Ansible role for installing and configuring KeepaliveD
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 1882285838
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:29:40 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:48:50 +00:00
defaults feat: initial commit 2025-07-14 16:30:11 +02:00
handlers chore: migrate bare ansible_* facts to ansible_facts[] syntax 2026-05-19 09:19:04 +02:00
meta feat: initial commit 2025-07-14 16:30:11 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:01 +02:00
tasks chore: migrate bare ansible_* facts to ansible_facts[] syntax 2026-05-19 09:19:04 +02:00
templates fix: keepalived config 2026-03-06 07:56:24 +01:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:44 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:49 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:49 +02:00
.gitignore feat: initial commit 2025-07-14 16:30:11 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:01 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:51 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:28 +02:00
AGENTS.md chore: add AGENTS.md for opencode agents 2026-02-16 10:06:22 +01:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:03 +02:00
readme.md docs: improve readme 2026-10-05 17:29:40 +02:00
renovate.json feat: initial commit 2025-07-14 16:30:11 +02:00

Ansible Role: Keepalived

Install and configure Keepalived for VRRP high availability with unicast peers and a process-based health check.

Requirements

Operating System Notes
Debian Installed with apt, restarted via systemd
Alpine Installed with apk, restarted via service

Variables

All defaults are placeholders ("these should not be used in production!") and must be overridden per host. The role has no role dependencies.

Variable Required Default Description
keepalived_auth_pass No "SuperSecurePassword" Authentication password. Not used by the current template.
keepalived_chk_service Yes "nginx" Process name checked with pgrep by the health check
keepalived_id Yes "dns01" Keepalived router_id (instance identifier)
keepalived_interface Yes "eth0" Network interface the VRRP instance runs on
keepalived_priority Yes "101" VRRP priority (higher wins the master election)
keepalived_state Yes "MASTER" Initial state (MASTER or BACKUP)
keepalived_unicast_peer Yes "192.168.1.3" Peer IP address for unicast VRRP
keepalived_unicast_src_ip Yes "192.168.1.2" Source IP address for unicast VRRP
keepalived_virtual_ipaddress Yes "192.168.1.1" Virtual IP address to manage
keepalived_virtual_ipaddress_interface Yes "eth0" Interface the virtual IP is attached to
keepalived_vr_id Yes "1" VRRP virtual router ID
keepalived_vrrp_instance No "VI_01" VRRP instance name. Not used by the current template.

The template (templates/keepalived.conf.j2) always names the instance VI_1 and has no authentication block, so keepalived_auth_pass and keepalived_vrrp_instance currently have no effect. "Required" means the value differs per host in practice and should be set in the inventory.

Example

Set one host as MASTER with the higher priority and its peer as BACKUP. Keep real values for keepalived_auth_pass in sops-encrypted inventory variables.

keepalived_chk_service: "haproxy"
keepalived_id: "lb01"
keepalived_interface: "eth0"
keepalived_priority: "101"
keepalived_state: "MASTER"
keepalived_unicast_peer: "192.168.1.11"
keepalived_unicast_src_ip: "192.168.1.10"
keepalived_virtual_ipaddress: "192.168.1.100"
keepalived_virtual_ipaddress_interface: "eth0"
keepalived_vr_id: "51"

What the role does

  • Installs the keepalived package.
  • Creates /etc/keepalived and renders /etc/keepalived/keepalived.conf (mode 0644).
  • Restarts and enables the service when the configuration changes.
  • The configuration uses VRRP version 3, unicast with a single peer, a 1 second advert interval and gratuitous ARP refresh. The health check runs /usr/bin/pgrep <keepalived_chk_service> every second as root; while the process is running the node's priority is raised by 2 (weight 2).

Usage

Run playbook.yaml through Semaphore. It first runs ansible-galaxy install -f -r roles/requirements.yml on the controller (works around a Semaphore bug), then includes the keepalived role on all hosts.