keepalived

keepalived高可用
1、Keepalived VRRP 介绍

Virtual Route Redundancy Protocol,即虚拟路由冗余协议。它主要是实现路由器高可用的容错协议。
将多台路由器组成路由器组(Router Group),组中包括Master及Backup,在外部看来就像一台路由器,拥有一个VIP。Master会发送组播消息,当Backup在指定的时间收不到vrrp包就会认为master宕掉,然后通过VRRP协议再次竞选新的路由器当Master,从而保证路由器的高可用。
在VRRP协议实现中,虚拟路由器使用00-00-5E-00-01-XX作为虚拟MAC地址,XX就是唯一的VRID。

2、LVS_Director + KeepAlived

实施步骤:

  1. RS配置(web1,web2)
    配置好网站服务器,测试所有RS
    [root@web1 ~]# echo "ip addr add dev lo 10.3.131.250/32" >> /etc/rc.local
    [root@web1 ~]# echo "net.ipv4.conf.all.arp_ignore = 1" >> /etc/sysctl.conf
    root@web1 ~]#echo 2 > /proc/sys/net/ipv4/conf/all/arp_announce
    [root@web1 ~]# sysctl -p
    [root@web1 ~]# yum -y install httpd php php-mysql
    [root@web1 ~]# echo "web1..." >> /var/www/html/index.html

  2. 主/备调度器安装软件
    [root@lvs-master ~]# yum -y install ipvsadm keepalived
    [root@lvs-backup ~]# yum -y install ipvsadm keepalived

  3. Keepalived
    lvs-master
    获得Real Server测试页面的MD5SUM值
    [root@lvs-master ~]# genhash -s 192.168.122.30 -p 80 -u /test.html
    MD5SUM = f5ac8127b3b6b85cdc13f237c6005d80

[root@lvs-master ~]# vim /etc/keepalived/keepalived.conf
! Configuration File for keepalived

global_defs {
router_id lvs-master //辅助改为lvs-backup
}

vrrp_instance VI_1 {
state BACKUP
nopreempt //不抢占
interface eth0 //VIP绑定接口
mcast src ip x.x.x.x //发送组播的源IP,心跳线网卡
virtual_router_id 80 //VRID 同一组集群,主备一致 虚拟路由器 MAC 00-00-5E-00-01-{VRID}
priority 100 //本节点优先级,辅助改为50
advert_int 1 //检查间隔,默认为1s
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
192.168.122.100
}
}

virtual_server 192.168.122.100 80 { //LVS配置,可以是fwmark 80
delay_loop 6
lb_algo rr //LVS调度算法
lb_kind DR //LVS集群模式(路由模式)
nat_mask 255.255.255.0
persistence_timeout 20 //持久性连接
protocol TCP //健康检查使用的协议
sorry_server 2.2.2.2 80 //当所有real server不可用时

real_server 192.168.122.30 80 {
    weight 1
    inhibit_on_failure                  //当该节点失败时,把权重设置为0,而不是从IPVS中删除
    HTTP_GET {                            //健康检查
        url {
          path /test.html
          digest f5ac8127b3b6b85cdc13f237c6005d80
        }
        connect_port 80                 //检查的端口
        connect_timeout 3            //连接超时的时间
        nb_get_retry 3                   //重新连接的次数
        delay_before_retry 2         //重连的间隔
    }
}

real_server 192.168.122.40 80 {
    weight 1
    inhibit_on_failure
    HTTP_GET {
        url {
          path /test.html
          digest f5ac8127b3b6b85cdc13f237c6005d80
        }
        connect_timeout 3
        nb_get_retry 3
        delay_before_retry 3
    }
 }

}

lvs-backup

  1. 启动KeepAlived(主备均启动)
    [root@lvs-master ~]# chkconfig keepalived on
    [root@lvs-master ~]# service keepalived start
    [root@lvs-master ~]# tail -f /var/log/messages

[root@tianyun ~]# ipvsadm -Ln
IP Virtual Server version 1.2.1 (size=4096)
Prot LocalAddress:Port Scheduler Flags
-> RemoteAddress:Port Forward Weight ActiveConn InActConn
TCP 192.168.122.100:80 wrr
-> 192.168.122.30:80 Route 1 0 0
-> 192.168.122.30:80 Route 3 0 0

2、Haproxy_Director + Keepalived

一、Haproxy负载均衡
主/备调度器均能够实现正常调度

二、Keepalived实现调度器HA
注:主/备调度器均能够实现正常调度

  1. 主/备调度器安装软件
    [root@master ~]# yum -y install keepalived
    [root@backup ~]# yum -y install keepalived

  2. Keepalived
    Master
    [root@tianyun ~]# vim /etc/keepalived/keepalived.conf
    ! Configuration File for keepalived

global_defs {
router_id director1 //辅助改为director2
}

vrrp_instance VI_1 {
state BACKUP
nopreempt
interface eth0 //VIP绑定接口
virtual_router_id 80 //MASTER,BACKUP一致
priority 100 //辅助改为50
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
192.168.122.100
}
}

BACKUP

  1. 启动KeepAlived(主备均启动)
    [root@tianyun ~]# chkconfig keepalived on
    [root@tianyun ~]# service keepalived start
    [root@tianyun ~]# ip addr
  1. 扩展对调度器Haproxy健康检查(可选)
    思路:
    让Keepalived以一定时间间隔执行一个外部脚本,脚本的功能是当Haproxy失败,则关闭本机的Keepalived
    a. script
    [root@master ~]# cat /etc/keepalived/check_haproxy_status.sh

!/bin/bash

/usr/bin/curl -I http://localhost &>/dev/null
if [ $? -ne 0 ];then
/etc/init.d/keepalived stop
fi
[root@master ~]# chmod a+x /etc/keepalived/check_haproxy_status.sh

b. keepalived使用script
! Configuration File for keepalived

global_defs {
router_id director1
}

vrrp_script check_haproxy {
script "/etc/keepalived/check_haproxy_status.sh"
interval 5
}

vrrp_instance VI_1 {
state BACKUP
interface eth0
nopreempt
virtual_router_id 90
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass tianyun
}
virtual_ipaddress {
192.168.122.100
}

track_script {
    check_haproxy
}

}

3、Nginx_Director + Keepalived

一、Nginx负载均衡
主/备调度器均能够实现正常调度

二、Keepalived实现调度器HA

  1. 主/备调度器安装软件
    [root@master ~]# yum -y install keepalived
    [root@backup ~]# yum -y install keepalived

  2. Keepalived
    BACKUP1
    [root@tianyun ~]# vim /etc/keepalived/keepalived.conf
    ! Configuration File for keepalived

global_defs {
router_id director1 //辅助改为director2
}

vrrp_instance VI_1 {
state BACKUP
nopreempt
interface eth0 //VIP绑定接口
virtual_router_id 80 //整个集群的调度器一致
priority 100 //辅助改为50
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
192.168.1.80
}
}

BACKUP2

  1. 启动KeepAlived(主备均启动)
    [root@tianyun ~]# chkconfig keepalived on
    [root@tianyun ~]# service keepalived start
    [root@tianyun ~]# ip addr

到此:
可以解决心跳故障 keepalived
不能解决Nginx服务故障

  1. 扩展对调度器Nginx健康检查(可选)
    思路:
    让Keepalived以一定时间间隔执行一个外部脚本,脚本的功能是当Nginx失败,则关闭本机的Keepalived
    a. script
    [root@master ~]# cat /etc/keepalived/check_nginx_status.sh

!/bin/bash

/usr/bin/curl -I http://localhost &>/dev/null
if [ $? -ne 0 ];then
/etc/init.d/keepalived stop
fi
[root@master ~]# chmod a+x /etc/keepalived/check_nginx_status.sh

b. keepalived使用script
! Configuration File for keepalived

global_defs {
router_id director1
}

vrrp_script check_nginx {
script "/etc/keepalived/check_nginx_status.sh"
interval 5
}

vrrp_instance VI_1 {
state BACKUP
interface eth0
nopreempt
virtual_router_id 90
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass tianyun
}

virtual_ipaddress {
    192.168.1.80
}

track_script {
    check_nginx
}

}

注:必须先启动nginx,再启动keepalived

4、MySQL+Keepalived

Keepalived+mysql 自动切换

项目环境:
VIP 192.168.122.100
mysql1 192.168.122.10
mysql2 192.168.122.20

一、mysql 主主同步 (不使用共享存储,数据保存本地存储)
二、安装keepalived
三、keepalived 主备配置文件
四、mysql状态检测脚本/root/bin/keepalived_check_mysql.sh
五、测试及诊断
注 keepalived之间使用vrrp组播方式通信使用的IP地址是224.0.0.18
=====================================================================

实施步骤:
一、mysql 主主同步 <略>

二、安装keepalived
[root@tianyun ~]# yum -y install ipvsadm kernel-headers kernel-devel openssl-devel popt-devel
[root@tianyun ~]# wget http://www.keepalived.org/software/keepalived-1.2.2.tar.gz
[root@tianyun ~]# tar zxvf keepalived-1.2.2.tar.gz
[root@tianyun ~]# cd keepalived-1.2.2
[root@tianyun ~]# ./configure --prefix=/
[root@tianyun ~]# make
[root@tianyun ~]# make install

三、keepalived 主备配置文件
192.168.122.10 Master配置
[root@tianyun ~]# vim /etc/keepalived/keepalived.conf
=====================================================================
! Configuration File for keepalived

global_defs {
router_id mysql1
}

vrrp_script check_run {
script "/root/keepalived_check_mysql.sh"
interval 5
}

vrrp_instance VI_1 {
state MASTER
interface eth0
virtual_router_id 88
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass tianyun
}

track_script {
    check_run
}

virtual_ipaddress {
    192.168.122.100
}

}

=====================================================================

192.168.122.20 Slave配置
[root@tianyun ~]# vim /etc/keepalived/keepalived.conf
=====================================================================
! Configuration File for keepalived

global_defs {
router_id mysql2
}

vrrp_script check_run {
script "/root/keepalived_check_mysql.sh"
interval 5
}

vrrp_instance VI_1 {
state BACKUP
interface eth0
virtual_router_id 88
priority 50
advert_int 1
authentication {
auth_type PASS
auth_pass tianyun
}

track_script {
    check_run
}

virtual_ipaddress {
    192.168.122.100
}

}

  1. 注意空格
  2. 日志查看脚本是否被执行
    [root@xen2 ~]# tail -f /var/log/messages
    Jun 19 15:20:19 xen1 Keepalived_vrrp[6341]: Using LinkWatch kernel netlink reflector...
    Jun 19 15:20:19 xen1 Keepalived_vrrp[6341]: VRRP sockpool: [ifindex(2), proto(112), fd(11,12)]
    Jun 19 15:20:19 xen1 Keepalived_vrrp[6341]: VRRP_Script(check_run) succeeded

=====================================================================

四、mysql状态检测脚本/root/keepalived_check_mysql.sh(两台MySQL同样的脚本)
版本一:简单使用:

!/bin/bash

/usr/bin/mysql -uroot -p123 -e "show status" &>/dev/null
if [ $? -ne 0 ] ;then
service keepalived stop
fi

版本二:检查多次:
[root@tianyun ~]# vim /root/keepalived_check_mysql.sh

!/bin/bash

MYSQL=/usr/local/mysql/bin/mysql
MYSQL_HOST=localhost
MYSQL_USER=root
MYSQL_PASSWORD=tianyun
CHECK_TIME=3

mysql is working MYSQL_OK is 1 , mysql down MYSQL_OK is 0

MYSQL_OK=1

check_mysql_helth (){
MYSQL -hMYSQL_HOST -u MYSQL_USER -p{MYSQL_PASSWORD} -e "show status" &>/dev/null
if [ ? -eq 0 ] ;then MYSQL_OK=1 else MYSQL_OK=0 fi returnMYSQL_OK
}

while [ CHECK_TIME -ne 0 ] do check_mysql_helth if [MYSQL_OK -eq 1 ] ; then
exit 0
fi

if [ $MYSQL_OK -eq 0 ] &&  [ $CHECK_TIME -eq 1 ];then
        /etc/init.d/keepalived stop                 
        exit 1                              
fi                                      
let CHECK_TIME--
sleep 1 

done

版本三:检查多次:
[root@tianyun ~]# vim /root/keepalived_check_mysql.sh

!/bin/bash

MYSQL=/usr/local/mysql/bin/mysql
MYSQL_HOST=localhost
MYSQL_USER=root
MYSQL_PASSWORD=tianyun
CHECK_TIME=3

mysql is working MYSQL_OK is 1 , mysql down MYSQL_OK is 0

MYSQL_OK=1

check_mysql_helth (){
MYSQL -hMYSQL_HOST -u MYSQL_USER -p{MYSQL_PASSWORD} -e "show status" &>/dev/null
if [ ? -eq 0 ] ;then MYSQL_OK=1 else MYSQL_OK=0 fi returnMYSQL_OK
}

while [ CHECK_TIME -ne 0 ] do check_mysql_helth if [MYSQL_OK -eq 1 ] ; then
exit 0
fi

let CHECK_TIME--
sleep 1 

done

/etc/init.d/keepalived stop
exit 1
===================================================

[root@tianyun ~]# chmod 755 /root/keepalived_check_mysql.sh

两边均启动keepalived
[root@tianyun ~]# /etc/init.d/keepalived start
[root@tianyun ~]# /etc/init.d/keepalived start
[root@tianyun ~]# chkconfig --add keepalived
[root@tianyun ~]# chkconfig keepalived on

配置文件

! Configuration File for keepalived

global_defs {
router_id lvs-master
}

vrrp_instance VI_1 {
state BACKUP
nopreempt
interface eth0
mcast src ip x.x.x.x
virtual_router_id 80
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
192.168.122.100
}
}

virtual_server 192.168.122.100 80 {
delay_loop 6
lb_algo rr
lb_kind DR
nat_mask 255.255.255.0
persistence_timeout 20
protocol TCP
sorry_server 2.2.2.2 80

real_server 192.168.122.30 80 {
    weight 1
    inhibit_on_failure                 
    HTTP_GET {                            
        url {
          path /test.html
          digest f5ac8127b3b6b85cdc13f237c6005d80
        }
        connect_port 80               
        connect_timeout 3            
        nb_get_retry 3                   
        delay_before_retry 2         
    }
}

real_server 192.168.122.40 80 {
    weight 1
    inhibit_on_failure
    HTTP_GET {
        url {
          path /test.html
          digest f5ac8127b3b6b85cdc13f237c6005d80
        }
        connect_timeout 3
        nb_get_retry 3
        delay_before_retry 3
    }
 }

}

©著作权归作者所有,转载或内容合作请联系作者
  • 序言:七十年代末,一起剥皮案震惊了整个滨河市,随后出现的几起案子,更是在滨河造成了极大的恐慌,老刑警刘岩,带你破解...
    沈念sama阅读 194,390评论 5 459
  • 序言:滨河连续发生了三起死亡事件,死亡现场离奇诡异,居然都是意外死亡,警方通过查阅死者的电脑和手机,发现死者居然都...
    沈念sama阅读 81,821评论 2 371
  • 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
    开封第一讲书人阅读 141,632评论 0 319
  • 文/不坏的土叔 我叫张陵,是天一观的道长。 经常有香客问我,道长,这世上最难降的妖魔是什么? 我笑而不...
    开封第一讲书人阅读 52,170评论 1 263
  • 正文 为了忘掉前任,我火速办了婚礼,结果婚礼上,老公的妹妹穿的比我还像新娘。我一直安慰自己,他们只是感情好,可当我...
    茶点故事阅读 61,033评论 4 355
  • 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
    开封第一讲书人阅读 46,098评论 1 272
  • 那天,我揣着相机与录音,去河边找鬼。 笑死,一个胖子当着我的面吹牛,可吹牛的内容都是我干的。 我是一名探鬼主播,决...
    沈念sama阅读 36,511评论 3 381
  • 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
    开封第一讲书人阅读 35,204评论 0 253
  • 序言:老挝万荣一对情侣失踪,失踪者是张志新(化名)和其女友刘颖,没想到半个月后,有当地人在树林里发现了一具尸体,经...
    沈念sama阅读 39,479评论 1 290
  • 正文 独居荒郊野岭守林人离奇死亡,尸身上长有42处带血的脓包…… 初始之章·张勋 以下内容为张勋视角 年9月15日...
    茶点故事阅读 34,572评论 2 309
  • 正文 我和宋清朗相恋三年,在试婚纱的时候发现自己被绿了。 大学时的朋友给我发了我未婚夫和他白月光在一起吃饭的照片。...
    茶点故事阅读 36,341评论 1 326
  • 序言:一个原本活蹦乱跳的男人离奇死亡,死状恐怖,灵堂内的尸体忽然破棺而出,到底是诈尸还是另有隐情,我是刑警宁泽,带...
    沈念sama阅读 32,213评论 3 312
  • 正文 年R本政府宣布,位于F岛的核电站,受9级特大地震影响,放射性物质发生泄漏。R本人自食恶果不足惜,却给世界环境...
    茶点故事阅读 37,576评论 3 298
  • 文/蒙蒙 一、第九天 我趴在偏房一处隐蔽的房顶上张望。 院中可真热闹,春花似锦、人声如沸。这庄子的主人今日做“春日...
    开封第一讲书人阅读 28,893评论 0 17
  • 文/苍兰香墨 我抬头看了看天上的太阳。三九已至,却和暖如春,着一层夹袄步出监牢的瞬间,已是汗流浃背。 一阵脚步声响...
    开封第一讲书人阅读 30,171评论 1 250
  • 我被黑心中介骗来泰国打工, 没想到刚下飞机就差点儿被人妖公主榨干…… 1. 我叫王不留,地道东北人。 一个月前我还...
    沈念sama阅读 41,486评论 2 341
  • 正文 我出身青楼,却偏偏与公主长得像,于是被迫代替她去往敌国和亲。 传闻我的和亲对象是个残疾皇子,可洞房花烛夜当晚...
    茶点故事阅读 40,676评论 2 335

推荐阅读更多精彩内容

  • 去年六月中旬,玉溪除去华宁和澄江两县,其他地方都跑了一圈。端午放假两天,是有些不爽了。 磨磨蹭蹭的来到南部客运站,...
    半城离火阅读 413评论 4 6
  • 看东西只有用心才能看得清楚。重要的东西用眼睛是看不到的。——《小王子》 《小王子》的作者是法国传奇作家安托万•德•...
    小小夕颜花阅读 9,824评论 14 89
  • 最近看了爱伦坡的《创作哲学》,真是写的非常好。灵机一动,用这个来分析一下平时喜欢的《红楼梦》里的诗词,发现居然是异...
    依赖注入阅读 1,463评论 1 2
  • 爸爸说 手不能抬太高 有理不在声高 郑重!表达郑重 妈妈说 笑的不自然 我说 自己觉睡的太多了,好久没看书。 西游...
    dec41dfda297阅读 120评论 0 0
  • 在你看到丁点希望之前 低谷从来就没有过下限 本已准备买票一路向北 低落 沉重 看不到任何有光 有温度的地方 一个电...
    cr7only阅读 171评论 0 0