildDSN).

The gap

buildDSN reads cfg.User as a static value, so even the refreshable path only refreshes the
password. There is no equivalent of PasswordCommand for the username.

Proposed solution

Extend the refreshable-credentials mechanism so the username is re-read on each connect() —
e.g. a UserCommand (analogous to PasswordCommand) or a credentials-provider that yields both
username and password at DSN-build time. On reconnect (driven by MaxConnLifetime or
ConvertError), the pool then re-authenticates with the rotated username+password without a
restart. This reuses the existing DatabaseHandle.reconnect() + PasswordCommand infrastructure,
generalizing the password refresh already present.

Environment

Version: v1.31.2 (mechanism unchanged on main). Plugin: postgres12 / postgres12_pgx.
Credentials: Vault per-lease username+password delivered as a K8s Secret by the Vault Secrets
Operator.

Related

Activity

  1. locked and limited conversation to collaborators on Oct 8, 2026
  2. converted this issue into a discussion #12467 on Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions