)]}'
{"id":"openstack%2Ftacker~999244","triplet_id":"openstack%2Ftacker~master~I72f6e100ab8289304559173859622d772527d402","project":"openstack/tacker","branch":"master","topic":"reuse-keymgr-api","attention_set":{"25701":{"account":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"last_update":"2026-07-30 11:24:28.000000000","reason":"A robot voted negatively on a label"}},"removed_from_attention_set":{},"hashtags":[],"change_id":"I72f6e100ab8289304559173859622d772527d402","subject":"Reuse the key manager API to get VIM credentials","status":"NEW","created":"2026-07-30 08:59:49.000000000","updated":"2026-08-02 19:17:56.000000000","submit_type":"MERGE_IF_NECESSARY","mergeable":true,"submittable":false,"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"0e3caa8bd3883566aabaace4cce2900466e771ce","_number":999244,"virtual_id_number":999244,"owner":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"actions":{},"labels":{"Verified":{"recommended":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"tag":"autogenerated:zuul:check","value":1,"date":"2026-08-02 19:17:56.000000000","permitted_voting_range":{"min":-2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","value":1,"default_value":0,"optional":true},"Code-Review":{"all":[{"value":0,"permitted_voting_range":{"min":-1,"max":1},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"all":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-30 11:24:28.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"}],"messages":[{"id":"f5e3f0f54faa7949311c6c68b9b09fe13d7c3b33","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"date":"2026-07-30 08:59:49.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"193e8f746178bee88a472137448ed9f4fe6cc4a0","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-30 11:24:28.000000000","message":"Patch Set 1: Verified-1\n\nBuild failed (check pipeline).  For information on how to proceed, see\nhttps://docs.opendev.org/opendev/infra-manual/latest/developers.html#automated-testing\nand https://docs.openstack.org/project-team-guide/testing.html#how-to-handle-test-failures\n\nhttps://zuul.opendev.org/t/openstack/buildset/30c66985fbaf4b188444db06e83da6cb\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/553613e32dc34886913fc6c2d3a64264 : FAILURE in 6m 30s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/1f5e04d262f74a09a31a65a6d9386337 : SUCCESS in 4m 47s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/a637d2ebd331414e969d694e673ad442 : FAILURE in 8m 55s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/f1093528ed3a4b32ba8295bd80f0de10 : FAILURE in 12m 09s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/3d6b2ee889f74e289c0746b5db97d300 : FAILURE in 13m 44s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/227af3ff683a4c418ebf4465dfd550c4 : SUCCESS in 9m 06s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/441a42b40c324be9b18ffeb5d959daa3 : SUCCESS in 6m 46s\n- tacker-ft-v2-k8s https://zuul.opendev.org/t/openstack/build/c3acae717e234394bee3b1f62ae83ba9 : SUCCESS in 1h 01m 21s\n- tacker-ft-v2-df-userdata-basic-min https://zuul.opendev.org/t/openstack/build/4d4b4dcdef674976a123a154953afa5a : SUCCESS in 54m 33s\n- tacker-ft-v2-df-userdata-update https://zuul.opendev.org/t/openstack/build/41eb6a7a891e4b76b09c2adb1267b3f3 : SUCCESS in 1h 01m 22s\n- tacker-ft-v2-df-userdata-scale https://zuul.opendev.org/t/openstack/build/e9a1ba102255458c92aeee18afdbf6b9 : SUCCESS in 1h 04m 58s\n- tacker-ft-v2-df-userdata-ccvp https://zuul.opendev.org/t/openstack/build/90c775f351dc45b3be6970a1b5e108ca : SUCCESS in 1h 01m 33s\n- tacker-ft-v2-df-userdata-err-handling https://zuul.opendev.org/t/openstack/build/3e7509785c374c66a51c65b351c65325 : SUCCESS in 59m 02s\n- tacker-ft-v2-st-userdata-basic https://zuul.opendev.org/t/openstack/build/1cbe210c03cc49b1a761ab804f6f6ef5 : POST_FAILURE in 58m 54s\n- tacker-ft-v2-st-userdata-basic-min https://zuul.opendev.org/t/openstack/build/c1b4507e73c846c8a8359651e5f19a5e : SUCCESS in 54m 29s\n- tacker-ft-v2-st-userdata-ccvp https://zuul.opendev.org/t/openstack/build/72f134c98ca24f789f7b3cbe62350dde : SUCCESS in 1h 06m 19s\n- tacker-ft-v2-df-userdata-https https://zuul.opendev.org/t/openstack/build/9a2a4c82c2fc421983849bbca0b25b21 : FAILURE in 51m 04s (non-voting)\n- tacker-ft-v2-df-userdata-notification https://zuul.opendev.org/t/openstack/build/5ac1222c44ad4131914412eb616d287b : SUCCESS in 1h 08m 08s (non-voting)\n- tacker-ft-v2-terraform https://zuul.opendev.org/t/openstack/build/606a073afbe24fa29aeb376a60e2dce5 : RETRY_LIMIT in 18m 28s (non-voting)\n- tacker-ft-v1-vnfpkgm https://zuul.opendev.org/t/openstack/build/67463e70a2c04bbda4bc012cf6009f40 : SUCCESS in 42m 38s\n- tacker-ft-v1-k8s https://zuul.opendev.org/t/openstack/build/b30eec240f104387a4af12867ba44beb : SUCCESS in 1h 10m 31s\n- tacker-ft-v1-compliance-sol https://zuul.opendev.org/t/openstack/build/ca63189ab1a64f74ae04ef28fbc4c75f : FAILURE in 2h 17m 20s (non-voting)","accounts_in_message":[],"_revision_number":1},{"id":"15832741a4b72f4c5fda4ba6644c38f09d675a89","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"date":"2026-07-30 12:03:05.000000000","message":"Patch Set 2: Patch Set 1 was rebased\n\nOutdated Votes:\n* Verified-1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":2},{"id":"09cbde419e6a3223f72e119f1cd744d9b940409a","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-07-30 14:28:39.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/f257def4fa554feaafe59d3aaac2a755\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/f1354e9b9e454a4f80bf3f4c12e8fad6 : SUCCESS in 8m 29s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/00b38876c2d74a6ca819ed2eb4acdadf : SUCCESS in 3m 15s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/bdb7f76d3d3e43e3b22af655de7ab30e : SUCCESS in 9m 20s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/a53c3113b1944cf19d377fd9e0e9ee73 : SUCCESS in 9m 39s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/9597d82ae5dc421da837ab362b2b82b2 : SUCCESS in 13m 03s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/c43c3cae7c4b40f4bf179b96f36aa630 : SUCCESS in 10m 59s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/fd4f63377b084786ae43cc3b75d748c7 : SUCCESS in 5m 43s\n- tacker-ft-v2-k8s https://zuul.opendev.org/t/openstack/build/5b6850b224474db68e921add513a4115 : SUCCESS in 1h 10m 52s\n- tacker-ft-v2-df-userdata-basic-min https://zuul.opendev.org/t/openstack/build/06980fc18993429d8273a72326f3dfca : SUCCESS in 53m 21s\n- tacker-ft-v2-df-userdata-update https://zuul.opendev.org/t/openstack/build/b51aec6e5d00425b995e2c2a45ace7fd : SUCCESS in 46m 16s\n- tacker-ft-v2-df-userdata-scale https://zuul.opendev.org/t/openstack/build/49c24764dcbf4c79bb6c60ca379f583b : SUCCESS in 1h 04m 52s\n- tacker-ft-v2-df-userdata-ccvp https://zuul.opendev.org/t/openstack/build/63d1c7c7f78746dba0fbc9ca599fbcc0 : SUCCESS in 56m 02s\n- tacker-ft-v2-df-userdata-err-handling https://zuul.opendev.org/t/openstack/build/1a785ee2334b4072b9cd219df812efd7 : SUCCESS in 56m 04s\n- tacker-ft-v2-st-userdata-basic https://zuul.opendev.org/t/openstack/build/d04a539831414d7f9d1ae491ff30a59e : SUCCESS in 34m 49s\n- tacker-ft-v2-st-userdata-basic-min https://zuul.opendev.org/t/openstack/build/c34ba14d1b9c43109eea91b3ea1dc4d5 : SUCCESS in 43m 00s\n- tacker-ft-v2-st-userdata-ccvp https://zuul.opendev.org/t/openstack/build/d2877a508e61496bbea3d6af9f59b887 : SUCCESS in 48m 03s\n- tacker-ft-v2-df-userdata-https https://zuul.opendev.org/t/openstack/build/68580d76c89f411f84893f93ca0803e3 : FAILURE in 55m 55s (non-voting)\n- tacker-ft-v2-df-userdata-notification https://zuul.opendev.org/t/openstack/build/bb95b9b08e4448c8b0f9b5252eaa346d : SUCCESS in 39m 50s (non-voting)\n- tacker-ft-v2-terraform https://zuul.opendev.org/t/openstack/build/5add43faadc84282a672737d234b0765 : RETRY_LIMIT in 15m 12s (non-voting)\n- tacker-ft-v1-vnfpkgm https://zuul.opendev.org/t/openstack/build/adeb1489259f4b1f9dadfecc544a070f : SUCCESS in 41m 33s\n- tacker-ft-v1-k8s https://zuul.opendev.org/t/openstack/build/f895f130223748bab0ea654977a18257 : SUCCESS in 1h 10m 23s\n- tacker-ft-v1-compliance-sol https://zuul.opendev.org/t/openstack/build/62a876dd099f43d0980802edebf493aa : FAILURE in 2h 16m 29s (non-voting)","accounts_in_message":[],"_revision_number":2},{"id":"60059919a0351f179607d19f1dd5d6982a2288e9","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"date":"2026-08-02 16:16:43.