Interface CredentialsResolver

All Known Implementing Classes:
CachingCredentialsResolver, EnvironmentCredentialsResolver, FileCredentialsResolver, StaticCredentialsResolver, SuppliedCredentialsResolver, SystemPropertyCredentialsResolver

public interface CredentialsResolver
Resolves Credentials on demand.

Implementations may read literals, environment variables, files, or call out to secret stores (Vault, AWS Secrets Manager, STS, KMS, ...). Endpoints call getCredentials() each time they open — never at construction — so rotated secrets are picked up automatically on the next connection. Implementations that resolve remotely should cache internally (see CachingCredentialsResolver).

See Also:
  • Method Summary

    Modifier and Type
    Method
    Description
    Resolves and returns the current credentials.
    default boolean
    Indicates if this resolver can return different credentials over time.
    default void
    Forces a re-fetch on the next call to getCredentials().
  • Method Details

    • getCredentials

      Credentials getCredentials() throws DataException
      Resolves and returns the current credentials. Must not return null.
      Throws:
      DataException
    • refresh

      default void refresh()
      Forces a re-fetch on the next call to getCredentials(). The default implementation does nothing.
    • isRotating

      default boolean isRotating()
      Indicates if this resolver can return different credentials over time. The default implementation returns false.