Email - keepalived.conf (virtual address of the internal pair)
Email Solution · Config document · referenced from High availability and key synchronization
auth_pass is a shared password in clear text; it is the placeholder <VRRP_AUTH_PASS> here. Password authentication of VRRP does not protect against anybody who can see the packets.The Keepalived configuration of the first internal email server. Two process checks, one VRRP instance over unicast, one virtual address in IPv4 and one in IPv6. Keepalived keeps the address on the node whose Postfix and Dovecot are both running.
| Item | Value |
|---|---|
| Path on the server | /etc/keepalived/keepalived.conf |
| Shown here | DC2-A-VCMSX001, the MASTER |
| Also on | DC2-B-VCMSX001, the BACKUP |
| Virtual address | 10.12.19.33/28 and 2001:db8:a2:b6f::f:1/64, DNS name dc2-s-xcmsx001.adm.example.net |
| Runs as | root |
| Activated with | systemctl start keepalived, systemctl enable keepalived |
| Stock file kept in | /etc/keepalived-original/ |
The file
# VRRP script to check status of Postfix master process vrrp_script check_postfix_master { script "killall -0 master" interval 1 # check every second fall 2 # require 2 failures for KO rise 2 # require 2 successes for OK } # VRRP script to check status of Dovecot process vrrp_script check_dovecot { script "killall -0 dovecot" interval 1 # check every second fall 2 # require 2 failures for KO rise 2 # require 2 successes for OK } # VRRP instance for email_services vrrp_instance email_services { # Initial state of this cluster member state MASTER # Interface for communication interface eth0 # ID of VRRPD instance (0.255) virtual_router_id 1 # Priority of this cluster member # For electing MASTER, highest priority wins. To be MASTER, make 50 more than other machines. # This cluster member is MASTER = priority 100. priority 100 advert_int 1 # Keepalived scripts to check status of Postfix and Dovecot processes track_script { check_postfix_master check_dovecot } # Cluster members authentication authentication { auth_type PASS auth_pass <VRRP_AUTH_PASS> } # Cluster members unicast_src_ip 10.12.19.41 # IP address of local interface unicast_peer { # IP address of peer interface 10.12.19.42 } # Virtual IP virtual_ipaddress { 10.12.19.33/28 dev eth0 2001:db8:a2:b6f::f:1/64 dev eth0 } }
Differences between the hosts
| Host | Line | Value |
|---|---|---|
DC2-A-VCMSX001 | state | MASTER |
DC2-B-VCMSX001 | state | BACKUP |
DC2-A-VCMSX001 | priority | 100 |
DC2-B-VCMSX001 | priority | 50 |
DC2-A-VCMSX001 | unicast_src_ip | 10.12.19.41 |
DC2-B-VCMSX001 | unicast_src_ip | 10.12.19.42 |
DC2-A-VCMSX001 | unicast_peer | 10.12.19.42 |
DC2-B-VCMSX001 | unicast_peer | 10.12.19.41 |
The comment above priority differs accordingly. For site 1 the design gives the same roles and priorities for DC1-A-VCMSX001 and DC1-B-VCMSX001, and the virtual address 10.11.19.33/28 and 2001:db8:a1:b6f::f:1/64 with the name dc1-s-xcmsx001.adm.example.net; I have no configuration file of site 1.
Reading it today
- The checks prove a process, not a service.
killall -0 mastersucceeds as long as a process calledmasterexists, whether or not it answers on port 25. - The check scripts have no path.
killallis found through thePATHof the daemon. - No
weight, nonopreempt. A failed check puts the instance into the fault state and the address leaves the node; when the checks pass again, node A takes the address back because its priority is higher. virtual_router_id 1. With unicast peers the id only has to agree between the two nodes.- No
notifyscript. Transitions are only in the system log.
Checked against Keepalived 2.4.3
The file was written for the Keepalived that RHEL 7 shipped; the Source material does not record the version. CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, carry 2.2.8.
| As built | Today |
|---|---|
vrrp_script with script, interval, fall, rise, no weight | Keywords unchanged. weight defaults to 0, and with weight 0 a failing script puts the instance into the fault state |
Process check with killall -0 | Keepalived has vrrp_track_process, which follows processes through the kernel and needs no script; the manual has a section on why not to use pgrep, pidof or killall |
No enable_script_security, no script_user | Scripts run as the user keepalived_script if it exists, otherwise as the user Keepalived runs as. enable_script_security refuses root scripts whose path a non-root user can write |
auth_type PASS | Still parsed. The manual calls it non-compliant, since authentication was removed from VRRP by RFC 3768 in 2004, and to be avoided "except when using unicast, where it can be helpful". Only the first eight characters of the password are used |
| No stronger authentication available | Keepalived 2.4.0 (June 2026) added auth_hmac, an HMAC-SHA256 trailer, meant especially for unicast. It is not in the 2.2.8 that CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, carry |
IPv4 and IPv6 address in one virtual_ipaddress block | The manual says all addresses in virtual_ipaddress must be of the same family; a mixture belongs in virtual_ipaddress_excluded. How a 2.x release reacts to the block as built was not tested |
unicast_src_ip, unicast_peer | Unchanged; check_unicast_src and TTL checks per peer were added |
No nopreempt | Unchanged; for nopreempt the initial state must not be MASTER |
No vrrp_version | Default is 2, but IPv6 instances use version 3 |
VRRP itself has no authentication any more: RFC 9568 (2024) says so in as many words. Between two unicast peers the protection is the network path, or auth_hmac once the distribution has a release that knows it.