- Jinja 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| templates | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Keepalived
Install and configure Keepalived for VRRP high availability with unicast peers and a process-based health check.
Requirements
| Operating System | Notes |
|---|---|
| Debian | Installed with apt, restarted via systemd |
| Alpine | Installed with apk, restarted via service |
Variables
All defaults are placeholders ("these should not be used in production!") and must be overridden per host. The role has no role dependencies.
| Variable | Required | Default | Description |
|---|---|---|---|
keepalived_auth_pass |
No | "SuperSecurePassword" |
Authentication password. Not used by the current template. |
keepalived_chk_service |
Yes | "nginx" |
Process name checked with pgrep by the health check |
keepalived_id |
Yes | "dns01" |
Keepalived router_id (instance identifier) |
keepalived_interface |
Yes | "eth0" |
Network interface the VRRP instance runs on |
keepalived_priority |
Yes | "101" |
VRRP priority (higher wins the master election) |
keepalived_state |
Yes | "MASTER" |
Initial state (MASTER or BACKUP) |
keepalived_unicast_peer |
Yes | "192.168.1.3" |
Peer IP address for unicast VRRP |
keepalived_unicast_src_ip |
Yes | "192.168.1.2" |
Source IP address for unicast VRRP |
keepalived_virtual_ipaddress |
Yes | "192.168.1.1" |
Virtual IP address to manage |
keepalived_virtual_ipaddress_interface |
Yes | "eth0" |
Interface the virtual IP is attached to |
keepalived_vr_id |
Yes | "1" |
VRRP virtual router ID |
keepalived_vrrp_instance |
No | "VI_01" |
VRRP instance name. Not used by the current template. |
The template (templates/keepalived.conf.j2) always names the instance VI_1 and has no authentication block,
so keepalived_auth_pass and keepalived_vrrp_instance currently have no effect. "Required" means the value
differs per host in practice and should be set in the inventory.
Example
Set one host as MASTER with the higher priority and its peer as BACKUP. Keep real values for
keepalived_auth_pass in sops-encrypted inventory variables.
keepalived_chk_service: "haproxy"
keepalived_id: "lb01"
keepalived_interface: "eth0"
keepalived_priority: "101"
keepalived_state: "MASTER"
keepalived_unicast_peer: "192.168.1.11"
keepalived_unicast_src_ip: "192.168.1.10"
keepalived_virtual_ipaddress: "192.168.1.100"
keepalived_virtual_ipaddress_interface: "eth0"
keepalived_vr_id: "51"
What the role does
- Installs the
keepalivedpackage. - Creates
/etc/keepalivedand renders/etc/keepalived/keepalived.conf(mode0644). - Restarts and enables the service when the configuration changes.
- The configuration uses VRRP version 3, unicast with a single peer, a 1 second advert interval and gratuitous ARP
refresh. The health check runs
/usr/bin/pgrep <keepalived_chk_service>every second as root; while the process is running the node's priority is raised by 2 (weight 2).
Usage
Run playbook.yaml through Semaphore. It first runs ansible-galaxy install -f -r roles/requirements.yml on the
controller (works around a Semaphore bug), then includes the keepalived role on all hosts.