VIP

Relays point at one address. Health-check HTTP /readyz. Starter HA uses keepalived for UDP. Clients do not need that L2.

Community has no VIP: relays and browsers use the node’s address. Starter three-node HA: relays and browsers use the unused IPv4 keepalived holds on the control-plane subnet. Client VLANs do not need that L2 — relays unicast to the VIP (or to a dhcp-only node at that site). Discover may land on A and Request on B; the lease store is the database. HA. Install prerequisites.

Health checks are HTTP /readyz, never UDP/67.

On the Starter installer path, UDP 67 and UDP 53 are keepalived IPVS; TCP 53 and HTTPS :443 are HAProxy. Do not configure the VIP in netplan.

Trusted relays: LATTICE_TRUSTED_RELAYS comma-separated IPs or CIDRs. Empty drops relayed packets. See Relays.