Blame doc/keepalived.conf.SYNOPSIS

Packit c22fc9
This file describe all the Keepalived available keywords. The keepalived.conf
Packit c22fc9
file is compounded by three configurations parts :
Packit c22fc9
Packit c22fc9
    * Globals configurations
Packit c22fc9
    * VRRP configuration
Packit c22fc9
    * LVS configuration
Packit c22fc9
    * BFD configuration
Packit c22fc9
Packit c22fc9
0. Comment string
Packit c22fc9
Packit c22fc9
There is 2 valid comment valid string : # or ! If you want to add comment
Packit c22fc9
in you configuration file use this char.
Packit c22fc9
Packit c22fc9
0.1. Parameter syntax
Packit c22fc9
Packit c22fc9
<BOOL> is one of on|off|true|false|yes|no or omitted which defaults to on
Packit c22fc9
Packit c22fc9
0.2. Conditional configuration and configuration id
Packit c22fc9
Packit c22fc9
The config-id defaults to the first part of the node name as returned by
Packit c22fc9
uname, and can be overridden with the -i or --config-id command line option.
Packit c22fc9
Packit c22fc9
Any configuration line starting with (i.e. before any whitespace) '@' is a
Packit c22fc9
conditional configuration line.  The word immediately following (i.e.
Packit c22fc9
without any space) the '@' character is compared against the config-id,
Packit c22fc9
and if they don't match, the configuration line is ignored.
Packit c22fc9
Packit c22fc9
Alternatively, '@^' is a negative comparison, so if the word immediately
Packit c22fc9
following does NOT match the config-id, the configuration line IS included.
Packit c22fc9
Packit c22fc9
The purpose of this is to allow a single configuration file to be used for
Packit c22fc9
multiple systems, where the only differences are likely to be the router_id,
Packit c22fc9
vrrp instance priorities, and possibly interface names.
Packit c22fc9
Packit c22fc9
For example:
Packit c22fc9
Packit c22fc9
global_defs
Packit c22fc9
{
Packit c22fc9
@main   router_id main_router
Packit c22fc9
@backup router_id backup_router
Packit c22fc9
}
Packit c22fc9
...
Packit c22fc9
vrrp_instance VRRP1 {
Packit c22fc9
    ...
Packit c22fc9
@main    unicast_src_ip 1.2.3.4
Packit c22fc9
@backup  unicast_src_ip 1.2.3.5
Packit c22fc9
@backup2 unicast_src_ip 1.2.3.6
Packit c22fc9
Packit c22fc9
    unicast_peer {
Packit c22fc9
@^main        1.2.3.4
Packit c22fc9
@^backup      1.2.3.5
Packit c22fc9
@^backup2     1.2.3.6
Packit c22fc9
    }
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
If keepalived is invoked with -i main, or if -i is not specified and the node
Packit c22fc9
name is main.SOMETHING, then the router_id will be set to main_router,
Packit c22fc9
if invoked with -i backup, or the node name is backup, then backup_router,
Packit c22fc9
if not invoked with -i and the node name is not main or backup, or with
Packit c22fc9
-i anything else, then the router_id will not be set.
Packit c22fc9
Packit c22fc9
The unicast peers for main will be 1.2.3.5 and 1.2.3.6.
Packit c22fc9
Packit c22fc9
0.3. Scripts
Packit c22fc9
Packit c22fc9
There are three classes of scripts can be configured to be executed.
Packit c22fc9
Packit c22fc9
a. Notify scripts that are run when a vrrp instance or vrrp group changes state,
Packit c22fc9
   or a virtual server quorum changes between up and down.
Packit c22fc9
Packit c22fc9
b. vrrp tracking scripts that will cause vrrp instances to go down it they exit
Packit c22fc9
   a non-zero exist status, or if a weight is specified will add or subtract the
Packit c22fc9
   weight to/from the priority of that vrrp instance.
Packit c22fc9
Packit c22fc9
c. LVS checker misc scripts that will cause a real server to be configured down
Packit c22fc9
   if they exit with a non-zero status.
Packit c22fc9
Packit c22fc9
By default the scripts will be executed by user keepalived_script if that user
Packit c22fc9
exists, or if not by root, but for each script the user/group under which it is
Packit c22fc9
to be executed can be specified.
Packit c22fc9
Packit c22fc9
There are significant security implications if scripts are executed with root
Packit c22fc9
privileges, especially if the scripts themselves are modifiable or replaceable
Packit c22fc9
by a non root user. Consequently, security checks are made at startup to ensure
Packit c22fc9
that if a script is executed by root, then it cannot be modified or replaced by
Packit c22fc9
a non root user.
Packit c22fc9
Packit c22fc9
All scripts should be written so that they will terminate on receipt of a SIGTERM
Packit c22fc9
signal. Scripts will be sent SIGTERM if their parent terminates, or it is a script
Packit c22fc9
the keepalived is awaiting its exit status and it has run for too long.
Packit c22fc9
Packit c22fc9
0.4 include directive
Packit c22fc9
Packit c22fc9
It is possible to include further configuration files from within a configuration
Packit c22fc9
file, and this can be done to any depth.
Packit c22fc9
Packit c22fc9
The format of the include directive is:
Packit c22fc9
include FILENAME
Packit c22fc9
Packit c22fc9
FILENAME can be a fully qualified or relative pathname, and can include wildcards,
Packit c22fc9
including csh style brace expressions such as "{foo/{,cat,dog},bar}" if glob()
Packit c22fc9
supports them.
Packit c22fc9
Packit c22fc9
After opening an included file, the current directory is set to the directory of
Packit c22fc9
the file itself, so any relative paths included from a file are relative to the
Packit c22fc9
directory of the including file itself.
Packit c22fc9
Packit c22fc9
0.5 Parameter substitution
Packit c22fc9
Packit c22fc9
Substitutable parameters can be specified. The format for defining a parameter is:
Packit c22fc9
$PARAMETER=VALUE
Packit c22fc9
where there must be no space before the '=' and only whitespace may preceed to '$'.
Packit c22fc9
Empty values are allowed.
Packit c22fc9
Packit c22fc9
Parameter names can be made up of any combination of A-Za-z0-9 and _, but cannot start
Packit c22fc9
with a digit. Parameter names starting with an underscore should be considered
Packit c22fc9
reserved names that keepalived will define for various pre-defined options.
Packit c22fc9
Packit c22fc9
After a parameter is defined, any occurrence of $PARAMETER followed by
Packit c22fc9
whitespace, or any occurrence of ${PARAMETER} (which need not be followed by
Packit c22fc9
whitespace) will be replaced by VALUE.
Packit c22fc9
Packit c22fc9
Replacement is recursive, so that if a parameter value itself includes a
Packit c22fc9
replaceable parameter, then after the first substitution, the parameter
Packit c22fc9
in the value will then be replaced; the substitution is done at replacement
Packit c22fc9
time and not at definition time, so for example:
Packit c22fc9
Packit c22fc9
$ADDRESS_BASE=10.2.${ADDRESS_BASE_SUB}
Packit c22fc9
$ADDRESS_BASE_SUB=0
Packit c22fc9
    ${ADDRESS_BASE}.100/32
Packit c22fc9
$ADDRESS_BASE_SUB=10
Packit c22fc9
    ${ADDRESS_BASE}.100/32
Packit c22fc9
Packit c22fc9
will produce:
Packit c22fc9
    10.2.0.100/32
Packit c22fc9
    10.2.10.100/32
Packit c22fc9
Packit c22fc9
Note in the above examples the use of both ADDRESS_BASE and ADDRESS_BASE_SUB
Packit c22fc9
required braces ({}) since the parameters were not followed by whitespace
Packit c22fc9
(after the first substitution which produced 10.2.${ADDRESS_BASE_SUB}.100/32
Packit c22fc9
the parameter is still not followed by whitespace).
Packit c22fc9
Packit c22fc9
If a parameter is not defined, it will not be replaced at all, so for
Packit c22fc9
example ${UNDEF_PARAMETER} will remain in the configuration if it is
Packit c22fc9
undefined; this means that existing configuration that contains a '$'
Packit c22fc9
character (for example in a script definition) will not be changed so
Packit c22fc9
long as no new parameter definitions are added to the configuration.
Packit c22fc9
Packit c22fc9
Parameter substitution works in conjunction with conditional configuration.
Packit c22fc9
For example:
Packit c22fc9
@main $PRIORITY=240
Packit c22fc9
@backup $PRIORITY=200
Packit c22fc9
...
Packit c22fc9
vrrp_instance VI_0 {
Packit c22fc9
    priority $PRIORITY
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
will produce:
Packit c22fc9
...
Packit c22fc9
vrrp_instance VI_0 {
Packit c22fc9
    priority 240
Packit c22fc9
}
Packit c22fc9
if the config_id is main.
Packit c22fc9
Packit c22fc9
$IF_MAIN=@main
Packit c22fc9
$IF_MAIN priority 240
Packit c22fc9
Packit c22fc9
will produce
Packit c22fc9
 priority 240
Packit c22fc9
if the config_id is main and nothing if the config_id is not main, although
Packit c22fc9
why anyone would want to use this rather than simply
Packit c22fc9
@main priority 240
Packit c22fc9
is not known.
Packit c22fc9
Packit c22fc9
Multiline definitions are also suppored, but when used there must be nothing on
Packit c22fc9
the line after the parameter name. A multiline definition is specified by ending
Packit c22fc9
each line except the last with a '\' character.
Packit c22fc9
Packit c22fc9
Example:
Packit c22fc9
Packit c22fc9
$INSTANCE= \
Packit c22fc9
vrrp_instance VI_${NUM} { \
Packit c22fc9
    interface eth0.${NUM} \
Packit c22fc9
    use_vmac vrrp${NUM}.1 \
Packit c22fc9
    virtual_router_id 1 \
Packit c22fc9
@high priority 130 \
Packit c22fc9
@low priority 120 \
Packit c22fc9
    advert_int 1 \
Packit c22fc9
    virtual_ipaddress { \
Packit c22fc9
        10.0.${NUM}.254/24 \
Packit c22fc9
    } \
Packit c22fc9
    track_script { \
Packit c22fc9
        offset_instance_${NUM} \
Packit c22fc9
    } \
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
$NUM=0
Packit c22fc9
$INSTANCE
Packit c22fc9
Packit c22fc9
$NUM=1
Packit c22fc9
$INSTANCE
Packit c22fc9
Packit c22fc9
The use of multiline definitions can be nested.
Packit c22fc9
Packit c22fc9
Example:
Packit c22fc9
Packit c22fc9
$RS= \
Packit c22fc9
  real_server 192.168.${VS_NUM}.${RS_NUM} 80 { \
Packit c22fc9
    weight 1 \
Packit c22fc9
    inhibit_on_failure \
Packit c22fc9
    smtp_alert \
Packit c22fc9
    MISC_CHECK { \
Packit c22fc9
	misc_path "${_PWD}/scripts/vs.sh RS_misc.${INST}.${VS_NUM}.${RS_NUM}.0 10.0.${VS_NUM}.4:80->192.168.${VS_NUM}.${RS_NUM}:80" \
Packit c22fc9
    } \
Packit c22fc9
    MISC_CHECK { \
Packit c22fc9
        misc_path "${_PWD}/scripts/vs.sh RS_misc.${INST}.${VS_NUM}.${RS_NUM}.1 10.0.${VS_NUM}.4:80->192.168.${VS_NUM}.${RS_NUM}:80" \
Packit c22fc9
    } \
Packit c22fc9
    notify_up "${_PWD}/scripts/notify.sh RS_notify.${INST}.${VS_NUM}.${RS_NUM} UP 10.0.${VS_NUM}.4:80->192.168.${VS_NUM}.${RS_NUM}:80" \
Packit c22fc9
    notify_down "${_PWD}/scripts/notify.sh RS_notify.${INST}.${VS_NUM}.${RS_NUM} DOWN 10.0.${VS_NUM}.4:80->192.168.${VS_NUM}.${RS_NUM}:80" \
Packit c22fc9
  }
Packit c22fc9
Packit c22fc9
$VS= \
Packit c22fc9
virtual_server 10.0.${VS_NUM}.4 80 { \
Packit c22fc9
  quorum 2 \
Packit c22fc9
  quorum_up "${_PWD}/scripts/notify.sh VS_notify.${INST} UP 10.0.${VS_NUM}.4:80" \
Packit c22fc9
  quorum_down "${_PWD}/scripts/notify.sh VS_notify.${INST} DOWN 10.0.${VS_NUM}.4:80" \
Packit c22fc9
$RS_NUM=1 \
Packit c22fc9
$RS \
Packit c22fc9
$RS_NUM=2 \
Packit c22fc9
$RS \
Packit c22fc9
$RS_NUM=3 \
Packit c22fc9
$RS \
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
$VS_NUM=0
Packit c22fc9
$ALPHA=alpha
Packit c22fc9
$VS
Packit c22fc9
Packit c22fc9
$VS_NUM=1
Packit c22fc9
$ALPHA=
Packit c22fc9
$VS
Packit c22fc9
Packit c22fc9
The above will create 2 virtual servers, each with 3 real servers
Packit c22fc9
Packit c22fc9
Packit c22fc9
0.5.1 Pre-defined definitions
Packit c22fc9
Packit c22fc9
The following pre-defined definitions are defined:
Packit c22fc9
${_PWD}		The directory of the current configuration file
Packit c22fc9
		(this can be changed if using the include directive).
Packit c22fc9
${_INSTANCE}	The instance name (as defined by the -i option, defaults
Packit c22fc9
                  to hostname).
Packit c22fc9
Packit c22fc9
Additional pre-defiend definitions will be added as their need is identified.
Packit c22fc9
It will normally be quite straightforward to add additional pre-defiend
Packit c22fc9
definitions, so if you need one, or have a good idea for one, then raise
Packit c22fc9
an issue at https://github.com/acasson/keepalived/issues requesting it.
Packit c22fc9
Packit c22fc9
0.6 Sequence blocks
Packit c22fc9
Packit c22fc9
A line starting ~SEQ(var, start, step, end) will cause the remainder of the
Packit c22fc9
line to be processed multiple times, with the variable $var set initially to
Packit c22fc9
start, and then $var will be incremented by step repeatedly, terminating when
Packit c22fc9
it is greater than end. step may be omitted, in which case it defaults to 1 or
Packit c22fc9
-1, depending on whether end is greater or less than start. Start may also be
Packit c22fc9
omitted, in which case it defaults to 1 if end > 0 or -1 if end < 0.
Packit c22fc9
Packit c22fc9
For example:
Packit c22fc9
  ~SEQ(SUBNET, 0, 3) ip_address 10.0.$SUBNET.1
Packit c22fc9
would produce:
Packit c22fc9
  ip_address 10.0.0.1
Packit c22fc9
  ip_address 10.0.1.1
Packit c22fc9
  ip_address 10.0.2.1
Packit c22fc9
  ip_address 10.0.3.1
Packit c22fc9
Packit c22fc9
There can be multiple ~SEQ elements on a line, so
Packit c22fc9
  $VI4= \
Packit c22fc9
  vrrp_track_file offset_instance_4.${IF}.${NUM}.${ID} { \
Packit c22fc9
      file "${_PWD}/679/track_files/4.${IF}.${NUM}.${ID}" \
Packit c22fc9
      weight -100 \
Packit c22fc9
  } \
Packit c22fc9
  \
Packit c22fc9
  vrrp_instance vrrp4.${IF}.${NUM}.${ID} { \
Packit c22fc9
      interface bond${IF}.${NUM} \
Packit c22fc9
      use_vmac vrrp4.${IF}.${NUM}.${ID} \
Packit c22fc9
      virtual_router_id ${ID} \
Packit c22fc9
      priority 130 \
Packit c22fc9
      virtual_ipaddress { \
Packit c22fc9
          10.${IF}.${NUM}.${ID}/24 \
Packit c22fc9
      } \
Packit c22fc9
  \
Packit c22fc9
      track_file { \
Packit c22fc9
          offset_instance_4.${IF}.${NUM}.${ID} \
Packit c22fc9
      } \
Packit c22fc9
  }
Packit c22fc9
Packit c22fc9
  ~SEQ(IF,0,7) ~SEQ(NUM,0,31) ~SEQ(ID,1,254) $VI4
Packit c22fc9
Packit c22fc9
will produce 65024 vrrp instances with names from vrrp4.0.0.1 through to
Packit c22fc9
vrrp4.7.31.254.
Packit c22fc9
Packit c22fc9
0.7 Quoted strings
Packit c22fc9
Packit c22fc9
Quoted strings are specified between " characters; more specifically a string
Packit c22fc9
will only end after a quoted string if there is whitespace afterwards. For
Packit c22fc9
example,
Packit c22fc9
"abcd" efg h jkl "mnop"
Packit c22fc9
will be the single string "abcd efg h jkl mnop", i.e. the embedded " characters
Packit c22fc9
are removed.
Packit c22fc9
Packit c22fc9
Quoted strings can also have escaped characters, like the shell. \a, \b, \E, \f,
Packit c22fc9
\n, \r, \t, \v, \nnn and \xXX (where nnn is up to 3 octal digits, and XX is any
Packit c22fc9
sequence of hex digits) and \cC (which produces the control version of
Packit c22fc9
character C) are all supported. \C for any other character C is just
Packit c22fc9
treated as an escaped version of character C, so \\ is a \ character, and
Packit c22fc9
\" will be a " character, but it won't start or terminate a quoted string.
Packit c22fc9
Packit c22fc9
For specifying scripts with parameters, unquoted spaces will separate the
Packit c22fc9
parameters.  If it is required for a parameter to contain a space, it should
Packit c22fc9
be enclosed in single quotes (').
Packit c22fc9
Packit c22fc9
0.8 Configuration file syntax parser
Packit c22fc9
Packit c22fc9
Traditionally the configuration file parser has not been one of the strengths of
Packit c22fc9
keepalived. yukki maintains a project on github that is a keepalived syntax
Packit c22fc9
checker that may be of use. It can be downloaded from https://github.com/yuuki/gokc
Packit c22fc9
Packit c22fc9
1. Globals configurations
Packit c22fc9
Packit c22fc9
This block is divided in 5 sub-blocks :
Packit c22fc9
Packit c22fc9
    * Global definitions
Packit c22fc9
    * Static track groups
Packit c22fc9
    * Static addresses
Packit c22fc9
    * Static rules
Packit c22fc9
    * Static routes
Packit c22fc9
Packit c22fc9
    1.1. Global definitions
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
global_defs {                                 # Block identification
Packit c22fc9
    notification_email {                      # Email address to send alerts to
Packit c22fc9
       <EMAIL ADDRESS>                        # Standard email address
Packit c22fc9
       <EMAIL ADDRESS>
Packit c22fc9
       ...
Packit c22fc9
    }
Packit c22fc9
    notification_email_from <EMAIL ADDRESS>   # Email From dealing with SMTP proto
Packit c22fc9
                                              #   defaults to keepalived@<local host name>
Packit c22fc9
    smtp_server <ADDRESS>|<DOMAIN_NAME> [<PORT>]
Packit c22fc9
                                              # SMTP server IP address or domain name
Packit c22fc9
                                              #  with optional port number (defaults to 25)
Packit c22fc9
    smtp_helo_name <HOST_NAME>                # name to use in HELO messages
Packit c22fc9
                                              #  defaults to local host name
Packit c22fc9
    smtp_connect_timeout <INTEGER>            # Number of seconds timeout connect
Packit c22fc9
                                              #  remote SMTP server
Packit c22fc9
    smtp_alert <BOOL>                         # Sets default state for all smtp_alerts
Packit c22fc9
    smtp_alert_vrrp <BOOL>                    # Sets default state for vrrp smtp_alerts
Packit c22fc9
    smtp_alert_checker <BOOL>                 # Sets default state for checker smtp_alerts
Packit c22fc9
    no_email_faults                           # Don't send smtp alerts for fault conditions
Packit c22fc9
    router_id <STRING>                        # String identifying router
Packit c22fc9
    vrrp_garp_interval <DECIMAL>              # Sets the default interval between Gratuitous ARP
Packit c22fc9
                                              #   (in seconds, resolution microseconds)
Packit c22fc9
    vrrp_gna_interval <DECIMAL>               # Sets the default interval between unsolicited NA
Packit c22fc9
                                              #   (in seconds, resolution microseconds)
Packit c22fc9
    vrrp_mcast_group4 <IPv4 ADDRESS>          # optional, default 224.0.0.18
Packit c22fc9
    vrrp_mcast_group6 <IPv6 ADDRESS>          # optional, default ff02::12
Packit c22fc9
    vrrp_skip_check_adv_addr <BOOL>           # Checking all the addresses in a received VRRP advert can be time consuming.
