[QUEENS] Added check cluster node role for bootstrap keystone admin user.

  * Admin user bootstrap procedure should be executed once on the primary ctl node.

Change-Id: Ib65457cdd1d64d1bfda3f9652cc4a187ba946b60
Related-PROD: PROD-29377
diff --git a/keystone/server.sls b/keystone/server.sls
index be3a282..2b300be 100644
--- a/keystone/server.sls
+++ b/keystone/server.sls
@@ -415,7 +415,7 @@
   - runas: 'keystone'
   - unless:
       . /root/keystonercv3; openstack endpoint list --service identity --interface internal -f value -c URL  |grep {{ server.bind.get('port', 5000) }}
-    {%- if grains.get('noservices', False) %}
+    {%- if server.get('role', 'secondary') != 'primary' or grains.get('noservices', False) %}
   - onlyif: /bin/false
     {%- endif %}
 {%- endif %}