|
| 1 | +# radvd |
| 2 | + |
| 3 | +Manage radvd (Router Advertisement Daemon) configuration. |
| 4 | + |
| 5 | +This role provides IPv6 Router Advertisements for network interfaces, enabling |
| 6 | +Stateless Address Autoconfiguration (SLAAC) and/or DHCPv6. |
| 7 | + |
| 8 | +## Privilege escalation |
| 9 | + |
| 10 | +- Package installation |
| 11 | +- Writing in protected locations `/etc/radvd.conf`, `/etc/cifmw-radvd.d` |
| 12 | +- Managing system service `radvd.service` |
| 13 | + |
| 14 | +## Common Parameters |
| 15 | + |
| 16 | +* `cifmw_radvd_basedir`: (String) Configuration fragments directory. Defaults to `/etc/cifmw-radvd.d`. |
| 17 | +* `cifmw_radvd_networks`: (List) List of networks to configure. Defaults to `[]`. |
| 18 | +* `cifmw_radvd_remove_package`: (Bool) Remove the radvd package during cleanup. Defaults to `false`. |
| 19 | + |
| 20 | +## Network Configuration |
| 21 | + |
| 22 | +Each network in `cifmw_radvd_networks` supports the following parameters: |
| 23 | + |
| 24 | +* `name`: (String) Network/interface name. **Required**. |
| 25 | +* `state`: (String) Network status. Must be either `present` or `absent`. Defaults to `present`. |
| 26 | +* `prefixes`: (List[mapping]) List of IPv6 prefixes to advertise. **Required when state is present**. |
| 27 | +* `adv_send_advert`: (Bool) Enable/disable router advertisements. Defaults to `true`. |
| 28 | +* `adv_managed_flag`: (Bool) Managed address configuration flag (M-flag). Indicates DHCPv6 for addresses. |
| 29 | +* `adv_other_config_flag`: (Bool) Other configuration flag (O-flag). Indicates DHCPv6 for other configuration. |
| 30 | +* `adv_ra_solicited_unicast`: (Bool) Enable unicast router advertisements. |
| 31 | +* `adv_link_mtu`: (Int) Advertised MTU for the link. |
| 32 | +* `min_rtr_adv_interval`: (Int) Minimum router advertisement interval in seconds. |
| 33 | +* `max_rtr_adv_interval`: (Int) Maximum router advertisement interval in seconds. |
| 34 | +* `routes`: (List[mapping]) List of routes to advertise. Optional. |
| 35 | +* `rdnss`: (List[mapping]) List of recursive DNS servers to advertise. Optional. |
| 36 | + |
| 37 | +### Prefix mapping |
| 38 | + |
| 39 | +* `network`: (String) IPv6 prefix (e.g., `2001:db8:1::/64`). **Required**. |
| 40 | +* `adv_on_link`: (Bool) On-link flag. Defaults to `true`. |
| 41 | +* `adv_autonomous`: (Bool) Autonomous address configuration flag (SLAAC). Defaults to `true`. |
| 42 | +* `adv_router_addr`: (Bool) Include router address in prefix information. |
| 43 | +* `adv_valid_lifetime`: (String/Int) Valid lifetime for the prefix (e.g., `86400`, `infinity`). |
| 44 | +* `adv_preferred_lifetime`: (String/Int) Preferred lifetime for the prefix. |
| 45 | + |
| 46 | +### Route mapping |
| 47 | + |
| 48 | +* `network`: (String) IPv6 route prefix. **Required**. |
| 49 | +* `adv_route_preference`: (String) Route preference (`low`, `medium`, `high`). |
| 50 | +* `adv_route_lifetime`: (Int) Route lifetime in seconds. |
| 51 | + |
| 52 | +### RDNSS mapping |
| 53 | + |
| 54 | +* `servers`: (List[String]) List of IPv6 DNS server addresses. **Required**. |
| 55 | +* `adv_rdnss_lifetime`: (Int) RDNSS lifetime in seconds. |
| 56 | + |
| 57 | +## Examples |
| 58 | + |
| 59 | +### Basic network with SLAAC only |
| 60 | + |
| 61 | +```yaml |
| 62 | +- name: Configure radvd networks |
| 63 | + vars: |
| 64 | + cifmw_radvd_networks: |
| 65 | + - name: testnet |
| 66 | + adv_managed_flag: false |
| 67 | + adv_other_config_flag: false |
| 68 | + adv_link_mtu: 1500 |
| 69 | + min_rtr_adv_interval: 30 |
| 70 | + max_rtr_adv_interval: 100 |
| 71 | + prefixes: |
| 72 | + - network: "2001:db8:1::/64" |
| 73 | + adv_on_link: true |
| 74 | + adv_autonomous: true |
| 75 | + adv_router_addr: true |
| 76 | + ansible.builtin.include_role: |
| 77 | + name: radvd |
| 78 | +``` |
| 79 | +
|
| 80 | +### Network with DHCPv6 for addresses and other configuration |
| 81 | +
|
| 82 | +```yaml |
| 83 | +- name: Configure radvd with DHCPv6 |
| 84 | + vars: |
| 85 | + cifmw_radvd_networks: |
| 86 | + - name: provisioning |
| 87 | + adv_managed_flag: true |
| 88 | + adv_other_config_flag: true |
| 89 | + adv_ra_solicited_unicast: true |
| 90 | + adv_link_mtu: 1500 |
