Keepalived起初是專門針對LVS設計的一款強大的輔助工具,主要用來提供故障切換(Failover)和健康檢查(Health Checking)功能——判斷LVS負載調度器、節點服務器的可用性,及時隔離並替換爲新的服務器,當故障主機恢復後將其從新加入羣集。html
lvs是一個在四層上實現後端realserver的負載均衡的集羣,lvs遺留下兩個問題,一個是lvs的單點故障;第二個是lvs不能檢測後端realserver的健康狀態檢查。
解決lvs的單點故障就用到了高可用集羣:web
解決lvs不能檢測後端realserver的健康狀態也後不少種方法:shell
名稱 | 操做系統 | IP地址 |
---|---|---|
Master | CentOS7 | 192.168.100.201(VIP:192.168.100.10) |
Backup | CentOS7 | 192.168.100.202(VIP:192.168.100.10) |
Apache1 | CentOS7 | 192.168.100.221(VIP:192.168.100.10) |
Apache2 | CentOS7 | 192.168.100.222(VIP:192.168.100.10) |
Realserver | Win7 | 192.168.100.50(網關:192.168.100.10) |
#yum install keepalived ipvsadm –y //安裝keepalived和ipvsadm服務 #vi /etc/sysctl.conf net.ipv4.ip_forward=1 //開啓路由轉發功能 net.ipv4.conf.all.send_redirects = 0 //關閉重定向功能 net.ipv4.conf.default.send_redirects = 0 net.ipv4.conf.ens33.send_redirects = 0 #sysctl –p //使服務生效
#cd /etc/sysconfig/network-scripts/ #cp ifcfg-ens33 ifcfg-ens33:0 //建立虛擬網卡 #vim ifcfg-ens33:0 DEVICE=ens33:0 //網卡名稱 ONBOOT=yes //網卡可用 IPADDR=192.168.100.10 //IP地址 NETMASK=255.255.255.0 //子網掩碼 #service network restart #ifup ens33:0 //開啓網卡
#vim /etc/init.d/dr.sh //配置DR模式腳本文件 #!/bin/bash GW=192.168.100.1 //網關地址 VIP=192.168.100.10 //虛擬網卡地址 RIP1=192.168.100.201 //節點服務器1IP地址 RIP2=192.168.100.202 //節點服務器2IP地址 case "$1" in start) /sbin/ipvsadm --save > /etc/sysconfig/ipvsadm systemctl start ipvsadm //啓用LVS工具 /sbin/ifconfig ens33:0 $VIP broadcast $VIP netmask 255.255.255.255 broadcast $VIP up //開啓虛擬網卡 /sbin/route add -host $VIP dev ens33:0 //配置路由段 /sbin/ipvsadm -A -t $VIP:80 -s rr /sbin/ipvsadm -a -t $VIP:80 -r $RIP1:80 -g /sbin/ipvsadm -a -t $VIP:80 -r $RIP2:80 -g echo "ipvsadm starting --------------------[ok]" //啓動完提示信息 ;; stop) /sbin/ipvsadm –C //清空LVS systemctl stop ipvsadm ifconfig ens33:0 down //關閉端口 route del $VIP echo "ipvsamd stoped----------------------[ok]" ;; status) if [ ! -e /var/lock/subsys/ipvsadm ];then echo "ipvsadm stoped---------------" exit 1 else echo "ipvsamd Runing ---------[ok]" fi ;; *) echo "Usage: $0 {start|stop|status}" exit 1 esac exit 0 #chmod +x dr.sh //給予執行權限 #service dr.sh start //開啓DR模式
#vim /etc/keepalived/keepalived.conf global_defs { ... smtp_server 127.0.0.1 //指向本地 router_id LVS_01 //指定名稱,備份服務器不一樣名稱 ... } vrrp_instance VI_1 { state MASTER //備份服務器是BACKUP interface ens33 //對應端口號 virtual_router_id 10 //組號 ... auth_pass abc123 #驗證密碼 priority 100 #優先級backup小於master ... virtual_ipaddress { 192.168.100.10 } ... virtual_server 192.168.100.10 80 { //虛擬服務器地址(VIP)、端口 ... real_server 192.168.100.221 80 { weight 1 TCP_CHECK { //健康檢查方式 connect_port 80 // connect_timeout 3 nb_get_retry 3 delay_before_retry 3 } } real_server 192.168.100.222 80 { weight 1 TCP_CHECK { connect_port 80 #添加端口 connect_timeout 3 nb_get_retry 3 delay_before_retry 3 } } }
Backup總體配置與Master相同,但在keepalived配置時須要注意:
router_id與Master的不一樣
state爲BACKUP
priority優先級Backup小於Mastervim
#systemctl start httpd.service //開啓httpd服務 #systemctl stop firewalld.service //關閉防火牆 #setenforce 0 #echo 「this is accp web」 > /var/www/html/index.html //添加首頁內容 #cd /etc/sysconfig/network-scripts #cp ifcfg-lo ifcfg-lo:0 #vim ifcfg-lo:0 DEVICE=lo:0 IPADDR=192.168.100.10 NETMASK=255.255.255.0 ONBOOT=yes
#vim /etc/init.d/web.sh //編寫網絡配置腳本web.sh #!/bin/bash VIP=192.168.100.10 case "$1" in start) ifconfig lo:0 $VIP netmask 255.255.255.255 broadcast $VIP /sbin/route add -host $VIP dev lo:0 echo "1" >/proc/sys/net/ipv4/conf/lo/arp_ignore echo "2" >/proc/sys/net/ipv4/conf/lo/arp_announce echo "1" >/proc/sys/net/ipv4/conf/all/arp_ignore echo "2" >/proc/sys/net/ipv4/conf/all/arp_announce sysctl -p >/dev/null 2>&1 echo "RealServer Start OK " ;; stop) ifconfig lo:0 down route del $VIP /dev/null 2>&1 echo "0" >/proc/sys/net/ipv4/conf/lo/arp_ignore echo "0" >/proc/sys/net/ipv4/conf/lo/arp_announce echo "0" >/proc/sys/net/ipv4/conf/all/arp_ignore echo "0" >/proc/sys/net/ipv4/conf/all/arp_announce echo "RealServer Stopd" ;; *) echo "Usage: $0 {start|stop}" exit 1 esac exit 0 #chmod +x web.sh #service web.sh start #ifup lo:0 //啓動後Xshell遠程鏈接會斷開 #ifconfig //到虛擬機中檢查虛擬網卡是否啓動 #firefox http://127.0.0.1/ & //在虛擬機中自測 #service web.sh stop #service web.sh start //重啓網絡配置腳本
總體配置過程同節點服務器1後端