keepalived, An Address That Moves, And Is Watched Moving
keepalived on EL 10: one VRRP instance, checked by keepalived's own --config-test before it lands, with the configuration at 0600 because auth_pass is a cleartext secret. The live test waits for this node to take the virtual address, stops the service and asserts the address LEFT, then starts it and asserts it came back. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-keepalived?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [keepalived, An Address That Moves, And Is Watched Moving](https://www.iac-bazaar.com/catalog/ansible-keepalived?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# keepalived, An Address That Moves, And Is Watched Moving: https://www.iac-bazaar.com/catalog/ansible-keepalived (download from your IaC Bazaar account)
```Preview:
Documentation
keepalived
A virtual address that moves, and a test that watches it move. The role
writes one VRRP instance, checked by keepalived --config-test before it lands,
and enables the unit the distribution ships. The live test waits for this node to
take the address, stops keepalived and asserts the address LEFT, then starts it
and asserts it came back.
No download, and no version to pin. EL 10 packages keepalived, so the role installs it by name and enables the unit the distribution ships. What the role owns is the instance: who this node is, what address it takes, what it checks before keeping it, and the proof that the address follows the service.
The configuration is 0600 because it contains a secret. auth_pass is a
shared VRRP password in cleartext; the file mode is part of the policy, and the
live test reads it off the file rather than trusting the template.
The live test needs CAP_NET_ADMIN and CAP_NET_RAW. The container the
lane boots carries neither, and without them the kernel refuses the very call
this role exists to make, so the test would pass having changed nothing. The
lane is therefore run as live-ansible.sh ... --cap-add=NET_ADMIN --cap-add=NET_RAW, and the receipt records it: a pass under an added
capability is not the same claim as a pass without one.
keepalived truncates auth_pass to 8 characters and says nothing. A longer
secret is not the secret in use, and two nodes that disagree past the eighth
character will still peer happily. The template truncates it here, so what is
written is what was meant.
The default virtual address is from TEST-NET-1 (192.0.2.0/24, RFC 5737). A placeholder that cannot route anywhere means a role applied before it is configured takes an address nobody is trying to reach, instead of quietly answering for a real one.
unicast_src_ip without unicast_peer falls back to multicast, with a
deprecation warning and no error. The template writes the unicast block only when
peers are given, so the configuration says what it does.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test