Barbican is a RESTful key manager service service for cloud applications.
Barbican includes a REST API (called Barbican) designed for the secure storage, provisioning and management of secrets. The API can interface with security appliances (such as HSMs).
The OpenStack community maintains several clients to this API:
* openstacksdk - https:/
* OpenStackClient - https:/
*
Barbican is part of OpenStack, and uses middleware to configure Keystone authentication/
Project information
- Licence:
- Apache Licence
View full history Series and milestones
2025.2 series is the current focus of development.
All code Code
- Version control system:
- Git
- Programming languages:
- python
All packages Packages in Distributions
-
barbican source package in Xenial
Version 1:2.0.0-0ubuntu1.1 uploaded -
barbican source package in Resolute
Version 2:21.0.0-0ubuntu1 uploaded -
barbican source package in Questing
Version 2:21.0.0-0ubuntu1 uploaded -
barbican source package in Plucky
Version 2:20.0.0-0ubuntu1 uploaded -
barbican source package in Noble
Version 2:18.0.0-0ubuntu1 uploaded
All bugs Latest bugs reported
-
Bug #2137646: kmip secret store incompatible with python3.12/3.13
Reported -
Bug #2130214: KEK rewrap (barbican-manage hsm rewrap_pkek) fails with TypeError when key_wrap_generate_iv=False (PKCS#11)
Reported -
Bug #2126581: devstack plugins should rely on devstack to install uwsgi
Reported -
Bug #2126788: barbican-retry is not gracefully shutting down
Reported -
Bug #2125699: unit tests cannot be run in parallel
Reported
All blueprints Latest blueprints
-
Add support for setting the KV engine version for Vault backends
Registered -
Add pre-ping to verify pooled DB connections before use
Registered -
PKCS#11 Mechanism List
Registered -
PKCS#11 Key Type Rotation
Registered -
Add authentication to AES-CBC encryption in PKCS#11 backend
Registered
More contributors Top contributors
- Sam Clippinger 504 points
- Takashi Kajinami 14 points
- Rajiv Mucheli 10 points
- Alexandre arents 10 points
- kaoru watanabe 8 points

