daryn reported that adding a new resource to a conf forces a complete reload of the conf instead of just loading the new resource. Instantiating a SSLFactory adds a new resource for the ssl client/server file. Formerly only the KMS client used the SSLFactory but now TLS/RPC uses it too.
The reload is so costly that RM token cancellation falls behind by hours or days. The accumulation of uncancelled tokens in the KMS rose from a few thousand to hundreds of thousands which risks ZK scalability issues causing a KMS outage.