Packit c22fc9
                                              # Setting this flag means the check won't be carried out if the advert is
Packit c22fc9
                                              # from the same master router as the previous advert received.
Packit c22fc9
                                              # Default: Don't skip.
Packit c22fc9
    default_interface <INTERFACE>             # sets the default interface for static addresses, default eth0
Packit c22fc9
    lvs_sync_daemon <INTERFACE> <VRRP_INSTANCE> [id <SYNC_ID>] [maxlen <LEN>] [port <PORT>] [ttl <TTL>] [group <IP ADDR>]
Packit c22fc9
                                              # Binding interface, vrrp instance and optional
Packit c22fc9
                                              #  syncid (0 to 255) for lvs syncd
Packit c22fc9
                                              #  maxlen (1..65507) maximum packet length
Packit c22fc9
                                              #  port (1..65535) UDP port number to use
Packit c22fc9
                                              #  ttl (1..255)
Packit c22fc9
                                              #  group - multicast group address (IPv4 or IPv6)
Packit c22fc9
                                              # NOTE: maxlen, port, ttl and group are only available on Linux 4.3 or later.
Packit c22fc9
    lvs_timeouts [tcp TO] [tcpfin TO] [udp [TO] # LVS session timeouts
Packit c22fc9
    lvs_flush                                 # flush any existing LVS configuration at startup
Packit c22fc9
    vrrp_garp_master_delay <INTEGER>          # delay in seconds for second set of gratuitous ARP
Packit c22fc9
                                              #  messages after MASTER state transition, default 5.
Packit c22fc9
                                              #  0 means no second set.
Packit c22fc9
    vrrp_garp_master_repeat <INTEGER>         # how many gratuitous ARP messages after MASTER
Packit c22fc9
                                              #  state transition should be sent, default 5
Packit c22fc9
    vrrp_garp_lower_prio_delay <INTEGER>      # delay for second set of gratuitous ARPs after lower
Packit c22fc9
                                              #  priority advert received when MASTER
Packit c22fc9
    vrrp_garp_lower_prio_repeat <INTEGER>     # number of gratuitous ARP messages to send at a time
Packit c22fc9
                                              #  after lower priority advert received when MASTER
Packit c22fc9
    vrrp_garp_master_refresh <INTEGER>        # Periodic delay in seconds sending
Packit c22fc9
                                              #  gratuitous ARP while in MASTER state
Packit c22fc9
                                              #  Default: 0 (no refreshing)
Packit c22fc9
    vrrp_garp_master_refresh_repeat <INTEGER> # how many gratuitous ARP messages should be sent
Packit c22fc9
                                              #  at each periodic repeat
Packit c22fc9
                                              #  Default: one (per period)
Packit c22fc9
    vrrp_lower_prio_no_advert [<BOOL>]        # If a lower priority advert is received, just discard
Packit c22fc9
                                              # it and don't send another advert. This causes adherence
Packit c22fc9
                                              # to the RFCs.
Packit c22fc9
    vrrp_higher_prio_send_advert [<BOOL>]     # If we are master and receive a higher priority
Packit c22fc9
                                              # advert, send an advert (which will be lower priority
Packit c22fc9
                                              # than the other master), before we transition to
Packit c22fc9
                                              # backup. This means that if the other master has
Packit c22fc9
                                              # garp_lower_priority_repeat set, it will resend garp
Packit c22fc9
                                              # messages. This is to get around the problem of their
Packit c22fc9
                                              # having been two simultaneous masters, and the last GARP
Packit c22fc9
                                              # messages seen were from us.
Packit c22fc9
    vrrp_version <INTEGER:2..3>               # Default VRRP version (default 2)
Packit c22fc9
    vrrp_iptables [keepalived_in [keepalived_out]] # default INPUT
Packit c22fc9
                                              # Specifies the iptables chains to add entries to
Packit c22fc9
                                              # If no table names are specied, no entries are added
Packit c22fc9
    vrrp_ipsets ipset4 [ipset6 [ipset_if6]]   # Set the ipset set names to use. If no names are specified,
Packit c22fc9
                                              #   ipsets will not be used. The default ipset4 name is 'keepalived'.
Packit c22fc9
                                              # If ipset6 is not specified, '6' as appended to the ipset4 name.
Packit c22fc9
                                              #   If ipset_if6 is not specified, any trailing '6' from ipset6
Packit c22fc9
                                              #   is removed and '_if6' appended
Packit c22fc9
    vrrp_check_unicast_src                    # Check source address of a unicast packet is a
Packit c22fc9
                                              # unicast peer
Packit c22fc9
    vrrp_strict                               # Enforce strict VRRP protocol compliance. This will prohibit:
Packit c22fc9
                                              #   0 VIPs
Packit c22fc9
                                              #   unicast peers
Packit c22fc9
                                              #   IPv6 addresses in VRRP version 2
Packit c22fc9
                                              # Sets:
Packit c22fc9
                                              #   vrrp_lower_priority_dont_send_advert
Packit c22fc9
                                              #
Packit c22fc9
                                              # The following 4 options can be used if vrrp or checker processes
Packit c22fc9
                                              #   are timing out. This can be seen by a backup vrrp instance becoming
Packit c22fc9
                                              #   master even when the master is still running, due to the master or
Packit c22fc9
                                              #   backup systems being busy, they are not processing the vrrp packets.
Packit c22fc9
    vrrp_priority <INTEGER:-20..19>           # Set the vrrp child process priority (negative values increase priority)
Packit c22fc9
    checker_priority <INTEGER:-20..19>        # Set the checker child process priority
Packit c22fc9
    bfd_priority <INTEGER:-20..19>            # Set the BFD child process priority
Packit c22fc9
    vrrp_no_swap                              # Set the vrrp child process non swappable
Packit c22fc9
    checker_no_swap                           # Set the checker child process non swappable
Packit c22fc9
    bfd_no_swap                               # Set the BFD child process non swappable
Packit c22fc9
    vrrp_rt_priority <INTEGER:1..99>          # Set the vrrp child process to use real-time scheduling at the specified priority
Packit c22fc9
    checker_rt_priority <INTEGER:1..99>       # Set the checker child process to use real-time scheduling at the specified priority
Packit c22fc9
    bfd_rt_priority <INTEGER:1..99>           # Set the BFD child process to use real-time scheduling at the specified  priority
Packit c22fc9
    vrrp_rlimit_rtime <INTEGER>               # Set the limit on CPU time between blocking system calls, in microseconds (default 10000)
Packit c22fc9
    checker_rlimit_rtime <INTEGER>            #   as above
Packit c22fc9
    bfd_rlimit_rtime <INTEGER>                #   as above
Packit c22fc9
                                              #
Packit c22fc9
                                              # If keepalived has been build with SNMP support,
Packit c22fc9
                                              #   the following keywords are available
Packit c22fc9
                                              # Note: keepalived, checker and rfc support can be
Packit c22fc9
                                              #   individually enabled/disabled
Packit c22fc9
    snmp_socket <PROTOCOL>:<ADDRESS>[:<PORT>] # specify socket to use for connecting to SNMP master agent (default unix:/var/agentx/master)
Packit c22fc9
                                              #   (see source module keepalived/vrrp/vrrp_snmp.c for more details)
Packit c22fc9
    enable_snmp_vrrp                          # enable SNMP handling of vrrp element of KEEPALIVED MIB
Packit c22fc9
    enable_snmp_checker                       # enable SNMP handling of checker element of KEEPALIVED MIB
Packit c22fc9
    enable_snmp_rfc                           # enable SNMP handling of RFC2787 and RFC6527 VRRP MIBs
Packit c22fc9
    enable_snmp_rfcv2                         # enable SNMP handling of RFC2787 VRRPv2 MIB
Packit c22fc9
    enable_snmp_rfcv3                         # enable SNMP handling of RFC6527 VRRPv3 MIB
Packit c22fc9
    enable_traps                              # enable SNMP trap generation
Packit c22fc9
                                              #
Packit c22fc9
    enable_dbus                               # enable the DBus interface
Packit c22fc9
    dbus_service_name SERVICE_NAME            # Name of DBus service (default org.keepalived.Vrrp1)
Packit c22fc9
                                              # Useful if you want to run multiple keepalived processes with DBus enabled
Packit c22fc9
                                              #
Packit c22fc9
    script_user USERNAME [GROUPNAME]          # Specify the default username/groupname to run scripts under
Packit c22fc9
                                              # If groupname is not specified, the group of the user is used.
Packit c22fc9
                                              # If this option is not specified, the user defaults to keepalived_script
Packit c22fc9
                                              # if that user exists, otherwise root.
Packit c22fc9
    enable_script_security                    # Don't run scripts configured to be run as root if any part of the path
Packit c22fc9
                                              # is writable by a non-root user.
Packit c22fc9
    notify_fifo FIFO_NAME                     # FIFO to write notify events to
Packit c22fc9
                                              # See vrrp_notify_fifo and lvs_notify_fifo for format of output
Packit c22fc9
                                              # For further details, see the description under vrrp_sync_group see
Packit c22fc9
                                              # doc/samples/sample_notify_fifo.sh for sample usage.
Packit c22fc9
    notify_fifo_script STRING|QUOTED_STRING [username [groupname]]
Packit c22fc9
                                              # script to be run by keepalived to process notify events
Packit c22fc9
                                              # The FIFO name will be passed to the script as the last parameter
Packit c22fc9
    vrrp_notify_fifo FIFO_NAME                # FIFO to write vrrp notify events to (must be different from other FIFO names)
Packit c22fc9
                                              # The string written will be a line of the form: INSTANCE "VI_1" MASTER 100
Packit c22fc9
                                              # and will be terminated with a new line character.
Packit c22fc9
                                              # For further details of the output, see the description under vrrp_sync_group
Packit c22fc9
                                              # and doc/samples/sample_notify_fifo.sh for sample usage.
Packit c22fc9
    vrrp_notify_fifo_script STRING|QUOTED_STRING [username [groupname]]
Packit c22fc9
                                              # script to be run by keepalived to process vrrp notify events
Packit c22fc9
                                              # The FIFO name will be passed to the script as the last parameter
Packit c22fc9
    lvs_notify_fifo FIFO_NAME                 # FIFO to write notify healthchecker events to (must be different from other FIFO names)
Packit c22fc9
                                              # The string written will be a line of the form:
Packit c22fc9
                                              #   VS [192.168.201.15]:tcp:80 {UP|DOWN}
Packit c22fc9
                                              #   RS [1.2.3.4]:tcp:80 [192.168.201.15]:tcp:80 {UP|DOWN}
Packit c22fc9
                                              # and will be terminated with a new line character.
Packit c22fc9
    lvs_notify_fifo_script STRING|QUOTED_STRING [username [groupname]]
Packit c22fc9
                                              # script to be run by keepalived to process healthchecher notify events
Packit c22fc9
                                              # The FIFO name will be passed to the script as the last parameter
Packit c22fc9
    dynamic_interfaces [allow_if_changes]     # Allow configuration to include interfaces that don't exist at startup.
