Ansible Role linuxfabrik.lfops.chrony¶
This role installs and configures chrony, a NTP daemon. This role configures Chrony
- to act like a client
- by specifying
chrony__allowto act like a NTP-server providing time syncing to other clients
Available since LFOps 2.0.0.
How the Role Behaves¶
- The configuration is fully templated:
/etc/chrony.confon the Red Hat family,/etc/chrony/chrony.confon Debian and Ubuntu, each close to the file the distribution ships. Out-of-band edits are overwritten on the next run (a timestamped backup is kept). - chronyd uses only the sources from
chrony__ntp_poolsandchrony__ntp_servers, by default the time serverntp.metas.chof the Swiss Federal Institute of Metrology (METAS). If both are set to[], the role aborts, since the host would have no time source. The distribution's default pools, time sources from DHCP and, on Debian and Ubuntu,/etc/chrony/sources.dare not used. Ubuntu 26.04 ships its default pools in/etc/chrony/sources.d, where chronyd would prefer them over every source from the inventory. - On Debian and Ubuntu, drop-ins in
/etc/chrony/conf.dare read at the beginning of the deployedchrony.conf, so the role's settings win over a drop-in that sets the same directive. Debian 13 and Ubuntu 26.04 read them at the end of their ownchrony.conf, where a drop-in would win. Directives that add something instead of replacing it still take effect from a drop-in: apool,serverorsourcedirthere adds time sources next to the ones from the inventory, and with thepreferoption chronyd uses only those. Likewise,allowanddenyadd access rules. - The deployed
chrony.confloads no key file, so NTP sources are not authenticated with symmetric keys. RHEL 10's ownchrony.confdoes the same, while RHEL 8 and 9, Debian and Ubuntu load a key file that holds no keys (/etc/chrony.keys,/etc/chrony/chrony.keys).
Tags¶
chrony
- Installs and configures chrony.
- Triggers: chrony service restart (
chronyd.serviceon the Red Hat family,chrony.serviceon Debian and Ubuntu).
chrony:state
- Manages the state of the chrony service.
- Triggers: none.
Optional Role Variables¶
chrony__allow
- A list of subnets which are allowed to access the server as a NTP server. Setting this effectively turns this server into a NTP server.
- Type: List.
- Default:
[]
chrony__bindaddress
- On which address chrony should listen. Can be used to restrict access to a certain address.
- Type: String.
- Default: unset
chrony__binddevice
- To which network interface chrony should bind. Can be used to restrict access to certain interfaces. Note that this does not work with enforcing SELinux. Try using
chrony__bindaddress. - Type: String.
- Default: unset
chrony__ntp_pools
- A list of NTP server pools. Same as
chrony__ntp_servers, except that it is used to specify a pool of NTP servers rather than a single NTP server. A pool name has to resolve to several addresses, of which chronyd uses up to four. Put a hostname with a single address intochrony__ntp_servers, since chronyd keeps resolving a pool name until it gets four sources from it. - Type: List.
- Default:
[]
chrony__ntp_servers
- A list of NTP servers which should be used as a time source. The
iburstoption is always used, meaning chronyd will start with a burst of 4-8 requests in order to make the first update of the clock sooner. - Type: List.
- Default:
['ntp.metas.ch']ifchrony__ntp_poolsis empty, else[] - Deviates from the distributions, which ship public pools: METAS, the Swiss Federal Institute of Metrology, keeps the official time of Switzerland and operates
ntp.metas.ch.
chrony__service_enabled
- Enables or disables the chrony service, analogous to
systemctl enable/disable. - Type: Bool.
- Default:
true
chrony__service_state
- Changes the state of the chrony service, analogous to
systemctl start/stop/restart/reload. - Type: String. One of
reloaded,restarted,started,stopped. - Default:
'started'ifchrony__service_enabledistrue, else'stopped'
Example:
# optional
chrony__allow:
- '192.0.2.0/24' # whole subnet
- '198.51.100.8' # only this address
chrony__bindaddress: '192.0.2.1'
chrony__binddevice: 'eth0'
chrony__ntp_pools:
- 'ch.pool.ntp.org'
chrony__ntp_servers:
- '192.0.2.2'
chrony__service_enabled: true
chrony__service_state: 'started'