Comment 1 for bug 1833756

Revision history for this message
Radosław Piliszek (yoctozepto) wrote : Re: Fresh Stein deployment - keystone logs flooded with each action

according to keystone stein release notes https://docs.openstack.org/releasenotes/keystone/stein.html :

"""
... if you have not overridden a policy, the old default and the new default will be OR’d together. This means that, for example, where we have changed the policy rule from 'rule:admin_required' to 'role:reader and system_scope:all', both policy rules will be in effect. Please check your current policies and role assignments before upgrading to ensure the policies will not be too permissive for your deployment. To hide the deprecation warnings and opt into the less permissive rules, you can override the policy configuration to use the newer policy rule.
"""

hence we should probably install the new default policies because logs are full of this junk entries otherwise.