Skip to content

Add Oracle thick mode support via ORACLE_THICK_MODE env var - #177

Open
Gigituier wants to merge 2 commits into
aws-samples:masterfrom
Gigituier:add-thick-mode-support
Open

Add Oracle thick mode support via ORACLE_THICK_MODE env var#177
Gigituier wants to merge 2 commits into
aws-samples:masterfrom
Gigituier:add-thick-mode-support

Conversation

@Gigituier

@Gigituier Gigituier commented Aug 14, 2026

Copy link
Copy Markdown

Summary

This PR adds configurable Oracle Thick mode support to the SecretsManagerRDSOracleRotationSingleUser template.

Changes

Oracle Thick Mode Toggle

Adds module-level initialization that checks the ORACLE_THICK_MODE environment variable. When enabled, calls oracledb.init_oracle_client() before any connection is created. This is required for customers whose Oracle databases enforce Native Network Encryption (NNE), checksumming, or Kerberos authentication, features that only work in python-oracledb's Thick mode.

New environment variables:

  • ORACLE_THICK_MODE (default: false) — set to true to enable
  • ORACLE_CLIENT_CONFIG_DIR (optional) — path to Oracle Net config files

When enabled, Oracle Instant Client libraries must be available via LD_LIBRARY_PATH (e.g., via a Lambda Layer).

Backward compatible, default behavior (thin mode) is unchanged.

Testing

Tested against Oracle Database Free (26ai) running on EC2 with Native Network Encryption set to REQUIRED:

Scenario Result
Original code, NNE REQUIRED, thin mode DPY-4011: the database or network closed the connection
Updated code, NNE REQUIRED, thick mode enabled Full rotation cycle passes

Note

The same change should be applied to SecretsManagerRDSOracleRotationMultiUser as well.

Related

Updated password handling in lambda function to use the correct pending password from the dictionary.
@Gigituier Gigituier changed the title Add Oracle thick mode support via ORACLE_THICK_MODE env var and fix password variable bug Add Oracle thick mode support via ORACLE_THICK_MODE env var Aug 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant