Envoy On Loopback, Its Admin Interface Kept Off The Network
Envoy from the upstream release, SHA-256 pinned, with its listener and its admin interface on loopback and its bootstrap checked by the installed release before it lands. The live test proxies a request to an upstream it serves, stops the upstream and sees Envoy answer 503 itself, and reads both outcomes in the admin stats. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-envoy?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [Envoy On Loopback, Its Admin Interface Kept Off The Network](https://www.iac-bazaar.com/catalog/ansible-envoy?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# Envoy On Loopback, Its Admin Interface Kept Off The Network: https://www.iac-bazaar.com/catalog/ansible-envoy (download from your IaC Bazaar account)
```Preview:
Documentation
envoy
Envoy from the upstream release binary (SHA-256 pinned, see below), as a hardened system service with its listener and its admin interface on loopback, routing every path to one upstream by default and accepting a complete bootstrap instead. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, and no checksum file to speak of. EL 10 carries no
envoy, and Envoy publishes the release with nothing beside it. This
role pins the SHA-256 per architecture beside the version, has Ansible's
get_url refuse the binary unless it matches, and installs it
as root's in /usr/local/bin. A new release is a new pair, on purpose.
A service account, a hardened unit, a loopback listener. envoy
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:10000 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
Checked by the release that will run it. envoy --mode validate -c
parses the bootstrap and resolves every reference before the file lands; a
broken value (an unknown cluster type, say) stops the converge instead of the
proxy. Envoy picks its parser from the file's extension, which is why this
works: Ansible hands the checker a temporary .source.yaml (measured with
ansible-core 2.21.4). The same valid text in a file WITHOUT an extension is
refused, so a wrapper that copies the file to an extension-less path before
checking it would block every change.
The admin interface stays on loopback. It serves /quitquitquit, config
dumps and runtime overrides, so the role binds it to 127.0.0.1:9901 and the
live test reads the listening sockets to see both listeners there. Hot
restart is off (--disable-hot-restart), so no shared-memory segment is
left in /dev/shm, and the workers default to two rather than one per CPU.
Proven by a request, and by its absence. The live test serves a page on
the default upstream, fetches it through the listener (the response carries
x-envoy-upstream-service-time and server: envoy), stops the upstream, and
sees Envoy answer 503 itself rather than hang; the admin stats count one
upstream_rq_200 and at least one upstream_cx_connect_fail.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-haproxy-tls
HAProxy terminating TLS 1.2 and 1.3 only with a modern cipher policy, HTTP redirected to HTTPS, HSTS on every response including HAProxy's own error pages (http-after-response, which the live test proved http-response does not cover), a self-signed certificate until yours arrives, stats kept local. Original role, live-tested on Rocky Linux 10.
ansible-keepalived
keepalived on EL 10: one VRRP instance, checked by keepalived's own --config-test before it lands, with the configuration at 0600 because auth_pass is a cleartext secret. The live test waits for this node to take the virtual address, stops the service and asserts the address LEFT, then starts it and asserts it came back. Original role, live-tested on Rocky Linux 10.