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Verified+1 (copy condition: \"NEVER\")\n","accounts_in_message":[],"_revision_number":3},{"id":"f8f6a1cb27c9eca5f48a56162bb4f3c08ef72e63","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"date":"2026-08-02 16:40:09.000000000","message":"Uploaded patch set 4: Commit message was updated.","accounts_in_message":[],"_revision_number":4},{"id":"9b4220ec1ffec58aff49b6b4483520acc430369a","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"date":"2026-08-02 17:02:43.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"0e3caa8bd3883566aabaace4cce2900466e771ce","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2026-08-02 19:17:56.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\nhttps://zuul.opendev.org/t/openstack/buildset/2520c968f79f482283a6951f57513cfe\n\n- openstack-tox-cover https://zuul.opendev.org/t/openstack/build/62f082923d824239969153327cae447c : SUCCESS in 6m 57s\n- openstack-tox-pep8 https://zuul.opendev.org/t/openstack/build/5a0c3d0530234e95b82f06a8385d0579 : SUCCESS in 3m 08s\n- openstack-tox-py311 https://zuul.opendev.org/t/openstack/build/429905a741474a8b81ea923be14d249a : SUCCESS in 8m 54s\n- openstack-tox-py313 https://zuul.opendev.org/t/openstack/build/41412efd017445549019fa06084b2df8 : SUCCESS in 6m 34s\n- openstack-tox-py314 https://zuul.opendev.org/t/openstack/build/579cfd4555514a11bbf705f64d3085b2 : SUCCESS in 7m 40s (non-voting)\n- openstack-tox-docs https://zuul.opendev.org/t/openstack/build/836a5137c9c54b16abae9b87fa4363c8 : SUCCESS in 7m 10s\n- build-openstack-releasenotes https://zuul.opendev.org/t/openstack/build/44166e411dd0483bb3ec8d2b448bdf79 : SUCCESS in 4m 55s\n- tacker-ft-v2-k8s https://zuul.opendev.org/t/openstack/build/17868f6262e34be5a6a793845b849638 : SUCCESS in 51m 46s\n- tacker-ft-v2-df-userdata-basic-min https://zuul.opendev.org/t/openstack/build/58f4ce978fe84f81a2c37ccded3a5f08 : SUCCESS in 38m 53s\n- tacker-ft-v2-df-userdata-update https://zuul.opendev.org/t/openstack/build/ff9f2d853a9e4c17a62215cc9921a08c : SUCCESS in 56m 54s\n- tacker-ft-v2-df-userdata-scale https://zuul.opendev.org/t/openstack/build/6de57c9fdee84b2ba76dc2d7d13cb938 : SUCCESS in 1h 00m 40s\n- tacker-ft-v2-df-userdata-ccvp https://zuul.opendev.org/t/openstack/build/277f9f1edf744653a54a3c418f00241d : SUCCESS in 29m 53s\n- tacker-ft-v2-df-userdata-err-handling https://zuul.opendev.org/t/openstack/build/9782ddf05c334208b59ef60bd8bf4982 : SUCCESS in 58m 22s\n- tacker-ft-v2-st-userdata-basic https://zuul.opendev.org/t/openstack/build/060317a1ab084ea3953584ffb9a48f3b : SUCCESS in 59m 51s\n- tacker-ft-v2-st-userdata-basic-min https://zuul.opendev.org/t/openstack/build/c6a04693e7aa4fc89ad2880d6bf41272 : SUCCESS in 52m 43s\n- tacker-ft-v2-st-userdata-ccvp https://zuul.opendev.org/t/openstack/build/2546178af4ac45f386fe1b3998caab25 : SUCCESS in 31m 47s\n- tacker-ft-v2-df-userdata-https https://zuul.opendev.org/t/openstack/build/1acfd3bf227f41eea82f269d7bd37100 : FAILURE in 22m 42s (non-voting)\n- tacker-ft-v2-df-userdata-notification https://zuul.opendev.org/t/openstack/build/1e852efef63843e5a467ac29f6ba4084 : SUCCESS in 33m 51s (non-voting)\n- tacker-ft-v2-terraform https://zuul.opendev.org/t/openstack/build/c52dd8e5af1f40a0ad5b95bd3a508fec : RETRY_LIMIT in 14m 30s (non-voting)\n- tacker-ft-v1-vnfpkgm https://zuul.opendev.org/t/openstack/build/ec461868a9564512be8ee65fb6931cd0 : SUCCESS in 39m 50s\n- tacker-ft-v1-k8s https://zuul.opendev.org/t/openstack/build/ac3d1aff9a644dfba3dfdb77ed4c6a4b : SUCCESS in 44m 46s\n- tacker-ft-v1-compliance-sol https://zuul.opendev.org/t/openstack/build/cd0a065543ec451f9466df19bb9d6cfb : FAILURE in 2h 09m 29s (non-voting)","accounts_in_message":[],"_revision_number":5}],"current_revision_number":5,"current_revision":"a035753867375ca53121018e1e9ca6d95eded06c","revisions":{"ec1c462ff0042500dbab59ff7510a401a7dd4453":{"kind":"REWORK","_number":1,"created":"2026-07-30 