Packit c22fc9
                                              #   This allows keepalived to work with interfaces that may be deleted
Packit c22fc9
                                              #   and restored and also allows virtual and static routes and rules on 
Packit c22fc9
                                              #   VMAC interfaces.
Packit c22fc9
                                              #   allow_if_changes allows an interface to be deleted and recreated with a
Packit c22fc9
                                              #   different type or underlying interface, eg changing from vlan to macvlan
Packit c22fc9
                                              #   or changing a macvlan from eth1 to eth2. This is predominantly used for
Packit c22fc9
                                              #   reporting duplicate VRID errors at startup if allow_if_changes is not set.
Packit c22fc9
Packit c22fc9
                                              # The following options are only needed for large configurations, where either
Packit c22fc9
                                              # keepalived creates a large number of interface, or the system has a large
Packit c22fc9
                                              # number of interface. These options only need using if
Packit c22fc9
                                              # "Netlink: Receive buffer overrun" messages are seen in the system logs.
Packit c22fc9
                                              # If the buffer size needed exceeds the value in /proc/sys/net/core/rmem_max
Packit c22fc9
                                              #  the corresponding force option will need to be set.
Packit c22fc9
    vrrp_netlink_cmd_rcv_bufs BYTES           # Set netlink receive buffer size. This is useful for
Packit c22fc9
    vrrp_netlink_cmd_rcv_bufs_force <BOOL>    #  very large configurations where a large number of interfaces exist, and
Packit c22fc9
    vrrp_netlink_monitor_rcv_bufs BYTES       #  the initial read of the interfaces on the system causes a netlink buffer
Packit c22fc9
    vrrp_netlink_monitor_rcv_bufs_force <BOOL> # overrun.
Packit c22fc9
    lvs_netlink_cmd_rcv_bufs BYTES            #  The vrrp netlink command and monitor socket and the checker command
Packit c22fc9
    lvs_netlink_cmd_rcv_bufs_force <BOOL>     #  and monitor socket buffer sizes can be independently set. 
Packit c22fc9
    lvs_netlink_monitor_rcv_bufs BYTES        #  The force flag means to use SO_RCVBUFFORCE, so that the buffer size can
Packit c22fc9
    lvs_netlink_monitor_rcv_bufs_force <BOOL> #  exceed /proc/sys/net/core/rmem_max.
Packit c22fc9
Packit c22fc9
                                              # When a socket is opened, the kernel configures the max rx buffer size for
Packit c22fc9
                                              # the socket to /proc/sys/net/core/rmem_default. On some systems this can be
Packit c22fc9
                                              # very large, and even generally this can be much larger than necessary.
Packit c22fc9
                                              # This isn't a problem so long as keepalived is reading all queued data from
Packit c22fc9
                                              # it's sockets, but if rmem_default was set sufficiently large, and if for
Packit c22fc9
                                              # some reason keepalived stopped reading, it could consume all system memory.
Packit c22fc9
                                              # The vrrp_rx_bufs_policy allows configuring of the rx bufs size when the
Packit c22fc9
                                              # sockets are opened. If the policy is MTU, the rx buf size is configured
Packit c22fc9
                                              # to the total of interface's MTU * vrrp_rx_bufs_multiplier for each vrrp
Packit c22fc9
                                              # instance using the socket. Likewise, if the policy is ADVERT, then it is
Packit c22fc9
                                              # the total of each vrrp instances advert packet size * multiplier.
Packit c22fc9
                                              # If policy is set to a number, the rx buf size is configured to that number.
Packit c22fc9
    vrrp_rx_bufs_policy [MTU|ADVERT|NUMBER]   # default is to use system default
Packit c22fc9
    vrrp_rx_bufs_multiplier NUMBER            # default 3
Packit c22fc9
Packit c22fc9
    rs_init_notifies			      # Send notifies at startup for real servers that are starting up
Packit c22fc9
    no_checker_emails                         # Don't send an email every time a real server checker changes state;
Packit c22fc9
                                              #   only send email when a real server is added or removed
Packit c22fc9
    umask [NUMBER|BITS]                       # The umask to use for creating files. The number can be specified in hex, octal
Packit c22fc9
                                              #   or decimal. BITS are I{R|W|X}{USR|GRP|OTH}, e.g. IRGRP, separated by '|'s.
Packit c22fc9
                                              #   The default umask is IWGRP | IWOTH. This option cannot override the
Packit c22fc9
                                              #   command-line option.
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
net_namespace NAME                            # Set the network namespace to run in
Packit c22fc9
                                              # The directory /var/run/keepalived will be created as an unshared mount point,
Packit c22fc9
                                              #   for example for pid files.
Packit c22fc9
                                              # syslog entries will have _NAME appended to the ident.
Packit c22fc9
                                              # Note: the namespace cannot be changed on a configuration reload
Packit c22fc9
namespace_with_ipsets                         # ipsets wasn't network namespace aware until Linux 3.13, and so if running with
Packit c22fc9
                                              # an earlier version of the kernel, by default use of ipsets is disabled if using
Packit c22fc9
                                              # a namespace and vrrp_ipsets isn't specified.
Packit c22fc9
                                              # This options overrides the default and allows ipsets to be used
Packit c22fc9
                                              # with a namespace on kernels prior to 3.13.
Packit c22fc9
Packit c22fc9
instance NAME                                 # If multiple instances of keepalived are run in the same namespace, this will
Packit c22fc9
                                              #   create pid files with NAME as part of the file names, in /var/run/keepalived.
Packit c22fc9
                                              # Note: the instance name cannot be changed on a configuration reload
Packit c22fc9
Packit c22fc9
use_pid_dir                                   # Create pid files in /var/run/keepalived
Packit c22fc9
Packit c22fc9
linkbeat_use_polling                          # Use media link failure detection polling fashion
Packit c22fc9
Packit c22fc9
child_wait_time SECS                          # Time for main process to allow for child processes to exit on termination
Packit c22fc9
                                              #   in seconds (default 5). This can be needed for very large configurations.
Packit c22fc9
Packit c22fc9
    1.2. Static track groups
Packit c22fc9
Packit c22fc9
    Static track groups are used to allow vrrp instances to track static addresses,
Packit c22fc9
    routes and rules. If a static address/route/rule specifies a track group, then
Packit c22fc9
    if the address/route/rule is deleted, the vrrp instance will transition to backup,
Packit c22fc9
    or to fault state if the address/route/rule cannot be re-added.
Packit c22fc9
Packit c22fc9
    The syntax for a track group is:
Packit c22fc9
Packit c22fc9
    track_group GROUP1 {
Packit c22fc9
        group {
Packit c22fc9
            VI_1
Packit c22fc9
            VI_2
Packit c22fc9
        }
Packit c22fc9
    }
Packit c22fc9
Packit c22fc9
    1.3. Static addresses
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
static_ipaddress {                            # block identification
Packit c22fc9
                                              # If no dev element is specified, it defaults to the default_interface (default eth0)
Packit c22fc9
					      # The track_group specification refers to a named track_group which lists the vrrp instances which
Packit c22fc9
                                              #   will track the address, i.e. if the address is deleted and cannot be restored the vrrp instances
Packit c22fc9
                                              #    will transition to fault state.
Packit c22fc9
                                              # no_track means that the address will not be reinstated if it is deleted
Packit c22fc9
                                              # Note: the broadcast address may be specified as '-' or '+' to clear or set the host
Packit c22fc9
                                              #       bits of the address.
Packit c22fc9
    <IP ADDRESS>[/<MASK>] [brd <IP ADDRESS>] [dev <STRING>] [scope <SCOPE>] [label <LABEL>] [peer <IP ADDRESS>] [home] [-nodad] [mngtmpaddr] [noprefixroute] [autojoin] [track_group GROUP|no_track]
Packit c22fc9
    <IP ADDRESS>[/<MASK>] ...
Packit c22fc9
    ...
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
SCOPE can take the following values :
Packit c22fc9
    * site
Packit c22fc9
    * link
Packit c22fc9
    * host
Packit c22fc9
    * nowhere
Packit c22fc9
    * global
Packit c22fc9
Packit c22fc9
    1.4. Static rules
Packit c22fc9
Packit c22fc9
static_rules {                                # block identification
Packit c22fc9
                                              # The syntax is that same as for ip rule add, without "ip rule add"
Packit c22fc9
                                              # with the addition of tunnel-id option (except shortened option names
Packit c22fc9
                                              #   aren't supported due to ambiguities).
Packit c22fc9
                                              # For a description of track_group and no_track, see static_addresses
Packit c22fc9
                                              # NOTE: since rules without preferences can be added in different orders
Packit c22fc9
                                              #   due to vrrp instances transitioning from master to backup etc, rules need
Packit c22fc9
                                              #   to have a preference. If a preference is not specified, keepalived will
Packit c22fc9
                                              #   assign one, but it will probably not be what you want.
Packit c22fc9
                                              # If the rule could apply to either IPv4 or IPv6 it will default to IPv4.
Packit c22fc9
                                              #   To force a rule to be IPv6, add the keyword "inet6"
Packit c22fc9
    from 192.168.28.0/24 to 192.168.29.0/26 table small iif p33p1 oif wlan0 tos 22 fwmark 24/12 preference 39 realms 30/20 track_group GROUP1
Packit c22fc9
    to 1:2:3:4:5:6:7:0/112 from 7:6:5:4:3:2::/96 table 6908 uidrange 10000-19999 no_track
Packit c22fc9
    to 1:2:3:4:6:6:7:0/112 from 8:6:5:4:3:2::/96 l3mdev protocol 12 ip_proto UDP sport 10-20 dport 20-30
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
    1.5. Static routes
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
static_routes {                               # block identification
Packit c22fc9
                                              # The syntax is the same as ip route add, without "ip route add"
Packit c22fc9
                                              #   (except shorted option names aren't supported due to ambiguities)
Packit c22fc9
                                              # For a description of track_group and no_track, see static_addresses
Packit c22fc9
                                              # If the route could apply to either IPv4 or IPv6 it will default to IPv4.
Packit c22fc9
                                              #   To force a route to be IPv6, add the keyword "inet6"
Packit c22fc9
    192.168.100.0/24 table 6909 nexthop via 192.168.101.1 dev wlan0 onlink weight 1 nexthop via 192.168.101.2 dev wlan0 onlink weight 2
Packit c22fc9
    192.168.200.0/24 dev p33p1.2 table 6909 tos 0x04 protocol bird scope link priority 12 mtu 1000 hoplimit 100 advmss 101 rtt 102 rttvar 103 reordering 104 window 105 cwnd 106 ssthresh lock 107 realms PQA/0x14 rto_min 108 initcwnd 109 initrwnd 110 features ecn track_group GROUP1
Packit c22fc9
    2001:470:69e9:1:2::4 dev p33p1.2 table 6909 tos 0x04 protocol bird scope link priority 12 mtu 1000 hoplimit 100 advmss 101 rtt 102 rttvar 103 reordering 104 window 105 cwnd 106 ssthresh lock 107 rto_min 108 initcwnd 109 initrwnd 110 features ecn fastopen_no_cookie 1 no_track
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
2. VRRP configuration
Packit c22fc9
Packit c22fc9
This block is divided in 5 sub-blocks:
Packit c22fc9
Packit c22fc9
    * VRRP scripts
Packit c22fc9
    * VRRP track files
Packit c22fc9
    * VRRP track BFDs
Packit c22fc9
    * VRRP synchronization group
Packit c22fc9
    * VRRP gratuitous ARP/NA intervals
Packit c22fc9
    * VRRP instance
Packit c22fc9
Packit c22fc9
    2.1. VRRP scripts
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
vrrp_script <STRING> {          # VRRP script declaration
Packit c22fc9
    script <QUOTED_STRING>      # script to run periodically
Packit c22fc9
    interval <INTEGER>          # run the script this every seconds
Packit c22fc9
    timeout <INTEGER>           # script considered failed after 'timeout' seconds
Packit c22fc9
    weight <INTEGER:-253..253>  # adjust priority by this weight
Packit c22fc9
    fall <INTEGER>              # required number of failures for KO switch
Packit c22fc9
    rise <INTEGER>              # required number of successes for OK switch
Packit c22fc9
    user USERNAME [GROUPNAME]   # specify user/group to run script under
Packit c22fc9
    init_fail                   # assume script initially is in failed state
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
The script will be executed periodically, every <interval> seconds. Its exit
Packit c22fc9
code will be recorded for all VRRP instances which monitor it.
Packit c22fc9
Note that the script will only be executed if at least one VRRP instance
Packit c22fc9
monitors it.
Packit c22fc9
Packit c22fc9
The default weight equals 0, which means that any VRRP instance monitoring
Packit c22fc9
the script will transition to the fault state after <fall> consecutive failures
Packit c22fc9
of the script. After that, <rise> consecutive successes will cause VRRP instances to
Packit c22fc9
leave the fault state, unless they are also in the fault state due to other scripts
Packit c22fc9
or interfaces that they are tracking.
Packit c22fc9
Packit c22fc9
A positive weight means that <rise> successes will add <weight> to the priority of all
Packit c22fc9
VRRP instances which monitor it. On the opposite, a negative weight will be subtracted
Packit c22fc9
from the initial priority in case of <fall> failures.
Packit c22fc9
Packit c22fc9
    2.2. VRRP track files
Packit c22fc9
Packit c22fc9
    The configuration block looks like:
Packit c22fc9
Packit c22fc9
vrrp_track_file <STRING> {      # VRRP track file declaration
Packit c22fc9
    file <QUOTED_STRING>        # file to monitor
Packit c22fc9
    weight <-254..254>          # default weight (default is 1)
Packit c22fc9
    init_file [VALUE] [overwrite] # create the file and/or initialise the value
Packit c22fc9
                                # This causes VALUE (default 0) to be written to
Packit c22fc9
                                # the specified file at startup if the file doesn't
Packit c22fc9
                                # exist, unless overwrite is specified in which case
Packit c22fc9
                                # any existing file contents will be overwritten with
Packit c22fc9
                                # the specified value.
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
The file will be read whenever it is modified. The value in the file
Packit c22fc9
will be recorded for all VRRP instances and sync groups which monitor it.
Packit c22fc9
Note that the file will only be read if at least one VRRP instance or
Packit c22fc9
sync group monitors it.
Packit c22fc9
Packit c22fc9
A value will be read as a number in text from the file.  If the weight
Packit c22fc9
configured against the track_file is 0, a non-zero value in the file will
Packit c22fc9
be treated as a failure status, and a zero value will be treated as
Packit c22fc9
an OK status, otherwise the value will be  multiplied by the weight configured
Packit c22fc9
in the track_file statement. If the result is less than -253 any VRRP
Packit c22fc9
instance or sync group monitoring the script will transition to the fault state
Packit c22fc9
(the weight can be 254 to allow for a negative value being read from the file).
Packit c22fc9
Packit c22fc9
If the vrrp instance or sync group is not the address owner and the result is between
Packit c22fc9
-253 and 253, the result will be added to the initial priority of the VRRP instance
Packit c22fc9
(a negative value will reduce the priority), although the effective priority will
Packit c22fc9
be limited to the range [1,254].
Packit c22fc9
Packit c22fc9
If a vrrp instance using a track_file is a member of a sync group, unless
Packit c22fc9
sync_group_tracking_weight is set on the group weight 0 must be set.
Packit c22fc9
Likewise, if the vrrp instance is the address owner, weight 0 must also be set.
Packit c22fc9
Packit c22fc9
    2.3. BFD Configuration
Packit c22fc9
Packit c22fc9
    This is an implementation of RFC5880 (Bidirectional forwarding detection),
Packit c22fc9
    and this can be configured to work between 2 keepalived instances, but using
Packit c22fc9
    unweighted track_bfds between a master/backup pair of VRRP instances means that
Packit c22fc9
    the VRRP instance will only be able to come up if both VRRP instance are running,
Packit c22fc9
    which somewhat defeats the purpose of VRRP.
Packit c22fc9
Packit c22fc9
    This imlpementation has been tested with OpenBFDD (available at
Packit c22fc9
    https://github.com/dyninc/OpenBFDD).
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
bfd_instance <STRING> {
Packit c22fc9
    neighbor_ip <IP ADDRESS>           # BFD Neighbor IP (synonym neighbour_ip)
Packit c22fc9
    source_ip <IP ADDRESS>             # Source IP to use (optional)
Packit c22fc9
    min_rx <INTEGER>                   # Required min RX interval, in ms
Packit c22fc9
                                       # (default is 10 ms)
Packit c22fc9
    min_tx <INTEGER>                   # Desired min TX interval, in ms
Packit c22fc9
                                       # (default is 10 ms)
Packit c22fc9
    idle_tx <INTEGER>                  # Desired idle TX interval, in ms
Packit c22fc9
                                       # (default is 1000 ms)
Packit c22fc9
    multiplier <INTEGER>               # Number of missed packets after
Packit c22fc9
                                       # which the session is declared down
Packit c22fc9
                                       # (default is 5)
Packit c22fc9
    passive                            # Operate in passive mode (default is active)
Packit c22fc9
    ttl <INTEGER 0..255>               # outgoing IPv4 ttl to use (default 255)
Packit c22fc9
    hoplimit <INTEGER 0..255>          # outgoing IPv6 hoplimit to use (default 64)
Packit c22fc9
    max_hops <INTEGER 0..255>          # maximum reduction of ttl/hoplimit in received packet (default 0)
Packit c22fc9
                                       #   (255 disables hop count checking)
Packit c22fc9
    weight <INTEGER -253..253>         # Default tracking weight
Packit c22fc9
    vrrp|checker                       # Only notify vrrp or checker process. Default is notify both.
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
    2.4. VRRP synchronization group
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
vrrp_sync_group <STRING> {      # VRRP sync group declaration
Packit c22fc9
    group {                     # group of instance to sync together
Packit c22fc9
      <STRING>                  #   a
Packit c22fc9
      <STRING>                  #       set
Packit c22fc9
      ...                       #             of VRRP_Instance string
Packit c22fc9
    }
Packit c22fc9
    global_tracking             # DEPRECATED. Use track_interface, track_script and
Packit c22fc9
                                # track_file on vrrp_sync_groups instead.
Packit c22fc9
    sync_group_tracking_weight  # allow sync groups to use differing weights. This
Packit c22fc9
                                # probably WON'T WORK, but is a replacement for
Packit c22fc9
                                # global_tracking in case different weights were used
Packit c22fc9
                                # across different vrrp instances in the same sync
Packit c22fc9
                                # group.
Packit c22fc9
    track_interface {           # Interfaces state we monitor
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING> weight <INTEGER:-253..253>
Packit c22fc9
      ...
Packit c22fc9
    }
Packit c22fc9
    track_script {              # Scripts state we monitor
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING> weight <INTEGER:-253..253>
Packit c22fc9
      ...
Packit c22fc9
    }
Packit c22fc9
    track_file {                # Files state we monitor
Packit c22fc9
      <STRING>			# weight defaults to value configured in the vrrp_track_file
Packit c22fc9
      <STRING> weight <INTEGER: -254..254>
Packit c22fc9
      ...
Packit c22fc9
    }
Packit c22fc9
    track_bfd {                 # BFD instance we monitor
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING> weight <INTEGER: -253..253>
Packit c22fc9
      ...
Packit c22fc9
    }
Packit c22fc9
Packit c22fc9
                                # The username and groupname specify the user and group
Packit c22fc9
                                # under which the scripts should be run. If username is
Packit c22fc9
                                # specified, the group defaults to the group of the user.
Packit c22fc9
                                # If username is not specified, they default to the
Packit c22fc9
                                # global script_user and script_group
Packit c22fc9
    notify_master <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                # Script to run during MASTER transit
Packit c22fc9
    notify_backup <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                # Script to run during BACKUP transit
Packit c22fc9
    notify_fault <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                # Script to run during FAULT transit
Packit c22fc9
    notify_stop <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                # Script to launch when stopping vrrp
Packit c22fc9
    notify <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                # Script to run during ANY state transit (1)
Packit c22fc9
    smtp_alert <BOOL>           # Send email notification during state transit
Packit c22fc9
                                #   (default no, unless global smtp_alert/smtp_alert_vrrp set)
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
    Synchronization group tracking scripts and files will update
Packit c22fc9
    the status/priority of all VRRP instances which are members of
Packit c22fc9
    the sync group.
Packit c22fc9
Packit c22fc9
(1) The "notify" script is called AFTER the corresponding notify_* script has
Packit c22fc9
    been called, and is given 4 additional arguments following the configured
Packit c22fc9
    arguments:
Packit c22fc9
Packit c22fc9
    $(n-3) = A string indicating whether it's a "GROUP" or an "INSTANCE"
Packit c22fc9
    $(n-2) = The name of said group or instance
Packit c22fc9
    $(n-1) = The state it's transitioning to ("MASTER", "BACKUP", "FAULT" or "STOP")
Packit c22fc9
    $(n)   = The priority value
Packit c22fc9
Packit c22fc9
    $(n-3) and $(n-1) are ALWAYS sent in uppercase, and the possible strings sent are the
Packit c22fc9
    same ones listed above ("GROUP"/"INSTANCE", "MASTER"/"BACKUP"/"FAULT"/"STOP")
Packit c22fc9
    (note: STOP is only applicable to instances)
Packit c22fc9
Packit c22fc9
Important: for a SYNC group to run reliably, it is vital that all instances in
Packit c22fc9
           the group are MASTER or that they are all either BACKUP or FAULT. A
Packit c22fc9
           situation with half instances having higher priority on machine A
Packit c22fc9
           half others with higher priority on machine B will lead to constant
Packit c22fc9
           re-elections. For this reason, when instances are grouped, any
Packit c22fc9
           track scripts/files configured against member VRRP instances will have
Packit c22fc9
           their tracking weights automatically set to zero, in order to avoid
Packit c22fc9
           inconsistent priorities across instances.
