radvd Router Advertisements, Refused Where The Host Does Not Route
radvd from AppStream advertising your IPv6 prefixes, DNS servers and search domains on the interfaces you name, checked with radvd -c and applied by reload, and refusing to advertise this host as a default router while IPv6 forwarding is off. The live test has a host in a namespace configure an address while a second segment hears nothing. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-radvd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [radvd Router Advertisements, Refused Where The Host Does Not Route](https://www.iac-bazaar.com/catalog/ansible-radvd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# radvd Router Advertisements, Refused Where The Host Does Not Route: https://www.iac-bazaar.com/catalog/ansible-radvd (download from your IaC Bazaar account)
```Preview:
Documentation
radvd
radvd from AppStream: IPv6 router advertisements for the interfaces you
name - the prefixes hosts configure their addresses from, their DNS servers and
search domains - checked with radvd -c before they land and applied with a
reload. It will not advertise this host as a default router unless the host
forwards IPv6. Original role for EL 10, live-tested with podman on Rocky Linux
10.
No download, and no version to pin. EL 10 packages radvd, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The distribution's unit, our configuration. The package's unit starts
radvd with -u radvd (from /etc/sysconfig/radvd), and the live test finds it
running as the radvd user; its reload sends SIGHUP, which re-reads the file
(measured: a changed prefix was heard on the segment after a reload). radvd
speaks ICMPv6 on the interfaces it serves and opens no TCP or UDP port: the
live test finds no listener of either kind on the host.
The role writes the whole of /etc/radvd.conf (root 0644).
It will not advertise a router that does not route. With
AdvDefaultLifetime above 0, radvd tells every host on the segment to send its
traffic here - and it does so even when this host does not forward IPv6: it logs
"IPv6 forwarding seems to be disabled, but continuing anyway" and keeps
advertising (measured: the peer installed a default route through it). The role
reads /proc/sys/net/ipv6/conf/all/forwarding and refuses that combination
(radvd_require_forwarding). The example advertises prefixes and DNS only
(default_lifetime: 0); give an interface a lifetime once this host routes.
DNS lifetimes the RFC asks for. Left to itself radvd advertised the DNS
server with a lifetime equal to the maximum interval (10 seconds at an interval
of 10, measured), while RFC 8106 asks for at least three times the interval, so
that one lost advertisement does not take a host's DNS server away. The role
writes three times max_interval for the DNS server and the search domain
unless you set rdnss_lifetime or dnssl_lifetime.
Answers only where you say. The example names an interface, radvd0, that a
real host does not have, with IgnoreIfMissing, and a prefix from the
documentation range (2001:db8::/32, RFC 3849): with it radvd advertises nothing.
Replace radvd_interfaces with your own.
Proven by a host that configures itself. tests/pre-converge.yml gives
radvd0 a home - a veth pair into a network namespace - and makes a second pair,
radvd1, that the configuration does not name. The live test makes each peer ask
(a link flap sends a router solicitation) and listens with radvdump: on the
served segment the advertisement carries the prefix, the DNS server and the
search domain with their lifetimes, the peer has configured an address from the
prefix and has no default route through a host that does not forward, and on
the second segment nothing is heard at all. The lane needs
--cap-add=NET_ADMIN --cap-add=NET_RAW for the namespaces and radvd's raw
ICMPv6 socket.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-squid
The stock squid.conf allows localhost before it denies loopback destinations, so a local client can proxy into loopback services. This role puts every deny first and binds loopback. The live test fetches a page through it, then sees squid itself refuse loopback, 169.254.169.254, an unsafe port, CONNECT to 25 and a non-loopback client. Original role, live-tested on Rocky Linux 10.
ansible-consul-server
HashiCorp Consul as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, DNS, RPC and both serf listeners on loopback and its configuration checked by consul validate before it lands. The live test waits for a leader, writes a KV key through the API, reads it back and reads the member alive. Original role, live-tested on Rocky Linux 10.
ansible-frr
FRR from AppStream: BGP that announces only your prefixes, accepts from each neighbour only what you list for it, signs sessions with TCP MD5, and applies a change without dropping them. The live test peers with a real BGP speaker in its own namespace; a filtered prefix stays out of the kernel and a wrong password keeps the session down. Original role, live-tested on Rocky Linux 10.
ansible-headscale
Headscale, the self-hosted Tailscale control server, from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; configtest runs as the service user (it opens the database). The live test creates a user over the unix socket, issues a reusable pre-auth key for it, reads the user back from the key, destroys it. Original role, live-tested on Rocky 10.
ansible-kea-dhcp4
Kea DHCPv4 from AppStream: your subnets, pools, options and reservations in Kea's own keys, checked with kea-dhcp4 -t and applied by reload, leases on disk. The live test runs a raw-socket DHCP client in a namespace: an address with router, DNS and lease time, the reserved address for its MAC, and nothing on a segment no subnet covers. Original role, live-tested on Rocky Linux 10.
ansible-libreswan
Libreswan from AppStream: IPsec connections authenticated by a pre-shared key made on the host, negotiated with IKEv2 under the system crypto policy, IKE kept to one address, each connection checked by its keywords and again by pluto. The live test brings a peer in a namespace up, sees the ping cross as ESP only, and is refused with a different key. Original role, live-tested on Rocky Linux 10.