LINUXOR.SK ... open source notes ...

Vault - keepalived.conf (virtual address)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Load balancer

noteauth_pass is a shared password in clear text. It is a placeholder here.

The Keepalived configuration of the first load-balancer node. Keepalived holds the virtual address of the cluster on whichever node has a running HAProxy, using VRRP between the two nodes over unicast.

ItemValue
Path on the host/etc/keepalived/keepalived.conf
Shown hereprod-vault-lb1, the MASTER
Deployed onboth load-balancer nodes of every cluster
Virtual address10.10.2.14
Applied withsystemctl restart keepalived

The file

nginx
#------------------------------------------------------------------------------
# File: keepalived.conf
# Description: Keepalived configuration
# Author: admin01
# Date: 2023
#------------------------------------------------------------------------------

#------------------------------------------------------------------------------
# VRRP script to check status of haproxy process
#------------------------------------------------------------------------------
vrrp_script check_haproxy {
    script "/usr/bin/killall -0 haproxy"
    interval 1            # check every second
    fall 2                # require 2 failures for KO
    rise 2                # require 2 successes for OK
}

#------------------------------------------------------------------------------
# VRRP instance for haproxy_service
#------------------------------------------------------------------------------
vrrp_instance haproxy_service {

    # Initial state of this cluster member
    state MASTER

    # Interface for communication
    interface ens160

    # ID of VRRPD instance (0..255)
    virtual_router_id 1

    # Priority of this cluster member
    # For electing MASTER, highest priority wins. To be MASTER, make 50 more than other machines.
    # This cluster member is MASTER = priority 100.
    priority 100

    advert_int 1

    # Keepalived scripts to check status of haproxy process
    track_script {
        check_haproxy
    }

    # Cluster members authentication
    authentication {
        auth_type PASS
        auth_pass <VRRP_PASSWORD>
    }

    # Cluster members
    unicast_src_ip 10.10.2.10      # IP address of local interface
    unicast_peer {                  # IP address of peer interface
        10.10.2.11
    }

    # Virtual IP
    virtual_ipaddress {
        10.10.2.14/32 dev ens160
    }

    # Notification script - storing keepalived transitions
    # Transition to/from MASTER, BACKUP, FAULT states
    notify "/usr/local/bin/keepalived_notify.sh"
}

What changes on the second node

Settinglb1lb2
stateMASTERBACKUP
priority10050
unicast_src_ip10.10.2.1010.10.2.11
unicast_peer10.10.2.1110.10.2.10

Per-environment differences

SettingPRODNONPRODCOMMON
interfaceens160ens192ens160
unicast_src_ip on lb110.10.2.1010.20.2.1010.30.2.10
virtual_ipaddress10.10.2.14/3210.20.2.14/2910.30.2.14/29
script/usr/bin/killall -0 haproxykillall -0 haproxykillall -0 haproxy

Reading it today

← solutionz