LINUXOR.SK ... open source notes ...

Email - keepalived.conf (virtual address of the internal pair)

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from High availability and key synchronization

noteauth_pass is a shared password in clear text; it is the placeholder <VRRP_AUTH_PASS> here. Password authentication of VRRP does not protect against anybody who can see the packets.

The Keepalived configuration of the first internal email server. Two process checks, one VRRP instance over unicast, one virtual address in IPv4 and one in IPv6. Keepalived keeps the address on the node whose Postfix and Dovecot are both running.

ItemValue
Path on the server/etc/keepalived/keepalived.conf
Shown hereDC2-A-VCMSX001, the MASTER
Also onDC2-B-VCMSX001, the BACKUP
Virtual address10.12.19.33/28 and 2001:db8:a2:b6f::f:1/64, DNS name dc2-s-xcmsx001.adm.example.net
Runs asroot
Activated withsystemctl start keepalived, systemctl enable keepalived
Stock file kept in/etc/keepalived-original/

The file

nginx
# VRRP script to check status of Postfix master process
vrrp_script check_postfix_master {
    script "killall -0 master"
    interval 1            # check every second
    fall 2                # require 2 failures for KO
    rise 2                # require 2 successes for OK
}

# VRRP script to check status of Dovecot process
vrrp_script check_dovecot {
    script "killall -0 dovecot"
    interval 1            # check every second
    fall 2                # require 2 failures for KO
    rise 2                # require 2 successes for OK
}

# VRRP instance for email_services
vrrp_instance email_services {

    # Initial state of this cluster member
    state MASTER

    # Interface for communication
    interface eth0

    # ID of VRRPD instance (0.255)
    virtual_router_id 1

    # Priority of this cluster member
    # For electing MASTER, highest priority wins. To be MASTER, make 50 more than other machines.
    # This cluster member is MASTER = priority 100.
    priority 100

    advert_int 1

    # Keepalived scripts to check status of Postfix and Dovecot processes
    track_script {
        check_postfix_master
        check_dovecot
    }

    # Cluster members authentication
    authentication {
        auth_type PASS
        auth_pass <VRRP_AUTH_PASS>
    }

    # Cluster members
    unicast_src_ip 10.12.19.41   # IP address of local interface
    unicast_peer {                  # IP address of peer interface
        10.12.19.42
    }

    # Virtual IP
    virtual_ipaddress {
        10.12.19.33/28 dev eth0
        2001:db8:a2:b6f::f:1/64 dev eth0

    }
}

Differences between the hosts

HostLineValue
DC2-A-VCMSX001stateMASTER
DC2-B-VCMSX001stateBACKUP
DC2-A-VCMSX001priority100
DC2-B-VCMSX001priority50
DC2-A-VCMSX001unicast_src_ip10.12.19.41
DC2-B-VCMSX001unicast_src_ip10.12.19.42
DC2-A-VCMSX001unicast_peer10.12.19.42
DC2-B-VCMSX001unicast_peer10.12.19.41

The comment above priority differs accordingly. For site 1 the design gives the same roles and priorities for DC1-A-VCMSX001 and DC1-B-VCMSX001, and the virtual address 10.11.19.33/28 and 2001:db8:a1:b6f::f:1/64 with the name dc1-s-xcmsx001.adm.example.net; I have no configuration file of site 1.

Reading it today

Checked against Keepalived 2.4.3

The file was written for the Keepalived that RHEL 7 shipped; the Source material does not record the version. CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, carry 2.2.8.

As builtToday
vrrp_script with script, interval, fall, rise, no weightKeywords unchanged. weight defaults to 0, and with weight 0 a failing script puts the instance into the fault state
Process check with killall -0Keepalived has vrrp_track_process, which follows processes through the kernel and needs no script; the manual has a section on why not to use pgrep, pidof or killall
No enable_script_security, no script_userScripts run as the user keepalived_script if it exists, otherwise as the user Keepalived runs as. enable_script_security refuses root scripts whose path a non-root user can write
auth_type PASSStill parsed. The manual calls it non-compliant, since authentication was removed from VRRP by RFC 3768 in 2004, and to be avoided "except when using unicast, where it can be helpful". Only the first eight characters of the password are used
No stronger authentication availableKeepalived 2.4.0 (June 2026) added auth_hmac, an HMAC-SHA256 trailer, meant especially for unicast. It is not in the 2.2.8 that CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, carry
IPv4 and IPv6 address in one virtual_ipaddress blockThe manual says all addresses in virtual_ipaddress must be of the same family; a mixture belongs in virtual_ipaddress_excluded. How a 2.x release reacts to the block as built was not tested
unicast_src_ip, unicast_peerUnchanged; check_unicast_src and TTL checks per peer were added
No nopreemptUnchanged; for nopreempt the initial state must not be MASTER
No vrrp_versionDefault is 2, but IPv6 instances use version 3

VRRP itself has no authentication any more: RFC 9568 (2024) says so in as many words. Between two unicast peers the protection is the network path, or auth_hmac once the distribution has a release that knows it.

← solutionz