Configures IPv6 privacy extensions for SLAAC (RFC 4941) in sysctl (Linux kernel attributes) and systemd-networkd.
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2024-12-21 15:21:16 +01:00
defaults Default to not reboot and respect global 2024-11-08 11:48:46 +01:00
handlers add variable to control reboot 2024-08-02 14:09:06 +02:00
meta rename role to ipv6 2024-08-02 12:30:58 +02:00
tasks assert public role variables 2024-08-02 14:37:18 +02:00
vars rename role to ipv6 2024-08-02 12:30:58 +02:00
LICENSE initial commit 2024-06-23 19:56:07 +02:00
README.md markdownlint format + adjust author / license note 2024-12-21 15:21:16 +01:00

Ansible Role: ipv6

This role manages IPv6 configuration for different networking software.

Features

  • Configure IPv6 privacy extensions for SLAAC as defined in RFC 4941 for following tools:
    • Linux kernel (sysctl)
    • systemd-networkd

Requirements

  • When configuring systemd-networkd the minimum version needed it systemd 254. This is because this role sets the option IPv6PrivacyExtensions=yes in /etc/systemd/networkd.conf.d/ipv6-privacy-extensions.conf, which was introduced in systemd 254. Prior to that version the option needed to be set in the configuration files for a single network, e. g. /etc/systemd/network/xyz.network. One notable system, which does run only systemd 242 is Debian 12.

Role Variables

  • ipv6_include_sysctl (boolean), default true. Whether kernel attributes (sysctl) should be configured or not.
  • ipv6_include_systemd_networkd (boolean), default true. Whether systemd-networkd should be configured or not.
  • ipv6_allow_flush_handlers (boolean), default true. Whether the flushing of handlers is allowed by this role or not. Most IPv6 configuration come into effect only after flushing the handlers. This could include a reboot of the system or restart of networking services, depending on the changed made. To activate the new IPv6 configuration as soon as possible the handlers are flushed at the end of this role. Set to false to prevent flushing the handlers prematurely.
  • ipv6_allow_reboot (boolean), default true: Whether this role is allowed to perform a reboot or not. Some changes require a reboot to take effect (e. g. sysctl configuration), so the corresponding tasks trigger a handler to perform a reboot. Set to false to disable automatic reboot.

Dependencies

None.

Example Playbook

- name: Configure IPv6 on all hosts
  hosts: all
  tasks:
    - name: Include role ipv6
      ansible.builtin.include_role:
        name: ipv6
      vars:
        ipv6_allow_reboot: false
        ipv6_allow_flush_handlers: false

This example playbook disables rebooting and flushing of handlers. Keep in mind that you need to take care of reboot or restarting services by yourself then.

License

The Unlicense

Author Information

lingling (Codeberg, GitHub)