系统环境说明:
系统版本:Centos6.2x86_64
Director的IP:主节点:192.168.56.101
备节点:192.168.56.102
Realserver的IP:192.168.56.103
192.168.56.104
VIP地址:192.168.56.200
一、编译安装keepalived
1、解决依赖关系
gcc
make
ipvsadm
openssl-devel
popt-devel
以上包均可通过yum安装
2、编译安装
[root@localhost ~]# tar xf keepalived-1.2.7.tar.gz
[root@localhost ~]# cd keepalived-1.2.7
[root@localhost keepalived-1.2.7]# ./configure --sysconf=/etc
[root@localhost keepalived-1.2.7]# make && make install
[root@localhost keepalived-1.2.7]# ln -s /usr/local/sbin/keepalived /sbin/keepalived
3、配置keepalived
[root@localhost ~]# vim /etc/keepalived/keepalived.conf ==> 内容如下
# 全局定义部分
global_defs {
notification_email {
} # 设置邮件报警,接受报警邮件地址,如有多个可以每行一个
notification_email_from [email protected] # 设置报警邮件的发件人地址
smtp_server 127.0.0.1 # smtp服务器地址
smtp_connect_timeout 30
# smtp连接的超时时间
router_id LVS_DEVEL
# 运行keepalived服务器的一个标识,发邮件时显示在邮件标题中
}
# vrrp实例定义部分
vrrp_instance VI_1 {
# 实例名称,自定义
state MASTER
# 指定keepalived的角色,MASTER表示为主服务器,BACKUP表示为备用服务器
interface eth0
# 指定监测的网络接口
virtual_router_id 51
# 虚拟路由标识,同一个实例下MASTER和BACKUP必须相同的id
priority 100
# 定义优先级,数字越大优先级越高,同一个实例下MASTER必须要比BACKUP优先级高
advert_int 1
# 指定MASTER和BACKUP之间的检测的时间间隔,单位秒
authentication {
auth_type PASS
# 指定验证类型,主要有PASS和AH两种
auth_pass 1111
# 设置验证密码,在同一个实例下MASTER和BACKUP必须相同,不然将无法通过认证
}
virtual_ipaddress {
192.168.56.200
# 设置虚拟IP地址,可以设置多个每行一个
}
}
# real server配置
virtual_server 192.168.56.200 80 {
# VIP的地址和端口
delay_loop 6
# 检测realserver的时间间隔
lb_algo wlc
# lvs的调度算法
lb_kind DR
# lvs的转发模型
nat_mask 255.255.255.0
persistence_timeout 50
# 持久连接的超时时间
protocol TCP
sorry_server 192.168.56.102 80
# 当后端的realserver都不可用时,把请求转发至该IP
real_server 192.168.56.103 80 {
# realserver的真实IP地址
weight 1
# lvs权重
HTTP_GET {
# 检测方法
url {
path /.heartbeat.html
# 检测的url
status_code 200
# 检测的页面返回的状态码为200,即表示正常
}
connect_timeout 3
# 检测的连接超时时间
nb_get_retry 3
# 在判定为不可用前的尝试次数
delay_before_retry 3
# 重连的时间间隔
}
}
real_server 192.168.56.104 80 {
weight 1
HTTP_GET {
url {
path /.heartbeat.html
status_code 200
}
connect_timeout 3
nb_get_retry 3
delay_before_retry 3
}
}
}
4、备用节点的相关配置
备用节点的配置与主节点基本相同,只需要修改如下部分:
# vrrp实例定义部分
state BACKUP
# 在备用节点上,此处修改为BACKUP
priority 90
# 优先级的设置也不能高于主节点
4、启动并测试
[root@localhost ~]# service keepalived start
[root@localhost ~]# ipvsadm -L
IP Virtual Server version 1.2.1 (size=4096)
Prot LocalAddress:Port Scheduler Flags
-> RemoteAddress:Port Forward Weight ActiveConn InActConn
TCP 192.168.56.200:http wlc
-> 192.168.56.103:http Route 1 0 0
-> 192.168.56.104:http Route 1 0 0
可以通过ipvsadm命令看到已经检测到客户端
二、配置Realserver
后端的Realserver配置其实就是在lo接口上启用一个子接口IP为VIP,然后禁止该接口响应arp包,可以通过如下脚本执行:
#!/bin/bash
#
# Script to start LVS DR real server.
# description: LVS DR real server
#
. /etc/rc.d/init.d/functions
VIP=192.168.56.200
host=`/bin/hostname`
case "$1" in
start)
# Start LVS-DR real server on this machine.
/sbin/ifconfig lo down
/sbin/ifconfig lo up
echo 1 > /proc/sys/net/ipv4/conf/lo/arp_ignore
echo 2 > /proc/sys/net/ipv4/conf/lo/arp_announce
echo 1 > /proc/sys/net/ipv4/conf/all/arp_ignore
echo 2 > /proc/sys/net/ipv4/conf/all/arp_announce
/sbin/ifconfig lo:0 $VIP broadcast $VIP netmask 255.255.255.255 up
/sbin/route add -host $VIP dev lo:0
;;
stop)
# Stop LVS-DR real server loopback device(s).
/sbin/ifconfig lo:0 down
echo 0 > /proc/sys/net/ipv4/conf/lo/arp_ignore
echo 0 > /proc/sys/net/ipv4/conf/lo/arp_announce
echo 0 > /proc/sys/net/ipv4/conf/all/arp_ignore
echo 0 > /proc/sys/net/ipv4/conf/all/arp_announce
;;
status)
# Status of LVS-DR real server.
islothere=`/sbin/ifconfig lo:0 | grep $VIP`
isrothere=`netstat -rn | grep "lo:0" | grep $VIP`
if [ ! "$islothere" -o ! "isrothere" ];then
# Either the route or the lo:0 device
# not found.
echo "LVS-DR real server Stopped."
else
echo "LVS-DR real server Running."
fi
;;
*)
# Invalid entry.
echo "$0: Usage: $0 {start|status|stop}"
exit 1
;;
esac
通过执行bash lvs_realserver.sh start来启动客户端相关的配置
[root@localhost ~]# echo "bash /root/lvs_realserver.sh start" >> /etc/rc.d/rc.local
# 设置该脚本开机自动执行
三、其他
HTTP_GET检测方法:
HTTP_GET {
url {
path /.heartbeat.html
digest eff5bc1ef8ec9d03e640fc4370f5eacd
}
connect_timeout 3
nb_get_retry 3
delay_before_retry 3
}
digest值的算法为:
genhash -s 192.168.56.103 -p 80 -u /.heartbeat.html
MD5SUM = eff5bc1ef8ec9d03e640fc4370f5eacd
也可以设置status_code 200 ,返回的状态码为200即成功。