Vault - keepalived.conf (virtual address)
Vault Solution · Config document · referenced from Load balancer
note
auth_pass is a shared password in clear text. It is a placeholder here.The Keepalived configuration of the first load-balancer node. Keepalived holds the virtual address of the cluster on whichever node has a running HAProxy, using VRRP between the two nodes over unicast.
| Item | Value |
|---|---|
| Path on the host | /etc/keepalived/keepalived.conf |
| Shown here | prod-vault-lb1, the MASTER |
| Deployed on | both load-balancer nodes of every cluster |
| Virtual address | 10.10.2.14 |
| Applied with | systemctl restart keepalived |
The file
#------------------------------------------------------------------------------ # File: keepalived.conf # Description: Keepalived configuration # Author: admin01 # Date: 2023 #------------------------------------------------------------------------------ #------------------------------------------------------------------------------ # VRRP script to check status of haproxy process #------------------------------------------------------------------------------ vrrp_script check_haproxy { script "/usr/bin/killall -0 haproxy" interval 1 # check every second fall 2 # require 2 failures for KO rise 2 # require 2 successes for OK } #------------------------------------------------------------------------------ # VRRP instance for haproxy_service #------------------------------------------------------------------------------ vrrp_instance haproxy_service { # Initial state of this cluster member state MASTER # Interface for communication interface ens160 # ID of VRRPD instance (0..255) virtual_router_id 1 # Priority of this cluster member # For electing MASTER, highest priority wins. To be MASTER, make 50 more than other machines. # This cluster member is MASTER = priority 100. priority 100 advert_int 1 # Keepalived scripts to check status of haproxy process track_script { check_haproxy } # Cluster members authentication authentication { auth_type PASS auth_pass <VRRP_PASSWORD> } # Cluster members unicast_src_ip 10.10.2.10 # IP address of local interface unicast_peer { # IP address of peer interface 10.10.2.11 } # Virtual IP virtual_ipaddress { 10.10.2.14/32 dev ens160 } # Notification script - storing keepalived transitions # Transition to/from MASTER, BACKUP, FAULT states notify "/usr/local/bin/keepalived_notify.sh" }
What changes on the second node
| Setting | lb1 | lb2 |
|---|---|---|
state | MASTER | BACKUP |
priority | 100 | 50 |
unicast_src_ip | 10.10.2.10 | 10.10.2.11 |
unicast_peer | 10.10.2.11 | 10.10.2.10 |
Per-environment differences
| Setting | PROD | NONPROD | COMMON |
|---|---|---|---|
interface | ens160 | ens192 | ens160 |
unicast_src_ip on lb1 | 10.10.2.10 | 10.20.2.10 | 10.30.2.10 |
virtual_ipaddress | 10.10.2.14/32 | 10.20.2.14/29 | 10.30.2.14/29 |
script | /usr/bin/killall -0 haproxy | killall -0 haproxy | killall -0 haproxy |
Reading it today
- The check proves a process, not a service.
killall -0 haproxysucceeds while HAProxy is running, even if it has no healthy backend. A check against the frontend port or the stats socket would move the address for more kinds of failure. - VRRP password authentication is weak.
auth_type PASSsends the password in clear text and was removed from the VRRP specification in RFC 3768. Unicast peers and a host firewall rule that allows protocol 112 only between the two nodes are the real protection here, and both were in place. - Unqualified script path. Current Keepalived warns about scripts without a full path and wants
enable_script_securitywith a dedicatedscript_user. PROD already used the full path; the other two environments did not. virtual_router_id 1everywhere. With unicast peers this is harmless. On a shared multicast segment three clusters with the same ID would collide.