FRR BGP With Filters Both Ways And MD5 Sessions

FRR from AppStream: BGP that announces only your prefixes, accepts from each neighbour only what you list for it, signs sessions with TCP MD5, and applies a change without dropping them. The live test peers with a real BGP speaker in its own namespace; a filtered prefix stays out of the kernel and a wrong password keeps the session down. Original role, live-tested on Rocky Linux 10.

ansibleNetworking & VPC

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-frr/badge)](https://www.iac-bazaar.com/catalog/ansible-frr?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [FRR BGP With Filters Both Ways And MD5 Sessions](https://www.iac-bazaar.com/catalog/ansible-frr?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# FRR BGP With Filters Both Ways And MD5 Sessions: https://www.iac-bazaar.com/catalog/ansible-frr (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

frr

FRR from AppStream: a BGP speaker that announces the prefixes you list and nothing else, accepts from each neighbour only the prefixes you list for it, signs each session with a TCP MD5 password, and applies a changed configuration without dropping a session. Original role for EL 10, live-tested with podman on Rocky Linux 10 against a real BGP peer.

No download, and no version to pin. EL 10 packages frr, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs frr, switches on the daemons you list in /etc/frr/daemons (a restart), and writes frr.conf frr:frr 0640, checked by vtysh -C first (exit 2 on an unknown command, measured). A changed frr.conf is applied by systemctl reload frr, which runs frr-reload: a probe changed the announced prefix and the BGP session stayed up (uptime 3 s, then 12 s). bgpd's vty stays on 127.0.0.1 - the package sets every daemon's vty there - and the live test reads the sockets to prove it for bgpd. BGP itself listens on port 179 on every address, for its peers.

Filters both ways, as RFC 8212 asks. Each announced prefix is anchored by a blackhole route, so it is announced while the router is up whatever else is in the table, and the export filter allows those prefixes and nothing else - a learned route is never passed on. Each neighbour's import filter allows only the prefixes listed for it; none listed refuses everything.

Proven against a real peer. The defaults are documentation values (AS 64496 and 64497, 192.0.2.0/24, 198.51.100.0/24) and the live test peers with exactly those: a second bgpd in its own network namespace announces 203.0.113.0/24 and 192.0.2.128/25. The session establishes; 203.0.113.0/24 reaches the kernel as a BGP route; 192.0.2.128/25 - announced, as the peer's own table shows - is refused by the import filter and never reaches the kernel; the peer learns 198.51.100.0/24 from us. Then the peer restarts with a wrong MD5 password and the session stays down for thirty seconds (it came up in about three with the right one).

The live test needs two capabilities. The namespace and its link need NET_ADMIN and NET_RAW in the test container: tools/validate/live-ansible.sh artifacts/ansible/frr --systemd --cap-add=NET_ADMIN --cap-add=NET_RAW.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-squid

The stock squid.conf allows localhost before it denies loopback destinations, so a local client can proxy into loopback services. This role puts every deny first and binds loopback. The live test fetches a page through it, then sees squid itself refuse loopback, 169.254.169.254, an unsafe port, CONNECT to 25 and a non-loopback client. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-consul-server

HashiCorp Consul as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, DNS, RPC and both serf listeners on loopback and its configuration checked by consul validate before it lands. The live test waits for a leader, writes a KV key through the API, reads it back and reads the member alive. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-headscale

Headscale, the self-hosted Tailscale control server, from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; configtest runs as the service user (it opens the database). The live test creates a user over the unix socket, issues a reusable pre-auth key for it, reads the user back from the key, destroys it. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-wireguard

WireGuard from AppStream: a wg-quick interface whose private key is generated once and kept in its own file, never in the config, peers from a variable, and each config loaded into a throwaway interface first. The live test pings through the tunnel from a peer in another network namespace while an unlisted key gets no reply. Original role, live-tested on Rocky Linux 10.

View module