| 91 | + min_rtr_adv_interval: 30 |
| 92 | + max_rtr_adv_interval: 100 |
| 93 | + prefixes: |
| 94 | + - network: "2001:db8:2::/64" |
| 95 | + adv_on_link: true |
| 96 | + adv_autonomous: false |
| 97 | + rdnss: |
| 98 | + - servers: |
| 99 | + - "2001:db8:2::53" |
| 100 | + adv_rdnss_lifetime: 300 |
| 101 | + ansible.builtin.include_role: |
| 102 | + name: radvd |
| 103 | +``` |
| 104 | +
|
| 105 | +### Multiple networks |
| 106 | +
|
| 107 | +```yaml |
| 108 | +- name: Configure multiple networks |
| 109 | + vars: |
| 110 | + cifmw_radvd_networks: |
| 111 | + - name: net1 |
| 112 | + adv_managed_flag: true |
| 113 | + adv_other_config_flag: true |
| 114 | + adv_link_mtu: 1500 |
| 115 | + min_rtr_adv_interval: 30 |
| 116 | + max_rtr_adv_interval: 100 |
| 117 | + prefixes: |
| 118 | + - network: "2001:db8:1::/64" |
| 119 | + adv_on_link: true |
| 120 | + adv_autonomous: true |
| 121 | + - name: net2 |
| 122 | + adv_managed_flag: false |
| 123 | + adv_other_config_flag: false |
| 124 | + prefixes: |
| 125 | + - network: "2001:db8:2::/64" |
| 126 | + adv_on_link: true |
| 127 | + adv_autonomous: true |
| 128 | + ansible.builtin.include_role: |
| 129 | + name: radvd |
| 130 | +``` |
| 131 | +
|
| 132 | +### Remove a network configuration |
| 133 | +
|
| 134 | +```yaml |
| 135 | +- name: Remove radvd configuration for a network |
| 136 | + vars: |
| 137 | + cifmw_radvd_networks: |
| 138 | + - name: testnet |
| 139 | + state: absent |
| 140 | + ansible.builtin.include_role: |
| 141 | + name: radvd |
| 142 | +``` |
| 143 | +
|
| 144 | +### Adding a single network dynamically |
| 145 | +
|
| 146 | +You can also add a single network using `tasks_from: manage_network.yml`: |
| 147 | + |
| 148 | +```yaml |
| 149 | +- name: Add a single network to radvd |
| 150 | + vars: |
| 151 | + cifmw_radvd_network: |
| 152 | + name: testnet |
| 153 | + adv_managed_flag: true |
| 154 | + adv_other_config_flag: true |
| 155 | + adv_link_mtu: 1500 |
| 156 | + min_rtr_adv_interval: 30 |
| 157 | + max_rtr_adv_interval: 100 |
| 158 | + prefixes: |
| 159 | + - network: "2001:db8:1::/64" |
| 160 | + adv_on_link: true |
| 161 | + adv_autonomous: true |
| 162 | + adv_router_addr: true |
| 163 | + ansible.builtin.include_role: |
| 164 | + name: radvd |
| 165 | + tasks_from: manage_network.yml |
| 166 | +``` |
| 167 | + |
| 168 | +### Cleanup entire radvd service |
| 169 | + |
| 170 | +```yaml |
| 171 | +- name: Cleanup radvd |
| 172 | + vars: |
| 173 | + # Set to true to also remove the radvd package (default: false) |
| 174 | + cifmw_radvd_remove_package: false |
| 175 | + ansible.builtin.include_role: |
| 176 | + name: radvd |
| 177 | + tasks_from: cleanup.yml |
| 178 | +``` |
| 179 | + |
| 180 | +## Understanding the flags |
| 181 | + |
| 182 | +### Managed Flag (M-flag) - `adv_managed_flag` |
| 183 | + |
| 184 | +When set to `true`, hosts should use DHCPv6 to obtain IPv6 addresses (stateful DHCPv6). |
| 185 | +When set to `false`, hosts should use SLAAC (Stateless Address Autoconfiguration) based on the advertised prefix. |
| 186 | + |
| 187 | +### Other Config Flag (O-flag) - `adv_other_config_flag` |
| 188 | + |
| 189 | +When set to `true`, hosts should use DHCPv6 to obtain other configuration information (DNS, NTP, etc.). |
| 190 | + |
| 191 | +### Common configurations |
| 192 | + |
| 193 | +1. **SLAAC only**: `adv_managed_flag: false`, `adv_other_config_flag: false`, `adv_autonomous: true` |
| 194 | +2. **SLAAC + DHCPv6 for options**: `adv_managed_flag: false`, `adv_other_config_flag: true`, `adv_autonomous: true` |
| 195 | +3. **DHCPv6 for everything**: `adv_managed_flag: true`, `adv_other_config_flag: true`, `adv_autonomous: false` |
| 196 | + |
| 197 | +## Notes |
| 198 | + |
| 199 | +- The interface/bridge specified by the `name` parameter must exist before radvd can advertise on it. |
| 200 | +- IPv6 forwarding must be enabled on the host for router advertisements to work properly. |
| 201 | +- Multiple prefixes can be advertised on the same interface. |
| 202 | +- The role uses the system `radvd.service` from the RPM package. |
| 203 | +- Configuration is assembled from fragments in `/etc/cifmw-radvd.d/` into `/etc/radvd.conf`. |
0 commit comments