咱們經常遇到這樣一些應用環境:客戶端經過訪問nginx,nginx再經過反向代理將後端web server運行的業務反饋給客戶端,可是若是nginx server出現宕機或者其餘bug致使業務不能正常運營,因此爲了避免影響業務正常運營,咱們引進了keepalive+nginx組合,來保證整個系統的高可用。前端
Keepalive+Nginx雙機熱備linux
如圖所示爲總體的拓撲圖:nginx
一.部署前說明:web
(1)系統版本: centos 6.6(64位)vim
(2)角色及ip相關信息:後端
角色名稱 | 網絡ip信息 |
客戶端(CIP) | 10.58.137.203/24 |
Master_DR | eth0:172.51.96.105/24 && eth1:192.168.0.105/24 |
Backup_DR | eth0:172.51.96.119/24 && eth1:192.168.0.119/24 |
VIP | 172.51.96.175/32 |
(3)相關中間件信息centos
keepalive版本信息: keepalived-1.2.15bash
nginx版本信息: nginx1.6.0 (提供http服務)服務器
二.部署操做:網絡
負載均衡器上配置操做
nginx部署:
分別在Master_DR和backup_DR上安裝nginx,操做以下:
1.1相關係統依賴包安裝檢查準備
1.2.1 檢查系統自帶nginx是否安裝
rpm -qa | grep nginx
若有安裝,請使用如下命令卸載相關程序
yum remove nginx -y
1.2.2 安裝編譯nginx須要的依賴包
yum install gcc openssl-devel pcre-devel zlib-devel -y
2.1.1到nginx官網下載nginx軟件,以下所示:
cd ~
wget http://nginx.org/download/nginx-1.8.0.tar.gz
2.1.2 添加運行nginx服務帳號
groupadd -r nginx
useradd -r -g nginx -s /bin/false -M nginx
2.1.3 解壓編譯安裝nginx
cd ~
tar -zxf /root/nginx-1.8.0.tar.gz -C /usr/local/src
./configure \
--prefix=/usr/local/nginx \
--sbin-path=/usr/local/nginx/sbin/nginx \
--conf-path=/etc/nginx/nginx.conf \
--error-log-path=/var/log/nginx/error.log \
--http-log-path=/var/log/nginx/access.log \
--pid-path=/var/run/nginx/nginx.pid \
--lock-path=/var/lock/nginx.lock \
--user=nignx \
--group=nginx \
--with-http_ssl_module \
--with-http_stub_status_module \
--with-http_gunzip_module \
--with-http_gzip_static_module \
--http-client-body-temp-path=/var/tmp/nginx/client/ \
--http-proxy-temp-path=/var/tmp/nginx/proxy/ \
--http-fastcgi-temp-path=/var/tmp/nginx/fastcgi/ \
--http-uwsgi-temp-path=/var/tmp/nginx/uwsgi/ \
--http-scgi-temp-path=/var/tmp/nginx/scgi/ \
--with-pcre
make && make install
2.1.4 使用sed修改nginx的配置文件,指定nginx的運行用戶
sed '3 iuser nginx;' -i /etc/nginx/nginx.conf
修改後,nginx主配置文件內容以下
注意:不修改nginx的運行用戶的話,會報以下錯誤,以下圖所示,
2.1.5 啓動nginx服務
/usr/local/nginx/sbin/nginx
下面就可訪問nginx的主頁面了,以下:
至此,nginx部署就基本OK了!