Packit c22fc9
Packit c22fc9
(2) The notify fifo output is the same as the last 4 parameters for the "notify"
Packit c22fc9
    script, with the addition of "MASTER_RX_LOWER_PRI" instead of state for an
Packit c22fc9
    instance. This is used if a master needs to set some external state, such as
Packit c22fc9
    setting a secondary IP address when using Amazon AWS; if another keepalived
Packit c22fc9
    has transitioned to master due to a communications break, the lower priority
Packit c22fc9
    instance will have taken over the secondary IP address, and the proper master
Packit c22fc9
    needs to be able to restore it.
Packit c22fc9
Packit c22fc9
    2.5. VRRP gratuitous ARP/NA intervals
Packit c22fc9
Packit c22fc9
    This section allows the setting of delays between sending gratuitous ARPs
Packit c22fc9
    and unsolicited neighbour advertisements. This is intended for when an
Packit c22fc9
    upstream switch is unable to handle being flooded with ARPs/NAs.
Packit c22fc9
Packit c22fc9
    Use interface when the limits apply on the single physical interface.
Packit c22fc9
    Use interfaces when a group of interfaces are linked to the same switch
Packit c22fc9
    and the limits apply to the switch as a whole.
Packit c22fc9
Packit c22fc9
    Note: Only one of interface or interfaces should be used per block.
Packit c22fc9
Packit c22fc9
garp_group {
Packit c22fc9
    garp_interval <DECIMAL>     # Sets the interval between Gratuitous ARP
Packit c22fc9
                                #   (in seconds, resolution microseconds)
Packit c22fc9
    gna_interval <DECIMAL>      # Sets the default interval between unsolicited NA
Packit c22fc9
                                #   (in seconds, resolution microseconds)
Packit c22fc9
    interface <STRING>          # The physical interface to which the intervals apply
Packit c22fc9
    interfaces {                # A list of interfaces across which the delays are
Packit c22fc9
        <STRING>                #   aggregated.
Packit c22fc9
        <STRING>
Packit c22fc9
        ...
Packit c22fc9
    }
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
    If the global vrrp_garp_interval and/or vrrp_gna_interval are set, any
Packit c22fc9
    interfaces that aren't specified in a garp_group will inherit the global
Packit c22fc9
    settings.
Packit c22fc9
Packit c22fc9
    2.6. VRRP instance
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
vrrp_instance <STRING> {                      # VRRP instance declaration
Packit c22fc9
    use_vmac [<NAME>]                         # Use VRRP Virtual MAC, optional NAME of interface
Packit c22fc9
                                              # NOTE: If sysctl net.ipv4.conf.all.rp_filter is set,
Packit c22fc9
                                              # and this vrrp_instance is an IPv4 instance, using
Packit c22fc9
                                              # this option will cause the individual interfaces to be
Packit c22fc9
                                              # updated to the greater of their current setting and
Packit c22fc9
                                              # all.rp_filter, as will default.rp_filter, and all.rp_filter
Packit c22fc9
                                              # will be set to 0.
Packit c22fc9
                                              # The original settings are restored on termination.
Packit c22fc9
    version <INTEGER:2..3>                    # VRRP version to use
Packit c22fc9
    vmac_xmit_base                            # Send/Recv VRRP messages from base
Packit c22fc9
                                              #  interface instead of VMAC interface
Packit c22fc9
    native_ipv6                               # Force instance to use IPv6 (this option is deprecated since
Packit c22fc9
                                              #   the virtual addresses determine whether IPv4 or IPv6 is used)
Packit c22fc9
    state MASTER|BACKUP                       # Start-up default state
Packit c22fc9
    interface <STRING>                        # Binding interface
Packit c22fc9
    accept                                    # Allow a non address-owner to process packets
Packit c22fc9
                                              # destined to VIPs and eVIPs. This is the default
Packit c22fc9
                                              # unless strict mode is set.
Packit c22fc9
    no_accept                                 # Set non-accept mode (default if strict mode)
Packit c22fc9
                                              #
Packit c22fc9
    skip_check_adv_addr [BOOL]                # See description of global vrrp_skip_check_adv_addr, which
Packit c22fc9
                                              # sets the default value. Defaults to vrrp_skip_check_adv_addr
Packit c22fc9
Packit c22fc9
    track_interface {                         # Interfaces state we monitor
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING> weight <INTEGER:-253..253>
Packit c22fc9
      ...
Packit c22fc9
    }
Packit c22fc9
    track_script {                            # Scripts state we monitor
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING> weight <INTEGER:-253..253>
Packit c22fc9
      ...
Packit c22fc9
    }
Packit c22fc9
    track_file {                              # Files state we monitor
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING> weight <INTEGER: -254..254>
Packit c22fc9
      ...
Packit c22fc9
    }
Packit c22fc9
    track_bfd {                               # BFD instance we monitor
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING>
Packit c22fc9
      <STRING> weight <INTEGER: -253..253>
Packit c22fc9
      ...
Packit c22fc9
    }
Packit c22fc9
    dont_track_primary                        # (default unset) ignore VRRP interface faults.
Packit c22fc9
                                              #  useful for cross-connect VRRP config.
Packit c22fc9
    mcast_src_ip <IP ADDRESS>                 # src_ip to use into the VRRP packets
Packit c22fc9
    unicast_src_ip <IP ADDRESS>               # src_ip to use into the VRRP packets (alias to mcast_src_ip)
Packit c22fc9
    track_src_ip                              # if the configured src_ip doesn't exist or is removed
Packit c22fc9
                                              # put the instance into fault state
Packit c22fc9
    unicast_peer {                            # Do not use multicast, instead send VRRP
Packit c22fc9
      <IP ADDRESS>                            #  adverts to following list of ip address
Packit c22fc9
      ...                                     #  in unicast design fashion
Packit c22fc9
    }
Packit c22fc9
    old_unicast_checksum [never]              # The checksum calculation when using VRRPv3 changed after v1.3.6.
Packit c22fc9
                                              #  Setting this flag forces the old checksum algorithm to be used
Packit c22fc9
                                              #  to maintain backward compatibility, although keepalived will
Packit c22fc9
                                              #  attempt to maintain compatibility anyway if it sees an old
Packit c22fc9
                                              #  version checksum. Specifying never will turn off autodetection
Packit c22fc9
                                              #  of old checksums. [This option may not be enabled - check output
Packit c22fc9
                                              #  of `keepalived -v` for OLD_CHKSUM_COMPAT.]
Packit c22fc9
Packit c22fc9
    # The following garp parameters take their defaults from the global config for vrrp_garp_...
Packit c22fc9
    # See their descriptions for the meaning of the parameters.
Packit c22fc9
    garp_master_delay <INTEGER>
Packit c22fc9
    garp_master_repeat <INTEGER>
Packit c22fc9
    garp_lower_prio_delay <INTEGER>
Packit c22fc9
    garp_lower_prio_repeat <INTEGER>
Packit c22fc9
    garp_master_refresh <INTEGER>
Packit c22fc9
    garp_master_refresh_repeat <INTEGER>
Packit c22fc9
Packit c22fc9
    virtual_router_id <INTEGER-1..255>        # VRRP VRID
Packit c22fc9
    priority <INTEGER-1..255>                 # VRRP PRIO
Packit c22fc9
    advert_int <FLOAT>                        # VRRP Advert interval (use default)
Packit c22fc9
Packit c22fc9
    lower_prio_no_advert [<BOOL>]             # If a lower priority advert is received, don't
Packit c22fc9
                                              # send another advert. This causes adherence
Packit c22fc9
                                              # to the RFCs (defaults to global
Packit c22fc9
                                              # vrrp_lower_priority_dont_send_advert).
Packit c22fc9
Packit c22fc9
    higher_prio_send_advert [<BOOL>]          # If we are master and receive a higher priority
Packit c22fc9
                                              # advert, send an advert (which will be lower priority
Packit c22fc9
                                              # than the other master), before we transition to
Packit c22fc9
                                              # backup. This means that if the other master has
Packit c22fc9
                                              # garp_lower_prio_repeat set, it will resend garp
Packit c22fc9
                                              # messages. This is to get around the problem of their
Packit c22fc9
                                              # having been two simultaneous masters, and the last GARP
Packit c22fc9
                                              # messages seen were from us.
Packit c22fc9
Packit c22fc9
    # Note: authentication was removed from the VRRPv2 specification by RFC3768 in 2004.
Packit c22fc9
    #   Use of this option is non-compliant and can cause problems; avoid using if possible,
Packit c22fc9
    #   except when using unicast, when it can be helpful.
Packit c22fc9
    authentication {                          # Authentication block
Packit c22fc9
        auth_type PASS|AH                     # Simple password or IPSEC AH
Packit c22fc9
        auth_pass <STRING>                    # Password string (up to 8 characters)
Packit c22fc9
    }
Packit c22fc9
    # For virutal_ipaddress and virtual_ipaddress_excluded most of the options match the options
Packit c22fc9
    #   of the command ip address add, likewise for virtual_routes and virtual_rules and the
Packit c22fc9
    #   respective ip route/rule add commands. no_track is specific to keepalived and means that the
Packit c22fc9
    #   vrrp_instance will not transition out of master state if the address/route/rule is deleted
Packit c22fc9
    #   and the address/route/rule will not be reinstated until the vrrp instance next transitions
Packit c22fc9
    #   to master.
Packit c22fc9
    # The track_group option only applies to static addresses/routes/rules.
Packit c22fc9
Packit c22fc9
    virtual_ipaddress {                       # VRRP IP addres block
Packit c22fc9
        <IP ADDRESS>[/<MASK>] [brd <IP ADDRESS>] [dev <STRING>] [scope <SCOPE>] [label <LABEL>] [peer <IP ADDRESS>] [home] [-nodad] [mngtmpaddr] [noprefixroute] [autojoin] [no_track]
Packit c22fc9
        <IP ADDRESS>[/<MASK>] ...
Packit c22fc9
        ...
