Kea DHCPv4 That Answers Only The Subnets You Name
Kea DHCPv4 from AppStream: your subnets, pools, options and reservations in Kea's own keys, checked with kea-dhcp4 -t and applied by reload, leases on disk. The live test runs a raw-socket DHCP client in a namespace: an address with router, DNS and lease time, the reserved address for its MAC, and nothing on a segment no subnet covers. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-kea-dhcp4?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [Kea DHCPv4 That Answers Only The Subnets You Name](https://www.iac-bazaar.com/catalog/ansible-kea-dhcp4?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# Kea DHCPv4 That Answers Only The Subnets You Name: https://www.iac-bazaar.com/catalog/ansible-kea-dhcp4 (download from your IaC Bazaar account)
```Preview:
Documentation
kea-dhcp4
Kea's DHCPv4 server from AppStream: your subnets, pools, options and
reservations written in Kea's own terms, checked with kea-dhcp4 -t before
they land and applied with a reload, leases kept on disk, and nothing answered
on a segment you have not described. Original role for EL 10, live-tested with
podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages Kea 3.0 in AppStream, so
the role installs kea by name and takes what the distribution ships: a
security update arrives through dnf, not through a new release of this role.
What the role owns is the configuration and the proof that the server works.
The distribution's unit, our configuration. The package's unit runs
kea-dhcp4 as the kea user, Type=notify, and its reload sends SIGHUP, which
re-reads the file (measured: a new pool served after systemctl reload). The
stock file serves nothing (interfaces: []) and logs to a file; the role's
serves the interfaces you name (* by default), logs to the journal, keeps the
control socket in /run/kea (Kea 3 refuses one anywhere else - measured), and
keeps leases in /var/lib/kea/kea-leases4.csv, which survive a restart. Kea's
HTTP control agent is a separate program that the role does not start: the
server opens no TCP listener.
Answers only where you say. The defaults are documentation values: one
subnet in TEST-NET-1 (192.0.2.0/24, RFC 5737) with a pool, a router, a DNS
server and one reservation - so with them the server answers nobody on a real
network. Kea picks a subnet by the address of the interface a request arrives
on, and a request from a segment no subnet covers gets no offer at all: the
live test's client there got nothing while the server counted its request as
received and dropped (measured), so the silence is a refusal and not a lost
packet. Replace kea_dhcp4_subnets with your own, in Kea's own keys.
Proven by a client. tests/pre-converge.yml gives TEST-NET-1 a home - a
network namespace joined to the host by a veth pair, the host end 192.0.2.1 -
and a second segment, 198.51.100.0/24, that no subnet covers. The live test's
client builds its DHCP frames itself on a raw socket in those namespaces (a UDP
client on an interface with no address got no offer - measured), and gets an
address from the pool with the router, the DNS server and the lease time; the
reserved hardware address gets its reserved address; and the client on the
second segment gets nothing. Both leases are in the lease file. The lane needs
--cap-add=NET_ADMIN --cap-add=NET_RAW for the namespaces and the raw sockets.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-squid
The stock squid.conf allows localhost before it denies loopback destinations, so a local client can proxy into loopback services. This role puts every deny first and binds loopback. The live test fetches a page through it, then sees squid itself refuse loopback, 169.254.169.254, an unsafe port, CONNECT to 25 and a non-loopback client. Original role, live-tested on Rocky Linux 10.
ansible-consul-server
HashiCorp Consul as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, DNS, RPC and both serf listeners on loopback and its configuration checked by consul validate before it lands. The live test waits for a leader, writes a KV key through the API, reads it back and reads the member alive. Original role, live-tested on Rocky Linux 10.
ansible-frr
FRR from AppStream: BGP that announces only your prefixes, accepts from each neighbour only what you list for it, signs sessions with TCP MD5, and applies a change without dropping them. The live test peers with a real BGP speaker in its own namespace; a filtered prefix stays out of the kernel and a wrong password keeps the session down. Original role, live-tested on Rocky Linux 10.
ansible-headscale
Headscale, the self-hosted Tailscale control server, from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; configtest runs as the service user (it opens the database). The live test creates a user over the unix socket, issues a reusable pre-auth key for it, reads the user back from the key, destroys it. Original role, live-tested on Rocky 10.
ansible-wireguard
WireGuard from AppStream: a wg-quick interface whose private key is generated once and kept in its own file, never in the config, peers from a variable, and each config loaded into a throwaway interface first. The live test pings through the tunnel from a peer in another network namespace while an unlisted key gets no reply. Original role, live-tested on Rocky Linux 10.