08:59:49.000000000","uploader":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"ref":"refs/changes/44/999244/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/tacker","ref":"refs/changes/44/999244/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/tacker refs/changes/44/999244/1"}}},"commit":{"parents":[{"commit":"f3615fce08fa37af57636b5346cd42df607f3d38","subject":"Merge \"Refactor access to hash object\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/f3615fce08fa37af57636b5346cd42df607f3d38"}]}],"author":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-07-29 16:26:48.000000000","tz":540},"committer":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-07-29 16:26:48.000000000","tz":540},"subject":"Reuse the key manager API to get VIM credentials","message":"Reuse the key manager API to get VIM credentials\n\n_decode_vim_auth() created a key manager API for every encrypted field\nof the VIM credentials. BarbicanKeyManager keeps the barbican client it\ncreates, but the cache was never used because the instance was thrown\naway after a single secret was fetched. Every call therefore ran the\nbarbican version discovery and got a new keystone token.\n\nIn a run of the tacker-ft-v1-k8s job, the conductor sent 2418 requests\nto keystone and barbican, of which 403 were token requests and 806 were\nversion discoveries. Note that they are sent to another node in this\njob, so they are also affected when that node is slow to respond.\n\nKeep the key manager API per auth url so that the barbican client is\ncreated once. Only the requests to get the secret itself are left.\n\nNote that this does not help when ext_oauth2_auth is enabled, because\nExtOAuth2Auth does not compare equal to the context of the cached\nclient and the client is created again.\n\nSigned-off-by: Yasufumi Ogawa \u003cyasufum.o@gmail.com\u003e\nChange-Id: I72f6e100ab8289304559173859622d772527d402\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/ec1c462ff0042500dbab59ff7510a401a7dd4453"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/ec1c462ff0042500dbab59ff7510a401a7dd4453"}]},"branch":"refs/heads/master"},"eb2c7fa7a1a85d90fdd9f11e28fd7901895bea1d":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-07-30 12:03:05.000000000","uploader":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"ref":"refs/changes/44/999244/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/tacker","ref":"refs/changes/44/999244/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/tacker refs/changes/44/999244/2"}}},"commit":{"parents":[{"commit":"04d16910590999c7c4056c87dd993a614bd0ed87","subject":"Remove enforce_scope override in tests","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/04d16910590999c7c4056c87dd993a614bd0ed87"}]}],"author":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-07-29 16:26:48.000000000","tz":540},"committer":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-07-30 12:03:05.000000000","tz":0},"subject":"Reuse the key manager API to get VIM credentials","message":"Reuse the key manager API to get VIM credentials\n\n_decode_vim_auth() created a key manager API for every encrypted field\nof the VIM credentials. BarbicanKeyManager keeps the barbican client it\ncreates, but the cache was never used because the instance was thrown\naway after a single secret was fetched. Every call therefore ran the\nbarbican version discovery and got a new keystone token.\n\nIn a run of the tacker-ft-v1-k8s job, the conductor sent 2418 requests\nto keystone and barbican, of which 403 were token requests and 806 were\nversion discoveries. Note that they are sent to another node in this\njob, so they are also affected when that node is slow to respond.\n\nKeep the key manager API per auth url so that the barbican client is\ncreated once. Only the requests to get the secret itself are left.\n\nNote that this does not help when ext_oauth2_auth is enabled, because\nExtOAuth2Auth does not compare equal to the context of the cached\nclient and the client is created again.