Comment 3 for bug 1963685

Revision history for this message
Alex Kavanagh (ajkavanagh) wrote :

This sounds like the policy change issue that came in in wallaby: https://docs.openstack.org/releasenotes/octavia/wallaby.html, particularly the bit:

"Legacy Octavia Advanced RBAC policies will continue to function as before as long as the [oslo_policy] enforce_scope = False and enforce_new_defaults = False settings are present (this is the current oslo.policy default). However, we highly recommend you update your user roles to follow the new keystone default roles and start using scoped tokens as appropriate. See the Octavia Policies administration guide for more information."