CARP virtual IPs and pfsync state synchronisation.
A live carp change to {{PENDING_IFACE}} by {{PENDING_ACTOR}} is awaiting confirmation and reverts automatically in {{PENDING_REMAINING}} seconds unless you keep it. If the change broke your connectivity, simply do nothing — the previous carp configuration restores itself.
{{#PENDING_REVERT_FAILED}}CARP election state is dynamic (a lone node is BACKUP/INIT, not instant MASTER) and never a drift signal.
Live status requires JavaScript.
A virtual IP shared between HA peers. The backing interface (carpdev) and vhid must match on both nodes; the carpdev/sync link should be a dedicated/trusted L2.
State synchronisation over a dedicated link. pfsync requires pf enabled and a pass proto pfsync rule on the syncdev; pfsync packets are unauthenticated, so use a trusted/crossover link.
Maintenance demotes this node's whole carp group so a peer takes over. preempt lets a demote/advskew change actually move traffic on a real pair (a box-wide sysctl). On a lone node these change state but do not move traffic (no peer).
You do not have permission to change failover controls (ha:*:write).
{{/WRITE_HA}}The primary node pushes a filtered config bundle (firewall, DNS, DHCP, routing, gateways — never management addresses or carp identity) to the standby over a pinned-certificate, PSK-authenticated link. Pushes are operator-triggered, rate-limited and fully audited. Both peers must have synchronised clocks (NTP).
{{SYNC_PSK_ONCE}}You do not have permission to configure peer sync (ha:sync:write).
{{/WRITE_SYNC}}Your own certificate fingerprint (to paste as the peer's pin on the other node) is on System → TLS.