\n\nSigned-off-by: Yasufumi Ogawa \u003cyasufum.o@gmail.com\u003e\nChange-Id: I72f6e100ab8289304559173859622d772527d402\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/eb2c7fa7a1a85d90fdd9f11e28fd7901895bea1d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/eb2c7fa7a1a85d90fdd9f11e28fd7901895bea1d"}]},"branch":"refs/heads/master","description":"Rebase","conflicts":{"base":"f3615fce08fa37af57636b5346cd42df607f3d38","ours":"ec1c462ff0042500dbab59ff7510a401a7dd4453","theirs":"04d16910590999c7c4056c87dd993a614bd0ed87","merge_strategy":"recursive","contains_conflicts":false}},"c4097d9b62ef98fbdbfcfe742d73f7161347653f":{"kind":"REWORK","_number":3,"created":"2026-08-02 16:16:43.000000000","uploader":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"ref":"refs/changes/44/999244/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/tacker","ref":"refs/changes/44/999244/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/tacker refs/changes/44/999244/3"}}},"commit":{"parents":[{"commit":"f3615fce08fa37af57636b5346cd42df607f3d38","subject":"Merge \"Refactor access to hash object\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/f3615fce08fa37af57636b5346cd42df607f3d38"}]}],"author":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-07-29 16:26:48.000000000","tz":540},"committer":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-08-02 13:16:07.000000000","tz":540},"subject":"Reuse the key manager API to get VIM credentials","message":"Reuse the key manager API to get VIM credentials\n\nRefactor by reducing the requests sent to Keystone and Barbican.\n\nBarbicanKeyManager keeps the barbican client it creates, but the cache\nwas never used because the instance was thrown\naway after a single secret was fetched. Every call therefore ran the\nbarbican version discovery and got a new keystone token.\n\nIn a run of the tacker-ft-v1-k8s job, the conductor sent 2418 requests\nto keystone and barbican, of which 403 were token requests and 806 were\nversion discoveries.\n\nBy this change, keep the key manager API per auth url so that the\nbarbican client is created once. Only the requests to get the secret\nitself are left.\n\nNote that this does not help when ext_oauth2_auth is enabled, because\nExtOAuth2Auth does not compare equal to the context of the cached\nclient and the client is created again.\n\nSigned-off-by: Yasufumi Ogawa \u003cyasufum.o@gmail.com\u003e\nChange-Id: I72f6e100ab8289304559173859622d772527d402\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/c4097d9b62ef98fbdbfcfe742d73f7161347653f"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/c4097d9b62ef98fbdbfcfe742d73f7161347653f"}]},"branch":"refs/heads/master"},"b66132aa79f8c3e07f4669b7546f67212209cbfe":{"kind":"NO_CODE_CHANGE","_number":4,"created":"2026-08-02 16:40:09.000000000","uploader":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"ref":"refs/changes/44/999244/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/tacker","ref":"refs/changes/44/999244/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/tacker refs/changes/44/999244/4"}}},"commit":{"parents":[{"commit":"f3615fce08fa37af57636b5346cd42df607f3d38","subject":"Merge \"Refactor access to hash object\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/f3615fce08fa37af57636b5346cd42df607f3d38"}]}],"author":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-07-29 16:26:48.000000000","tz":540},"committer":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-08-02 16:38:59.000000000","tz":540},"subject":"Reuse the key manager API to get VIM credentials","message":"Reuse the key manager API to get VIM credentials\n\nRefactor by reducing the requests sent to Keystone and Barbican.\n\nBarbicanKeyManager keeps the barbican client it creates, but the cache\nwas never used because the instance was thrown\naway after a single secret was fetched. Every call therefore ran the\nbarbican version discovery and got a new keystone token.\n\nIn a run of the tacker-ft-v1-k8s job, the conductor sent 2418 requests\nto keystone and barbican, of which 403 were token requests and 806 were\nversion discoveries.\n\nBy this change, keep the key manager API per auth url so that the\nbarbican client is created once. Only the requests to get the secret\nitself are left.\n\nNote that this does not help when ext_oauth2_auth is enabled, because\nExtOAuth2Auth does not compare equal to the context of the cached\nclient and the client is created again.