Packit c22fc9
    }
Packit c22fc9
    virtual_ipaddress_excluded {              # VRRP IP excluded from VRRP packets
Packit c22fc9
        <IP ADDRESS>[/<MASK>] [brd <IP ADDRESS>] [dev <STRING>] [scope <SCOPE>] [label <LABEL>] [peer <IP ADDRESS>] [home] [-nodad] [mngtmpaddr] [noprefixroute] [autojoin] [no_track]
Packit c22fc9
        <IP ADDRESS>[/<MASK>] ...
Packit c22fc9
        ...
Packit c22fc9
    }
Packit c22fc9
    promote_secondaries                       # Set the promote_secondaries flag on the interface to stop other
Packit c22fc9
                                              # addresses in the same CIDR being removed when 1 of them is removed
Packit c22fc9
    virtual_routes {                          # VRRP virtual routes
Packit c22fc9
                                              # The syntax is the same as static_routes with the additional option [no_track]
Packit c22fc9
                                              #   and excluding track_group.
Packit c22fc9
    }
Packit c22fc9
    virtual_rules {                           # VRRP virtual rules
Packit c22fc9
                                              # The syntax is the same as static_rules with the additional option [no_track]
Packit c22fc9
                                              #   and excluding track_group.
Packit c22fc9
    }
Packit c22fc9
Packit c22fc9
    nopreempt                                 # Override VRRP RFC preemption default
Packit c22fc9
    preempt_delay <FLOAT>                     # Seconds after startup or seeing a lower priority master
Packit c22fc9
                                              #  until preemption. 0 (default) to 1,000
Packit c22fc9
    strict_mode [<BOOL>]                      # See description of global vrrp_strict
Packit c22fc9
                                              # If vrrp_strict is not specified, it takes the value of vrrp_strict
Packit c22fc9
                                              # If strict_mode without a parameter is specified, it defaults to on
Packit c22fc9
    debug <LEVEL>                             # Debug level. LEVEL is a number in the range 0 to 4.
Packit c22fc9
    notify_master <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                              # Same as vrrp_sync_group
Packit c22fc9
    notify_backup <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                              # Same as vrrp_sync_group
Packit c22fc9
    notify_fault <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                              # Same as vrrp_sync_group
Packit c22fc9
    notify_stop <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                              # Script to launch when stopping vrrp
Packit c22fc9
    notify <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                              # Same as vrrp_sync_group
Packit c22fc9
    notify_master_rx_lower_pri <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                              # Script to run if a master receives a lower priority advert
Packit c22fc9
    smtp_alert <BOOL>                         # Same as vrrp_sync_group
Packit c22fc9
                                              #   (default no, unless global smtp_alert/smtp_alert_vrrp set)
Packit c22fc9
    kernel_rx_buf_size                        # Set socket receive buffer size (see global_defs
Packit c22fc9
                                              #   vrrp_rx_bufs_policy for explanation)
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
SCOPE can take the following values :
Packit c22fc9
    * site
Packit c22fc9
    * link
Packit c22fc9
    * host
Packit c22fc9
    * nowhere
Packit c22fc9
    * global
Packit c22fc9
Packit c22fc9
LABEL is optional and creates a name for the alias. For compatibility with
Packit c22fc9
"ifconfig", it should be of the form <realdev>:<anytext>, for example
Packit c22fc9
eth0:1 for an alias on eth0.
Packit c22fc9
Packit c22fc9
METRIC is optional and specify a route priority.
Packit c22fc9
Packit c22fc9
When a weight is specified in track_interface, instead of setting the vrrp
Packit c22fc9
instance to the FAULT state in case of failure, its priority will be
Packit c22fc9
increased by the weight when the interface is up (for positive weights),
Packit c22fc9
or decreased by the weight's absolute value when the interface is down
Packit c22fc9
(for negative weights). The weight must be comprised between -254 and +254
Packit c22fc9
inclusive. 0 is the default behaviour which means that a failure implies a
Packit c22fc9
FAULT state. The common practice is to use positive weights to count a
Packit c22fc9
limited number of good services so that the server with the highest count
Packit c22fc9
becomes master. Negative weights are better to count unexpected failures
Packit c22fc9
among a high number of interfaces, as it will not saturate even with high
Packit c22fc9
number of interfaces.
Packit c22fc9
Packit c22fc9
The same principle can be applied to track_script entries, except that an
Packit c22fc9
unspecified weight means that the default weight declared in the script
Packit c22fc9
will be used (which itself defaults to 0).
Packit c22fc9
Packit c22fc9
Packit c22fc9
3. LVS configuration
Packit c22fc9
Packit c22fc9
This block is divided in 2 sub-block :
Packit c22fc9
Packit c22fc9
    * Virtual server group
Packit c22fc9
    * Virtual server
Packit c22fc9
    * SSL config
Packit c22fc9
Packit c22fc9
    3.1. Virtual server group
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
virtual_server_group <STRING> {
Packit c22fc9
    <IP ADDRESS> [<PORT>]       # VIP [VPORT]
Packit c22fc9
    <IP ADDRESS> [<PORT>]
Packit c22fc9
    ...
Packit c22fc9
    <IP ADDRESS RANGE> [<PORT>] # VIP range [VPORT]
Packit c22fc9
    <IP ADDRESS RANGE> [<PORT>]
Packit c22fc9
    ...
Packit c22fc9
    fwmark <INTEGER>            # fwmark
Packit c22fc9
    fwmark <INTEGER>
Packit c22fc9
    ...
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
Note:   <IP ADDRESS RANGE> has the form of : XXX.YYY.ZZZ.WWW-VVV, define
Packit c22fc9
        the IP address range starting at WWW and monotonaly incremented by
Packit c22fc9
        one to VVV. Example : 192.168.200.1-10 means .1 to .10 IP addresses.
Packit c22fc9
Packit c22fc9
    3.2. Virtual server
Packit c22fc9
Packit c22fc9
    The configuration block looks like :
Packit c22fc9
Packit c22fc9
    A virtual_server can be either :
Packit c22fc9
    * vip vport declaration
Packit c22fc9
    * fwmark declaration
Packit c22fc9
    * group declaration
Packit c22fc9
Packit c22fc9
    Note: Where an option can be configured for a virtual server, real server,
Packit c22fc9
    and possibly checker, the virtual server setting is the default for real servers,
Packit c22fc9
    and the real server setting is the default for checkers.
Packit c22fc9
Packit c22fc9
    Note 2: Tunnelled real/sorry servers can differ from the address family of
Packit c22fc9
    the virtual server and non tunnelled real/sorry servers, which all have to be the
Packit c22fc9
    same. If a virtual server uses a fwmark, and all the real/sorry servers are
Packit c22fc9
    tunnelled, the address family of the virtual server will be the same as the
Packit c22fc9
    address family of the real/sorry servers if they are all the same, otherwise
Packit c22fc9
    it will default to IPv4 (use ip_family inet6 to override this).
Packit c22fc9
Packit c22fc9
    Note 3: The port for the virtual server can only be omitted if the virtual service
Packit c22fc9
    is persistent.
Packit c22fc9
Packit c22fc9
virtual_server <IP ADDRESS> [<PORT>] {        # VS IP/PORT declaration
Packit c22fc9
virtual_server fwmark <INTEGER>      {        # VS fwmark declaration
Packit c22fc9
virtual_server group <STRING>        {        # VS group declaration
Packit c22fc9
    ip_family inet|inet6                      # Address family
Packit c22fc9
    delay_loop <INTEGER>                      # delay timer for service polling
Packit c22fc9
    lvs_sched rr|wrr|lc|wlc|lblc|sh|mh|dh|fo|ovf|lblcr|sed|nq
Packit c22fc9
                                              # LVS scheduler used
Packit c22fc9
    hashed                                    # Apply hashing
Packit c22fc9
    flag-1                                    # Apply scheduler flag 1
Packit c22fc9
    flag-2                                    # Apply scheduler flag 2
Packit c22fc9
    flag-3                                    # Apply scheduler flag 3
Packit c22fc9
    sh-port                                   # Apply sh-port scheduler flag (only for sh scheduler,
Packit c22fc9
                                              #  same as flag-2 for sh scheduler)
Packit c22fc9
    sh-fallback                               # Apply sh-fallback scheduler flag (only for sh scheduler,
Packit c22fc9
                                              #  same as flag-1 for sh scheduler)
Packit c22fc9
    mh-port                                   # Apply mh-port scheduler flag (only for mh scheduler,
Packit c22fc9
                                              #  same as flag-2 for mh scheduler)
Packit c22fc9
    mh-fallback                               # Apply mh-fallback scheduler flag (only for mh scheduler,
Packit c22fc9
                                              #  same as flag-1 for mh scheduler)
Packit c22fc9
    ops                                       # Apply One-Packet-Scheduling (only for UDP)
Packit c22fc9
    lvs_method NAT|DR|TUN                     # default LVS method to use
Packit c22fc9
    persistence_engine <STRING>               # LVS persistence engine name
Packit c22fc9
    persistence_timeout [<INTEGER>]           # LVS persistence timeout, default 6 minutes
Packit c22fc9
    persistence_granularity <NETMASK>         # LVS granularity mask
Packit c22fc9
    protocol TCP|UDP|SCTP                     # L4 protocol
Packit c22fc9
    ha_suspend                                # If VS IP address is not set, suspend
Packit c22fc9
                                              #  healthcheckers activity
Packit c22fc9
    virtualhost <STRING>                      # Default VirtualHost string to use for
