Merge "Updated security compliance section in README" into release/2019.2.0
diff --git a/keystone/server.sls b/keystone/server.sls
index 2c9e6b1..886b5e8 100644
--- a/keystone/server.sls
+++ b/keystone/server.sls
@@ -425,7 +425,7 @@
   - runas: 'keystone'
   - unless:
       . /var/lib/keystone/keystonercv3; openstack endpoint list --service identity --interface internal -f value -c URL  |grep {{ server.bind.get('port', 5000) }}
-    {%- if grains.get('noservices', False) %}
+    {%- if server.get('role', 'secondary') != 'primary' or grains.get('noservices', False) %}
   - onlyif: /bin/false
     {%- endif %}
   - require: