1. 程式人生 > >003.Keepalived搭建LVS高可用叢集

003.Keepalived搭建LVS高可用叢集

一 基礎環境

1.1 IP規劃

OS:CentOS 6.8 64位
節點型別 IP規劃 主機名 型別
主 Director Server eth0:172.24.8.10 DR1
公共IP
eth1:192.168.56.100 心跳 私有IP
eth0:0:172.24.8.100 虛擬IP
主 Director Server
eth0:172.24.8.11 DR2 公共IP
eth1:192.168.56.101 心跳 私有IP
Real Server 1 eth0:172.24.8.12
rs1 公共IP
lo:0:172.24.8.100 虛擬IP
Real Server 1 eth0:172.24.8.13 rs2 公共IP
lo:0:172.24.8.100 虛擬IP

1.2 架構規劃

01

二 高可用LVS負載均衡叢集部署

2.1 NTP部署

操作略,具體可參考N01.1.1-常見服務《NTP》。 注意:為了保證叢集的穩定性,強烈建議在所有節點均部署NTP同步服務,保證所有時鐘一致。

2.2 部署httpd叢集

  1 [[email protected] ~]# yum -y install httpd
  2 [[email protected] ~]# service iptables stop
  3 [[email protected] ~]# chkconfig iptables off
  4 [[email protected] ~]# vi /etc/selinux/config
  5 SELINUX=disabled
  6 [[email protected] ~]# setenforce 0			                 #關閉SELinux及防火牆
  注意:後端所有Real伺服器節點都需要安裝,用於模擬測試。 建議:為了測試方便,建議所有節點關閉防火牆和SELinux,若未關閉防火牆也可通過下列方式放通:
  1 firewall-cmd --permanent–-add-service=keepalived
  2 firewall-cmd --reload
 

2.3 安裝Keepalived

  1 [[email protected] ~]# yum -y install gcc gcc-c++ make kernel-devel kernel-tools kernel-tools-libs kernel libnl libnl-devel libnfnetlink-devel openssl-devel wget openssh-clients	        #安裝基礎環境及依賴
  2 [[email protected] ~]# ln -s /usr/src/kernels/`uname -r` /usr/src/linux
  3 [[email protected] ~]# wget http://www.keepalived.org/software/keepalived-1.3.6.tar.gz
  4 [[email protected] ~]# tar -zxvf keepalived-1.3.6.tar.gz	        #編譯安裝Keepalived
  5 [[email protected] ~]# cd keepalived-1.3.6/
  6 [[email protected] keepalived-1.3.6]# ./configure --prefix=/usr/local/keepalived
  7 [[email protected] keepalived-1.3.9]# make && make install
  注意:CentOS6.8安裝高於1.3.6版本會出現未知錯誤。

2.4 新增啟動相關服務

  1 [[email protected] ~]# mkdir /etc/keepalived
  2 [[email protected] ~]# cp /usr/local/keepalived/etc/keepalived/keepalived.conf /etc/keepalived/
  3 [[email protected] ~]# cp /usr/local/keepalived/etc/sysconfig/keepalived /etc/sysconfig/
  4 [[email protected] ~]# cp /usr/local/keepalived/sbin/keepalived /usr/sbin/
  5 [[email protected] ~]# vi /etc/init.d/keepalived		#建立Keepalived啟動指令碼,如附件
  6 #!/bin/sh
  7 #
  8 # keepalived   High Availability monitor built upon LVS and VRRP
  9 #
 10 # chkconfig:   - 86 14
 11 # description: Robust keepalive facility to the Linux Virtual Server project \
 12 #              with multilayer TCP/IP stack checks.
 13 
 14 ### BEGIN INIT INFO
 15 # Provides: keepalived
 16 # Required-Start: $local_fs $network $named $syslog
 17 # Required-Stop: $local_fs $network $named $syslog
 18 # Should-Start: smtpdaemon httpd
 19 # Should-Stop: smtpdaemon httpd
 20 # Default-Start:
 21 # Default-Stop: 0 1 2 3 4 5 6
 22 # Short-Description: High Availability monitor built upon LVS and VRRP
 23 # Description:       Robust keepalive facility to the Linux Virtual Server
 24 #                    project with multilayer TCP/IP stack checks.
 25 ### END INIT INFO
 26 
 27 # Source function library.
 28 . /etc/rc.d/init.d/functions
 29 
 30 exec="/usr/sbin/keepalived"
 31 prog="keepalived"
 32 config="/etc/keepalived/keepalived.conf"
 33 
 34 [ -e /etc/sysconfig/$prog ] && . /etc/sysconfig/$prog
 35 
 36 lockfile=/var/lock/subsys/keepalived
 37 
 38 start() {
 39     [ -x $exec ] || exit 5
 40     [ -e $config ] || exit 6
 41     echo -n $"Starting $prog: "
 42     daemon $exec $KEEPALIVED_OPTIONS
 43     retval=$?
 44     echo
 45     [ $retval -eq 0 ] && touch $lockfile
 46     return $retval
 47 }
 48 
 49 stop() {
 50     echo -n $"Stopping $prog: "
 51     killproc $prog
 52     retval=$?
 53     echo
 54     [ $retval -eq 0 ] && rm -f $lockfile
 55     return $retval
 56 }
 57 
 58 restart() {
 59     stop
 60     start
 61 }
 62 
 63 reload() {
 64     echo -n $"Reloading $prog: "
 65     killproc $prog -1
 66     retval=$?
 67     echo
 68     return $retval
 69 }
 70 
 71 force_reload() {
 72     restart
 73 }
 74 
 75 rh_status() {
 76     status $prog
 77 }
 78 
 79 rh_status_q() {
 80     rh_status &>/dev/null
 81 }
 82 
 83 
 84 case "$1" in
 85     start)
 86         rh_status_q && exit 0
 87         $1
 88         ;;
 89     stop)
 90         rh_status_q || exit 0
 91         $1
 92         ;;
 93     restart)
 94         $1
 95         ;;
 96     reload)
 97         rh_status_q || exit 7
 98         $1
 99         ;;
100     force-reload)
101         force_reload
102         ;;
103     status)
104         rh_status
105         ;;
106     condrestart|try-restart)
107         rh_status_q || exit 0
108         restart
109         ;;
110     *)
111         echo $"Usage: $0 {start|stop|status|restart|condrestart|try-restart|reload|force-reload}"
112         exit 2
113 esac
114 exit $
115 [[email protected] ~]# chmod u+x /etc/rc.d/init.d/keepalived
116 [[email protected] ~]# vi /etc/keepalived/keepalived.conf
117 ! Configuration File for keepalived
118 ……
119    smtp_connect_timeout 30
120    router_id LVS_Master		#表示執行Keepalived伺服器的一個標識
121 }
122 
123 vrrp_instance VI_1 {
124     state MASTER			#指定Keepalived的角色
125     interface eth0			#指定HA監測網路的介面
126     virtual_router_id 51            #同一個vrrp例項使用唯一的標識,即同一個vrrp_instance下,Master和Backup必須是一致的
128     priority 100			#定義優先順序,數值越大,優先順序越高
129     advert_int 1			#設定Mater和Backup負載均衡器之間同步檢查時間間隔
130     authentication {
131         auth_type PASS
132         auth_pass 1111
133     }
134     virtual_ipaddress {
135         172.24.8.100		#設定虛擬IP地址
136     }
137 }
138 
139 virtual_server 172.24.8.100 80 {
140     delay_loop 6			#執行情況檢查時間
141     lb_algo rr			#設定負載均衡演算法
142     lb_kind DR			#設定LVS實現負載均衡的機制,有NAT/DR/TUN
143     persistence_timeout 50		#會話保持時間
144     protocol TCP 			#指定轉發型別
145 
146     real_server 172.24.8.12 80 {
147         weight 1			#服務節點的權值,數值越大,權值越高
148         TCP_CHECK {
149         connect_timeout 5		#表示無響應超時時間,單位是秒
150         nb_get_retry 3		#表示重試次數
151         delay_before_retry 3	#表示重試間隔
152         }
153     }
154 real_server 172.24.8.13 80 {
155         weight 1
156         TCP_CHECK {
157         connect_timeout 5
158         nb_get_retry 3
159         delay_before_retry 3
160      }
161 }
162 }
163 [[email protected] ~]# scp /etc/keepalived/keepalived.conf 172.24.8.11:/etc/keepalived/keepalived.conf
164 [[email protected] ~]# vi /etc/keepalived/keepalived.conf
165 state BACKUP
166 priority 80
  注意;備用Director Server上需要修改狀態為BACKUP和priority優先順序。

2.5 安裝IPVS管理工具

  1 [[email protected] ~]# yum -y install ipvsadm

2.6 配置Real Server節點

在LVS的DR和TUN模式下,使用者訪問請求到大Real Server後,Real Server的響應報文直接返回給使用者,而不需經過Director Server。因此,需要在每個Real Server上配置虛擬VIP地址。 注意:迴環介面繫結vip,且禁止arp請求等操作,可通過以下指令碼實現:指令碼可留言索要。
  1 [[email protected] ~]# vi /etc/init.d/lvsrs
  2 [[email protected] ~]# chmod u+x /etc/init.d/lvsrs
 

2.7 啟動叢集

  1 [[email protected] ~]# service httpd start
  2 [[email protected] ~]# chkconfig httpd on
  3 [[email protected] ~]# service httpd start
  4 [[email protected] ~]# chkconfig httpd on
  5 
  6 [[email protected] ~]# service keepalived start
  7 [[email protected] ~]# chkconfig keepalived on
  8 [[email protected] ~]# service keepalived start
  9 [[email protected] ~]# chkconfig keepalived on
 10 
 11 [[email protected] ~]# service lvsrs start
 12 [[email protected] ~]# service lvsrs start
 

三 測試叢集

3.1 高可用功能測試

停止主Director Server伺服器的Keepalived,觀察/var/log/messages日誌,可知備機會立刻變為MASTER,並且接管主機的虛擬ip資源。重啟主Director Server伺服器的Keepalived,備機會重新恢復為BACKUP角色。 具體測試略。

3.2 負載均衡測試

  1 [[email protected] ~]# echo 'This is Real Server01!' >>/var/www/html/index.html
  2 [[email protected] ~]# echo 'This is Real Server02!' >>/var/www/html/index.html
  然後瀏覽器訪問:http://172.24.8.100,並不斷的重新整理,能分別看到Server01和Server02即可。

3.3 故障切換測試

  1 [[email protected] ~]# service httpd stop

02

當關掉其中一個Real Server時,訪問VIP,只會顯示還處於叢集中的web節點。

03