Packit c22fc9
                                              #  HTTP_GET or SSL_GET
Packit c22fc9
Packit c22fc9
    # Assume silently all RSs down and healthchecks
Packit c22fc9
    # failed on start. This helps preventing false
Packit c22fc9
    # positive actions on startup. Alpha mode is
Packit c22fc9
    # disabled by default.
Packit c22fc9
    alpha
Packit c22fc9
Packit c22fc9
    # On daemon shutdown, consider quorum and RS
Packit c22fc9
    # down notifiers for execution, where appropriate.
Packit c22fc9
    # Omega mode is disabled by default.
Packit c22fc9
    omega
Packit c22fc9
Packit c22fc9
    # Minimum total weight of all live servers in
Packit c22fc9
    # the pool necessary to operate VS with no
Packit c22fc9
    # quality regression. Defaults to 1.
Packit c22fc9
    quorum <INT>
Packit c22fc9
Packit c22fc9
    # Tolerate this much weight units compared to the
Packit c22fc9
    # nominal quorum, when considering quorum gain
Packit c22fc9
    # or loss. A flap dampener. Defaults to 0.
Packit c22fc9
    hysteresis <INT>
Packit c22fc9
Packit c22fc9
    # Script to launch when quorum is gained.
Packit c22fc9
    quorum_up <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
Packit c22fc9
    # Script to launch when quorum is lost.
Packit c22fc9
    quorum_down <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
Packit c22fc9
    sorry_server <IP ADDRESS> <PORT>          # RS to add to LVS topology when the
Packit c22fc9
                                              #  quorum isn't achieved.
Packit c22fc9
                                              #  If a sorry server is configured, all
Packit c22fc9
                                              #  real servers will be brought down when
Packit c22fc9
                                              #  the quorum is not achieved.
Packit c22fc9
    sorry_server_inhibit                      # applies inhibit_on_failure behaviour
Packit c22fc9
                                              # to the sorry_server
Packit c22fc9
    sorry_server_lvs_method NAT|DR|TUN        # LVS method to use for sorry server
Packit c22fc9
Packit c22fc9
    retry <INTEGER>                           # number of retries before fail
Packit c22fc9
    delay_before_retry <INTEGER>              # delay before retry (default 1 unless otherwise specified)
Packit c22fc9
    warmup <INTEGER>                          # random delay for maximum N seconds
Packit c22fc9
    delay_loop <INTEGER>                      # delay timer for service polling
Packit c22fc9
    inhibit_on_failure                        # Set weight to 0 on healthchecker failure
Packit c22fc9
    smtp_alert <BOOL>                         # Send email notification when quorum gained/lost
Packit c22fc9
                                              #   (default no, unless global smtp_alert/smtp_alert_checker set)
Packit c22fc9
Packit c22fc9
    real_server <IP ADDRESS> <PORT> {         # RS declaration
Packit c22fc9
        weight <INTEGER>                      # weight to use (default: 1)
Packit c22fc9
        lvs_method NAT|DR|TUN                 # LVS method to use
Packit c22fc9
        notify_up <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                              # Script to launch when
Packit c22fc9
                                              #  healthchecker consider service
Packit c22fc9
                                              #  as up.
Packit c22fc9
        notify_down <STRING>|<QUOTED-STRING> [username [groupname]]
Packit c22fc9
                                              # Script to launch when
Packit c22fc9
                                              #  healthchecker consider service
Packit c22fc9
                                              #  as down.
Packit c22fc9
        uthreshold <INTEGER>                  # maximum number of connections to server
Packit c22fc9
        lthreshold <INTEGER>                  # minimum number of connections to server
Packit c22fc9
        alpha <BOOL>                          # see above
Packit c22fc9
        retry <INTEGER>                       # see above
Packit c22fc9
        delay_before_retry <INTEGER>          # see above
Packit c22fc9
        warmup <INTEGER>                      # see above
Packit c22fc9
        delay_loop <INTEGER>                  # see above
Packit c22fc9
        inhibit_on_failure <BOOL>             # see above
Packit c22fc9
        smtp_alert <BOOL>                     # Send email notification when quorum gained/lost
Packit c22fc9
                                              #   (default yes, unless global smtp_alert/smtp_alert_checker set)
Packit c22fc9
        virtualhost <STRING>                  # Default VirtualHost string to use for
Packit c22fc9
                                              #  HTTP_GET or SSL_GET (overrides
Packit c22fc9
                                              #  virtual_server virtualhost)
Packit c22fc9
Packit c22fc9
        # healthcheckers. Can be multiple of each type
Packit c22fc9
        # HTTP_GET|SSL_GET|TCP_CHECK|SMTP_CHECK|DNS_CHECK|MISC_CHECK|BFD_CHECK
Packit c22fc9
Packit c22fc9
        # All checkers have the following options, except MISC_CHECK which only has alpha onwards,
Packit c22fc9
	#  and BFD_CHECK which has no standard options:
Packit c22fc9
        CHECKER_TYPE {
Packit c22fc9
            connect_ip <IP ADDRESS>           # IP address to connect (default real_server address)
Packit c22fc9
            connect_port <PORT>               # Port to connect (default real_server port)
Packit c22fc9
            bindto <IP ADDRESS>               # IP address to bind to
Packit c22fc9
            bind_if <IFNAME>                  # Interface to bind to; needed if the bindto
Packit c22fc9
                                              #  address is IPv6 link local
Packit c22fc9
            bind_port <PORT>                  # Port to bind to
Packit c22fc9
            connect_timeout <INTEGER>         # Timeout connection
Packit c22fc9
            fwmark <INTEGER>                  # fwmark to set on socket (SO_MARK)
Packit c22fc9
            alpha <BOOL>                      # see above
Packit c22fc9
            retry <INTEGER>                   # number of retries before fail
Packit c22fc9
            delay_before_retry <INTEGER>      # delay before retry (default 1 unless otherwise specified)
Packit c22fc9
            warmup <INTEGER>                  # random delay for maximum N seconds
Packit c22fc9
            delay_loop <INTEGER>              # delay timer for service polling
Packit c22fc9
        }
Packit c22fc9
Packit c22fc9
        # The following options are additional checker specific
Packit c22fc9
Packit c22fc9
        HTTP_GET|SSL_GET {                    # HTTP and SSL healthcheckers
Packit c22fc9
            url {                             # A set of url to test
Packit c22fc9
              path <STRING>                   # Path
Packit c22fc9
              digest <STRING>                 # Digest computed with genhash
Packit c22fc9
              status_code <INTEGER>           # status code returned into the HTTP
Packit c22fc9
                                              #   header. If not specified, then any
Packit c22fc9
                                              #   2xx code is accepted.
Packit c22fc9
              virtualhost <STRING>            # VirtualHost string to use. If not set
Packit c22fc9
                                              #  uses virtualhost from checker or real
Packit c22fc9
                                              #  or virtual_server.
Packit c22fc9
            }
Packit c22fc9
            url {
Packit c22fc9
              path <STRING>
Packit c22fc9
              digest <STRING>
Packit c22fc9
              status_code <INTEGER>
Packit c22fc9
              virtualhost <STRING>
Packit c22fc9
              regex <STRING>                  # Regular expression to search returned
Packit c22fc9
                                              #  data against. A failure to match causes
Packit c22fc9
                                              #  the check to fail.
Packit c22fc9
              regex_no_match                  # Reverse the sense of the match, so a
Packit c22fc9
                                              #  match of the returned text causes the
Packit c22fc9
                                              #  check to fail.
Packit c22fc9
              regex_options <OPTIONS>         # Space separated list of options for regex.
Packit c22fc9
                                              #  See man pcre2api for a description of the options.
Packit c22fc9
                                              #  The following option are supported:
Packit c22fc9
                                              #   allow_empty_class alt_bsux auto_callout caseless
Packit c22fc9
                                              #   dollar_endonly dotall dupnames extended firstline
Packit c22fc9
                                              #   match_unset_backref multiline never_ucp never_utf
Packit c22fc9
                                              #   no_auto_capture no_auto_possess no_dotstar_anchor
Packit c22fc9
                                              #   no_start_optimize ucp ungreedy utf never_backslash_c
Packit c22fc9
                                              #   alt_circumflex alt_verbnames use_offset_limit
Packit c22fc9
              regex_stack <START> <MAX>       # For complicated regular expressions a larger stack
Packit c22fc9
                                              #   may be needed, and this allows the start and maximum
Packit c22fc9
                                              #   sizes in bytes to be specified. For more details see
Packit c22fc9
                                              #   the documentation for pcre2_jit_stack_create()
Packit c22fc9
              regex_min_offset <OFFSET>       # The minimum offset into the returned data to start
Packit c22fc9
                                              #   checking for the regex pattern match. This can save
Packit c22fc9
                                              #   processing time if the returned data is large.
Packit c22fc9
              regex_max_offset <OFFSET>       # The maximum offset into the returned data for the
Packit c22fc9
                                              #   start of the subject match.
Packit c22fc9
            }
Packit c22fc9
            ...
Packit c22fc9
Packit c22fc9
            virtualhost <STRING>              # VirtualHost string to use. If not set
Packit c22fc9
                                              #  uses virtualhost from real or
Packit c22fc9
                                              #  virtual_server.
Packit c22fc9
        }
Packit c22fc9
Packit c22fc9
        SSL_GET {
Packit c22fc9
            enable_sni            # send Server Name Indication during SSL handshake
Packit c22fc9
        }
Packit c22fc9
Packit c22fc9
        TCP_CHECK {                           # TCP healthchecker
Packit c22fc9
            # No additional options
Packit c22fc9
        }
Packit c22fc9
Packit c22fc9
        SMTP_CHECK {                          # SMTP healthchecker
Packit c22fc9
            helo_name <STRING>|<QUOTED-STRING> # Host to use for the HELO request
Packit c22fc9
        }
Packit c22fc9
Packit c22fc9
        DNS_CHECK {                           # DNS healthchecker
Packit c22fc9
            type A|NS|CNAME|SOA|MX|TXT|AAAA   # DNS query type (default SOA)
Packit c22fc9
            name <STRING>                     # Domain name to use for the DNS query
Packit c22fc9
        }
Packit c22fc9
Packit c22fc9
        MISC_CHECK {                          # MISC healthchecker
Packit c22fc9
            misc_path <STRING>|<QUOTED-STRING> # External system script or program
Packit c22fc9
            misc_timeout <INTEGER>            # Script execution timeout
Packit c22fc9
Packit c22fc9
            # If set, exit code from healthchecker is used
Packit c22fc9
            # to dynamically adjust the weight as follows:
Packit c22fc9
            #   exit status 0: svc check success, weight
Packit c22fc9
            #     unchanged.
Packit c22fc9
            #   exit status 1: svc check failed.
Packit c22fc9
            #   exit status 2-255: svc check success, weight
Packit c22fc9
            #     changed to 2 less than exit status.
Packit c22fc9
            #   (for example: exit status of 255 would set
Packit c22fc9
            #     weight to 253)
Packit c22fc9
            # NOTE: do not have more than one dynamic MISC_CHECK per real_server.
Packit c22fc9
            misc_dynamic
Packit c22fc9
            user USERNAME [GROUPNAME]         # Specify user/group to run script under
Packit c22fc9
        }
Packit c22fc9
        BFD_CHECK {
Packit c22fc9
            name <STRING>                     # the name of the bfd instance
Packit c22fc9
        }
Packit c22fc9
    }
Packit c22fc9
}
Packit c22fc9
Packit c22fc9
    3.3. SSL config
Packit c22fc9
Packit c22fc9
    Parameters used for SSL_GET check.
Packit c22fc9
    If none of the parameters is specified, the SSL context will be auto generated.
Packit c22fc9
Packit c22fc9
SSL {
Packit c22fc9
    password <STRING>           # password
Packit c22fc9
    ca <STRING>                 # ca file
Packit c22fc9
    certificate <STRING>        # certificate file
Packit c22fc9
    key <STRING>                # key file
Packit c22fc9
}