keepalived简介

keepalived是一个类似于layer3, 4 & 5交换机制的软件,也就是我们平时说的第3层、第4层和第5层交换。Keepalived的作用是检测web服务器的状态,如果有一台web服务器死机,或工作出现故障,Keepalived将检测到,并将有故障的web服务器从系统中剔除,当web服务器工作正常后Keepalived自动将web服务器加入到服务器群中,通过ping来监测对方的状态。

拓扑图:

-----------------------------------------------------------------------------------------

实验环境:

centos-6.4

所需的安装包:

主的和备的Director上都安装上keepalived

后端的两个realserver上都安装上htppd服务

-----------------------------------------------------------------------------------------

1.先同步个节点上的时间

[root@yulong]# ntpdate  172.16.0.1

2.在主的和从的上面安装keepalived

[root@yulong ~]# yum install keepalived -y

3.编辑keepalived配置文件

[root@yulong keepalived]# vim  keepalived.conf修改一下参数为自己所用的global_defs {   notification_email {                                                                                                                                                                                       root@localhost        收件人                                                                                                                                                                                      }                                                                                                                                                                                      notification_email_from  keep@localhost  发件人   smtp_server 127.0.0.1       邮件服务器   smtp_connect_timeout 10   链接超时时间   router_id LVS_DEVEL添加如下字段设置可以手动切换故障转移:vrrp_script chk_maintainace {                                                                                                                                                                                     script "[[ -f /etc/keepalived/down ]] && exit 1 || exit 0"                                                                                                                                                                                     interval 1  weight   -2                                                                                                                                                                                    }这段脚本的意思就是如果在这个目录下存在down的这个一个文件就把vip给转移到BAKPUP节点.这个文件可以手动创建来实现调试.以下用文字注释的都是需要修改的地方vrrp_instance VI_1 {    state MASTER                   设置主节点    interface eth0               网卡类型    virtual_router_id 51  虚拟路由ID    priority 100                    设置权重,权重必须大于BACKUP的权重    advert_int 1    authentication {           auth_type PASS       加密方法        auth_pass 1111       密码    }    virtual_ipaddress {                                                                                                                                                                                         172.16.8.100     设置访问的虚拟IP    }  track_script {                                                                                                                                                                                     chk_maintainace     这个是定义刚才添加的那段代码生效    }}

4.配置完毕以上内容后复制到从节点上一份

[root@yulong keepalived]# scp  keepalived.conf   yu:/etc/keepalived/

5.然后在从节点上需要修改下如下两项

[root@www ~]# vim  /etc/keepalived/keepalived.confstate BACKUP            设置为备用节点priority 99              权重设置为比主节点的小

6.然后主备都启动keepalived服务

[root@yulong keepalived]# service keepalived restartStopping keepalived:                                       [  OK  ]Starting keepalived:                                       [  OK  ]

7.然后查看master上的状态

[root@yulong keepalived]# ip addr show2: eth0: 
mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:0c:29:0e:d7:4d brd ff:ff:ff:ff:ff:ff inet 172.16.8.17/16 brd 172.16.255.255 scope global eth0 inet 172.16.8.100/32 scope global eth0 刚才配置的虚拟ip已经生效 inet6 fe80::20c:29ff:fe0e:d74d/64 scope link valid_lft forever preferred_lft forever

8.然后我们把master上的节点给停掉看看能不能转移

root@yulong keepalived]# touch  down[root@yulong keepalived]# ip addr show2: eth0: 
mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:0c:29:0e:d7:4d brd ff:ff:ff:ff:ff:ff inet 172.16.8.17/16 brd 172.16.255.255 scope global eth0 inet6 fe80::20c:29ff:fe0e:d74d/64 scope link valid_lft forever preferred_lft forever在keepalived目录下Touch down 文件是我们写的那条脚本,很强大哟在次ip addr show查看vip已经没有了

9.在备节点上查看vip有没有转移过来

[root@www ~]# ip  addr show2: eth0: 
mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:0c:29:6a:51:21 brd ff:ff:ff:ff:ff:ff inet 172.16.8.18/16 brd 172.16.255.255 scope global eth0 inet 172.16.8.100/32 scope global eth0 OK,已经转移过来了,说明是正常的. inet6 fe80::20c:29ff:fe6a:5121/64 scope link valid_lft forever preferred_lft forever

