net-snmp Agent With SNMPv3 Users Only, And Passphrases That Rotate
The net-snmp agent from AppStream answering SNMPv3 only: no community string (the package answers "public" on every address), every user authenticated and encrypted, and users kept in step with their passphrases, so a changed one takes effect where the usual recipe keeps the old. The live test rotates a passphrase and the old one stops working. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-snmpd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [net-snmp Agent With SNMPv3 Users Only, And Passphrases That Rotate](https://www.iac-bazaar.com/catalog/ansible-snmpd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# net-snmp Agent With SNMPv3 Users Only, And Passphrases That Rotate: https://www.iac-bazaar.com/catalog/ansible-snmpd (download from your IaC Bazaar account)
```Preview:
Documentation
snmpd
The net-snmp agent from AppStream answering SNMPv3 only: no community string, every user authenticated and encrypted (SHA-512 and AES-256 by default), a passphrase pair made for each user, and the users kept in step with those passphrases - so changing one takes effect, which net-snmp's usual recipe silently does not. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages snmpd, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The distribution's unit, our configuration. The role installs net-snmp
and net-snmp-utils, writes /etc/snmp/snmpd.conf (root 0600, checked by
running it first) and /etc/sysconfig/snmpd, and enables the package's
snmpd.service. It answers on udp:127.0.0.1:161 and udp6:[::1]:161 by
default; the live test reads the UDP sockets and expects loopback only.
The package answers "public" to anyone. Its snmpd.conf grants the
community public to every source (com2sec notConfigUser default public) on
every address (UDP 0.0.0.0:161): an SNMPv2c get of sysDescr returned the
kernel version (measured). The role defines no community at all, so v1 and v2c
get no answer, and every user must authenticate and encrypt.
A changed passphrase in snmpd.conf does nothing. The common recipe puts
createUser in snmpd.conf. It works once: as snmpd starts it stores the
user's keys in /var/lib/net-snmp/snmpd.conf, and from then on a new passphrase
in snmpd.conf is ignored - the old one keeps working, across restarts - and
deleting the line does not delete the user (measured). The package's own
net-snmp-create-v3-user fails differently: given AES-256 it wrote the
protocol name where the privacy passphrase belongs. The role keeps each user's
passphrases in /etc/snmp/iacbazaar-users/<name> and, after every start, asks
the agent with them; any user it refuses is re-created in the persistent file
(with snmpd stopped, the one place a new passphrase takes effect) and users no
longer listed are removed. snmpd turns the new line into stored keys as it
starts, and the sync refuses to report success while a passphrase is left in
clear. The live test changes the passphrases and finds the new pair accepted
and the old one refused.
A checker, because snmpd has none. An unknown keyword is a warning and a bad value an error, and the agent runs on regardless. The role runs each candidate on a spare loopback port, with SMUX off and a persistent directory of its own, and refuses it on either.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-victoria-logs
VictoriaLogs from the upstream release as a hardened service on loopback. Its JSON-lines endpoint answers 200 and stores nothing when the content type is wrong, so the README names the one it needs. The live test ingests two lines, gets the right one back from LogsQL, and sees an unwritten stream come back empty and bad LogsQL refused. Original role, live-tested on Rocky Linux 10.
ansible-alertmanager
Prometheus Alertmanager from the upstream release (sha256-verified) as a hardened system service on loopback, its cluster gossip listener switched off and its configuration checked by amtool before it lands. The live test posts an alert through the API and reads it back active, held by the default receiver, and expects no 9094 listener at all. Original role, live-tested on Rocky Linux 10.
ansible-alloy
Grafana Alloy from the upstream release (sha256-verified) as a hardened system service on loopback with --disable-reporting, a self-scrape pipeline that proves the collector runs, and its configuration checked by alloy validate before it lands. The live test reads Alloy's own metrics and asks the component API for the scrape component's health. Original role, live-tested on Rocky Linux 10.
ansible-blackbox-exporter
Prometheus Blackbox exporter from the upstream release (sha256-verified) as a hardened system service on loopback with HTTP and TCP modules, checked by --config.check before the file lands. The live test has it probe itself over HTTP and TCP (probe_success 1) and a port with nothing behind it (probe_success 0): it measures, not only answers. Original role, live-tested on Rocky Linux 10.
ansible-cockpit
Cockpit from BaseOS bound to loopback, with logins limited to an admin group through PAM and root refused outright. The live test sees an administrator log in while an ordinary account, a wrong password and root, placed in the admin group to isolate its own rule, are refused, and reads the login banner. Original role, live-tested on Rocky Linux 10.
ansible-fluent-bit
fluent-bit from EPEL, following a log-file glob it re-reads every few seconds and shipping over the Forward protocol, with retries unlimited instead of the default single retry. Its config is checked with --dry-run before it lands. The live test writes a line to a new file and watches it arrive at an aggregator it started. Original role, live-tested on Rocky Linux 10.