注:關於nginx服務方式啓動腳本示例請訪問:http://blief.blog.51cto.com/6170059/1690492
Keepalive部署
(1)分別在Master_DR和backup_DR上安裝keepalive,操做以下:
1. 安裝Keepalive所須要的相關依賴包:
# yum install openssl-devel popt-devel libnl-devel kernel-devel -y
2. 編譯安裝keepalive
1.1 keepalived的源碼獲取
keepalived源碼包咱們能夠到keepalived的官網:http://www.keepalived.org/去下載,相關說明文檔亦可在其官網查看,好比keepalived的使用,相關配置說明,這裏演示的版本爲:1.2.15
# cd ~
# wget http://www.keepalived.org/software/keepalived-1.2.15.tar.gz
1.2 編譯安裝keepalived
<--編譯安裝keepalived-->
# ln -s /usr/src/kernels/2.6.32-573.18.1.el6.x86_64/ /usr/src/linux
# tar zxvf keepalived-1.2.15.tar.gz -C /usr/local/src
# cd /usr/local/src/keepalived-1.2.15/
# ./configure \
--prefix=/usr/local/keepalived \
--with-kernel-dir=/usr/src/kernels/2.6.32-573.18.1.el6.x86_64
# make make install
<--對keepalived進行相關路徑優化調整-->
<---拷貝keepalived相關啓動命令--->
# cp /usr/local/keepalived/sbin/keepalived /usr/sbin/
# cp /usr/local/keepalived/etc/sysconfig/keepalived /etc/sysconfig/
<---將keepalived啓動腳本添加到系統服務--->
# cp /usr/local/keepalived/etc/rc.d/init.d/keepalived /etc/init.d/
# chkconfig --add keepalived
# chkconfig --level 2345 keepalived on
<---建立keepalived相關配置文件--->
# mkdir -p /etc/keepalived
# cp /usr/local/keepalived/etc/keepalived/keepalived.conf /etc/keepalived
(3)分別配置Master_DR以及Backup_DR上的keepalive實例,以下所示:
1. Lvs_master_dr配置代碼示例(主調度器)
vim /etc/keepalived/keepalived.conf
內容以下
! Configuration File for keepalived global_defs { notification_email { admin@bluemobi.cn } notification_email_from lvs_admin@bluemobi.cn smtp_server 127.0.0.1 smtp_connect_timeout 30 router_id DR_MASTER } vrrp_script check_nginx { #表示建立一個腳本check_nginx script "/etc/keepalived/scripts/check_nginx.sh" #引用的腳本路徑 interval 3 #表示檢測時間的間隔爲3s } vrrp_instance http { state BACKUP interface eth0 lvs sync daemon interface eth0 #相似HA心跳檢測的端口 dont_track_primary nopreempt #不搶佔master track_interface { #表示須要檢測的網卡 eth0 eth1 } mcast_src_ip 172.51.96.105 #表示設置組播的源地址 garp_master_delay 6 virtual_router_id 60 priority 110 advert_int 1 authentication { auth_type PASS autp_pass 1234 } virtual_ipaddress { 172.51.96.175/24 brd 172.51.96.255 dev eth0 label eth0:1 } virtual_routes { 172.51.96.175/24 dev eth0 } track_script { check_nginx } notify_master /etc/keepalived/scripts/state_master.sh notify_backup /etc/keepalived/scripts/state_backup.sh notify_fault /etc/keepalived/scripts/state_fault.sh }
2 Lvs_backup_dr配置示例(備調度器)
vim /etc/keepalived/keepalived.conf
內容以下
! Configuration File for keepalived global_defs { notification_email { admin@bluemobi.cn } notification_email_from lvs_admin@bluemobi.cn smtp_server 127.0.0.1 smtp_connect_timeout 30 router_id DR_BACKUP } vrrp_script check_nginx { script "/etc/keepalived/scripts/check_nginx.sh" interval 3 } vrrp_instance http { state BACKUP interface eth0 lvs sync daemon interface eth0 dont_track_primary track_interface { eth0 eth1 } mcast_src_ip 172.51.96.119 garp_master_delay 6 virtual_router_id 60 priority 105 advert_int 1 authentication { auth_type PASS autp_pass 1234 } virtual_ipaddress { 172.51.96.175/24 brd 172.51.96.255 dev eth0 label eth0:1 } virtual_routes { 172.51.96.175/24 dev eth0 } track_script { check_nginx } notify_master /etc/keepalived/scripts/state_master.sh notify_backup /etc/keepalived/scripts/state_backup.sh notify_fault /etc/keepalived/scripts/state_fault.sh }
3.分別在主調度server和備調度server編寫如下腳本,以下:
i 當調度器爲切換master server時,記錄切換時間日誌
vim /etc/keepalived/scripts/state_master.sh
代碼以下:
#!/bin/bash echo -e >> $LOGFILE host=CN-SH-DR01 #設置當前的主機名 LOGFILE="/var/log/keepalived-state.log" echo "[Master]" >> $LOGFILE date >> $LOGFILE echo "The ${host} Starting to become master server...." >> $LOGFILE 2>&1 echo "Please run the 「ipvsadm -Ln」 check the keepalived state ..." >> $LOGFILE echo ".........................................................................!">> $LOGFILE echo >>$LOGFILE
ii 當調度器爲切換backup server時,記錄切換時間日誌
vim /etc/keepalived/scripts/state_backup.sh
代碼以下:
#!/bin/bash echo -e >> $LOGFILE host=CN-SH-DR01 #設置當前的主機名 LOGFILE="/var/log/keepalived-state.log" echo "[Backup]" >> $LOGFILE date >> $LOGFILE echo "The ${host} Starting to become Backup server...." >> $LOGFILE 2>&1 echo "Please run the 「ipvsadm -Ln」 check the state ..." >> $LOGFILE echo "........................................................................!">> $LOGFILE echo >> $LOGFILE
iii 當調度器出現錯誤時,記錄錯誤時間日誌
vim /etc/keepalived/scripts/state_fault.sh
代碼以下:
#!/bin/bash echo -e >> $LOGFILE host=CN-SH-DR01 #設置當前的主機名 LOGFILE="/var/log/keepalived-state.log" echo "[fault errot ]" >> $LOGFILE date >> $LOGFILE echo "The ${host} is fault error...." >> $LOGFILE 2>&1 echo "Please check the server state ..." >> $LOGFILE echo "........................................................................!">> $LOGFILE echo >> $LOGFILE
iiii 服務狀態健康監測腳本,好比當nginx不可用時,及時切換到backup調度器上
vim /etc/keepalived/scripts/check_nginx.sh
#!/bin/bash #nginx="/usr/local/nginx/sbin/nginx" PID=`ps -C nginx --no-heading|wc -l` if [ "${PID}" = "0" ]; then /etc/init.d/nginx start sleep 3 LOCK=`ps -C nginx --no-heading|wc -l` if [ "${LOCK}" = "0" ]; then /etc/init.d/keepalived stop fi fi
(4)依次重啓master_dr,backup-dr上keepalive服務
# service keepalived restart
三.測試驗證:
在兩臺調度器建立相關測試頁,以下:
master-dr主調度服務器的測試頁面
[root@master-dr www]# curl 172.51.96.105 this is master server [root@master-dr www]#
backup-dr主調度服務器的測試頁面
[root@backup-dr htdocs]# curl 127.0.0.1
this is backup server [root@backup-dr htdocs]#
經過messages查看vip搶奪狀況,以下所示:
述上發現vip已經被master-dr搶奪,經過ifconfig看到master-dr已經存在vip地址,以下
在客戶端經過:http://vip 就能夠訪問到頁面,此時訪問的是master-dr的頁面:
將nginx的啓動命令:/usr/local/nginx/sbin/nginx命名爲:/usr/local/nginx/sbin/nginx1,再關閉nginx來模仿nginx服務故障
分別查看master-dr和backup-dr的keepalive日誌:
此時vip已經由backup-dr接管了,由於master-dr上nginx服務異常,而keepalive會定時觸發引用的檢查腳本「check_nginx」檢查nginx狀態,發現nginx可用就中止了keepalive服務,從而使vip順利的飄逸到backup-dr上;
查看keepalive-state.log,能夠看到master-dr和backup-dr會記錄每一個狀態的的信息:同時日誌記錄腳本也會記錄相關信息:
[root@master-dr sbin]# tail -10 /var/log/keepalived-state.log The CN-SH-DR01 Starting to become Backup server.... Please run the 「ipvsadm -Ln」 check the state ... ...............................................................................! [fault errot ] Fri Mar 11 15:28:48 CST 2016 The CN-SH-DR01 is fault error.... Please check the server state ... ...............................................................................!
[root@backup-dr htdocs]# tail -10 /var/log/keepalived-state.log [Backup] Fri Mar 11 14:42:56 CST 2016 The CN-SH-DR02 Starting to become Backup server.... Please run the 「ipvsadm -Ln」 check the state ... ...............................................................................! [Master] Fri Mar 11 15:06:58 CST 2016 The CN-SH-DR02 Starting to become master server.... Please run the 「ipvsadm -Ln」 check the state ... ...............................................................................!
再次訪問http://vip 發現頁面爲backup-dr的頁面:
到這裏,整個keepalive+nginx雙機熱備就部署完成了
總結:關於keepalive+nginx雙機熱備適合不少web前端高可用集羣應用,相對於keepalive+lvs案例應用,配置起來更方便,更簡單,與它一樣的經典應用案例:keepalive+haproxy也是一個不錯的雙機熱備方案,好比在不少反向代理場景,每每須要根據業務應用來選擇這兩個應用組合!