\n\nSigned-off-by: Yasufumi Ogawa \u003cyasufum.o@gmail.com\u003e\nCloses-Bug: https://bugs.launchpad.net/tacker/+bug/2162669\nChange-Id: I72f6e100ab8289304559173859622d772527d402\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/b66132aa79f8c3e07f4669b7546f67212209cbfe"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/b66132aa79f8c3e07f4669b7546f67212209cbfe"}]},"branch":"refs/heads/master"},"a035753867375ca53121018e1e9ca6d95eded06c":{"kind":"REWORK","_number":5,"created":"2026-08-02 17:02:43.000000000","uploader":{"_account_id":25701,"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","username":"yasufum"},"ref":"refs/changes/44/999244/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/tacker","ref":"refs/changes/44/999244/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/tacker refs/changes/44/999244/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/tacker refs/changes/44/999244/5"}}},"commit":{"parents":[{"commit":"f3615fce08fa37af57636b5346cd42df607f3d38","subject":"Merge \"Refactor access to hash object\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/f3615fce08fa37af57636b5346cd42df607f3d38"}]}],"author":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-07-29 16:26:48.000000000","tz":540},"committer":{"name":"Yasufumi Ogawa","email":"yasufum.o@gmail.com","date":"2026-08-02 17:01:51.000000000","tz":540},"subject":"Reuse the key manager API to get VIM credentials","message":"Reuse the key manager API to get VIM credentials\n\nRefactor by reducing the requests sent to Keystone and Barbican.\n\nBarbicanKeyManager keeps the barbican client it creates, but the cache\nwas never used because the instance was thrown\naway after a single secret was fetched. Every call therefore ran the\nbarbican version discovery and got a new keystone token.\n\nIn a run of the tacker-ft-v1-k8s job, the conductor sent 2418 requests\nto keystone and barbican, of which 403 were token requests and 806 were\nversion discoveries.\n\nBy this change, keep the key manager API per auth url so that the\nbarbican client is created once. Only the requests to get the secret\nitself are left.\n\nNote that this does not help when ext_oauth2_auth is enabled, because\nExtOAuth2Auth does not compare equal to the context of the cached\nclient and the client is created again.\n\nSigned-off-by: Yasufumi Ogawa \u003cyasufum.o@gmail.com\u003e\nCloses-Bug: https://bugs.launchpad.net/tacker/+bug/2162669\nChange-Id: I72f6e100ab8289304559173859622d772527d402\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/a035753867375ca53121018e1e9ca6d95eded06c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/tacker/commit/a035753867375ca53121018e1e9ca6d95eded06c"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"rule_name":"gerrit~DefaultSubmitRule","status":"OK","labels":[{"label":"Verified","status":"MAY","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"MAY"},{"label":"Workflow","status":"MAY"}]}],"submit_requirements":[{"name":"Verified","description":"Verified in gate by CI","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Verified\u003dMAX AND -label:Verified\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Verified\u003dMAX","label:Verified\u003dMIN"],"atom_explanations":{"label:Verified\u003dMAX":"","label:Verified\u003dMIN":""}}},{"name":"Code-Review","description":"Code reviewed by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Code-Review\u003dMAX AND -label:Code-Review\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Code-Review\u003dMAX","label:Code-Review\u003dMIN"],"atom_explanations":{"label:Code-Review\u003dMAX":"","label:Code-Review\u003dMIN":""}}},{"name":"Workflow","description":"Approved for gate by core reviewer","status":"UNSATISFIED","is_legacy":false,"submittability_expression_result":{"expression":"label:Workflow\u003dMAX AND -label:Workflow\u003dMIN","fulfilled":false,"status":"FAIL","passing_atoms":[],"failing_atoms":["label:Workflow\u003dMAX","label:Workflow\u003dMIN"],"atom_explanations":{"label:Workflow\u003dMAX":"","label:Workflow\u003dMIN":""}}}]}
