Use Cases and Supported Integrations
Why Deploy Delinea Credentials Cache
Applications that connect to databases, middleware, or other systems often retrieve the same secret many times, for example every time a connection pool opens a new connection or a discovery job runs. Without a cache, each of those requests is an API call to Secret Server or the Delinea Platform. Delinea Credentials Cache sits between the application and the vault: the first request for a secret fetches it from the vault and stores it locally, and subsequent requests for the same secret are answered from the cache until it expires or is refreshed.
Deploy Delinea Credentials Cache when you need to:
-
Reduce the number of repeated API calls to the vault for the same secret and the load that those calls place on Secret Server or the Delinea Platform.
-
Improve the response time of applications that read secrets at high frequency, such as JDBC connection pools and ServiceNow MID Server credential resolvers.
-
Keep applications running during short vault outages: secrets that are already cached continue to be served until their time-to-live (TTL) expires.
-
Cache any secret type, not only passwords. SSH keys, certificates, PEM files, and tokens are cached in the same way as credentials.
Tested Integrations
Delinea Credentials Cache has been implemented and tested to improve performance in the following integrations:
-
Integrating WebSphere Application Server with Delinea Using the JDBC Proxy Driver
-
Integrating Tomcat Server with Delinea Using the JDBC Proxy Driver
-
Integrating Secret Server with MID Server Credential Resolver
-
Integrating Delinea Platform with ServiceNow MID Server Credential Resolver
The cache is not limited to these integrations. Any client that can obtain a Bearer token and call the REST API described in API Reference can use it.
Keeping Cached Secrets Fresh
There are two mechanisms that keep the cache current. By default, every cached secret has a time-to-live (10 minutes unless you change it); when the TTL expires, the next request fetches the current value from the vault. If a secret is rotated inside the TTL window, the cache returning the previous value is expected behavior. To remove that window, configure event-driven refresh: a Secret Server or Delinea Platform Event Pipeline notifies the cache as soon as a password changes, and the cache re-fetches the secret immediately. See Configuring Delinea Credentials Cache for the TTL setting and Event-Driven Secret Refresh for the Event Pipeline approach.