Part 9 · 1 chapters · ~8 min

Capstone: Rotate a Database Password Under Load

The capstone: run a service at steady load, rotate its database credentials with the overlap pattern (or switch it to Vault dynamic credentials), and prove zero failed requests with metrics.

14

The exercise

code
setup
  ledger service (any language) → PgBouncer → Postgres, load generator at 500 req/s, dashboards for errors and p99
  two database roles: ledger_blue (active), ledger_green (created, same grants)

run
  1 set ledger_green's new password; store it in the secrets manager as version N+1
  2 consumers reload credentials from the mounted file (or rolling restart); the pool drains old connections
  3 verify: SELECT usename, count(*) FROM pg_stat_activity GROUP BY 1;   → only ledger_green
  4 ALTER ROLE ledger_blue NOLOGIN; then rotate blue's password for next time
  5 evidence: error rate flat, p99 flat, zero authentication failures in the Postgres log

stretch
  replace both roles with Vault database secrets engine credentials (1 h leases) and repeat the measurement