)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"f8275e5e482cd203c5e3bff8fde189af3671be9c","unresolved":false,"context_lines":[{"line_number":14,"context_line":""},{"line_number":15,"context_line":"For this, leverage the unused NAMESPACE_CREATING state and advance the"},{"line_number":16,"context_line":"statemachine only after K8s tells us that we are allowed to create"},{"line_number":17,"context_line":"service accounts."},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"Change-Id: I8f390339241da67a073f231bd0047485f1689f28"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"e7dc9b95_37c4bfed","line":17,"updated":"2026-08-07 13:41:09.000000000","message":"This will add an extra k8s api call to every pod creation, but it should be fast.  If we decide it\u0027s not fast enough, we could wrap the SA creation in a check that performs this only on initial failure, but that\u0027s more complex, so I think it\u0027s worth seeing if this is a problem first.","commit_id":"c8224508ca02a2efc6be5f15d20a957d5af4e86c"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":27582,"name":"Simon Westphahl","email":"simon.westphahl@bmw.de","username":"simon.westphahl"},"change_message_id":"e3bf4e03cc05edc38c440f2c0214a6c301c50976","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"3726710d_4c51e8d4","updated":"2026-08-08 10:44:09.000000000","message":"recheck","commit_id":"c8224508ca02a2efc6be5f15d20a957d5af4e86c"}],"zuul/driver/kubernetes/kubernetesendpoint.py":[{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"f8275e5e482cd203c5e3bff8fde189af3671be9c","unresolved":false,"context_lines":[{"line_number":316,"context_line":"        try:"},{"line_number":317,"context_line":"            return self.auth_client.create_self_subject_access_review(body)"},{"line_number":318,"context_line":"        except Exception:"},{"line_number":319,"context_line":"            return None"},{"line_number":320,"context_line":""},{"line_number":321,"context_line":"    def _createImagePullSecrets(self, namespace, label):"},{"line_number":322,"context_line":"        # Copy any image pull secrets required"}],"source_content_type":"text/x-python","patch_set":1,"id":"ebd262dd_a30e972f","line":319,"updated":"2026-08-07 13:41:09.000000000","message":"Note to reviewers: AIUI, these are \"created\" like normal resources, but they don\u0027t appear to persist as real objects.  Instead all the requested data is just returned in the response to the \"create\" call.  https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access","commit_id":"c8224508ca02a2efc6be5f15d20a957d5af4e86c"}]}