10.下面在主节点上配置keepalivedrealserver能调度上游的服务器

[root@yulong keepalived]# vim  keepalived.confvirtual_server 172.16.8.100 80 {      虚拟IP,就是一会要访问的IP    delay_loop 6    lb_algo rr        调度算法                  lb_kind DR         lvs的模式    nat_mask 255.255.0.0    persistence_timeout 50    protocol TCP    使用的协议                                                                                                                                                  real_server 172.16.8.10 80 {    realserver的ip地址 这个别写错了        weight 1      权重                                                                                                                                                                        TCP_CHECK {       realserver的状态监测                                                                                                                                                 connect_timeout 3     响应超时时间,默认3秒   nb_get_retry 3            重试次数   delay_before_retry 3  重试间隔时间        }    }                                                                                                                                                real_server  172.16.8.11 80 {     第二个realserver的定义 和上面的一样                                                                                                                                                 TCP_CHECK {                                                                                                                                                 connect_timeout 3   nb_get_retry 3   delay_before_retry 3      }                                                                                                                                                  }}

11.配置完毕以后复制到备服务器上一份

[root@yulong keepalived]# scp   keepalived.conf   yu:/etc/keepalived/然后在备的上面编辑keepalived.conf修改如下两项state BACKUP            设置为备用节点priority 99              权重设置为比主节点的小

12.上面的配置好以后我们来配置realserver服务器,两个realserver上都配置如下命令

[root@node1 ~]# ifconfig lo:0 172.16.8.100 broadcast 172.16.8.100   netmask 255.255.255.255  up由于我们使用的DR模型配置DR模型的vip,在lo上配置就行[root@node1 ~]# echo "1" >/proc/sys/net/ipv4/conf/lo/arp_ignore[root@node1 ~]# echo "1" >/proc/sys/net/ipv4/conf/all/arp_ignore[root@node1 ~]# echo "2" >/proc/sys/net/ipv4/conf/all/arp_announce[root@node1 ~]# echo "2" >/proc/sys/net/ipv4/conf/lo/arp_announce关闭arp广播[root@node1 ~]# echo  "

you are word

" > /var/www/html/index.html设置访问的网页主页内容

13.配置完成后两个realserver服务器上都启动web服务器进行测试

[root@node1 ~]# service  httpd   restartStopping httpd:                                            [  OK  ]Starting httpd:                                            [  OK  ]多点击几下看看是不是均衡

访问成功,看来是均衡的

14.下面我们来通过ipvsadm查看下访问的状态

[root@yulong keepalived]# yum install  ipvsadm[root@yulong keepalived]# ipvsadm -L  -n --statsIP Virtual Server version 1.2.1 (size=4096)Prot LocalAddress:Port               Conns   InPkts  OutPkts  InBytes OutBytes  -> RemoteAddress:PortTCP  172.16.8.100:80                     3        3        0      156        0  -> 172.16.8.10:80                      2        2        0      104        0  -> 172.16.8.11:80                      1        1        0       52        0

Ok 看来是通过keepalived调用的

下面来配置keepalived双主模型

1.在主的上面添加如下内容

[root@yulong keepalived]# vim   keepalived.confvrrp_instance VI_2 {    state BACKUP    interface eth0    virtual_router_id 51    priority 99    advert_int 1    authentication {        auth_type PASS        auth_pass 2111    }    virtual_ipaddress {                                                                                                   172.16.8.200    }  track_script {                                                                                               chk_maintainace    }}

2.在备的上面添加如下内容

vrrp_instance VI_2 {    state MASTER    interface eth0    virtual_router_id 51    priority 100    advert_int 1    authentication {        auth_type PASS        auth_pass 2111    }    virtual_ipaddress {      172.16.8.200    }  track_script {  chk_maintainace    }}

3.重启主备的keepalived的服务

[root@yulong keepalived]# service keepalived  restart

4.查看备的上面虚拟主ip有木有生效

[root@www ~]# ip addr show2: eth0: 
mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:0c:29:6a:51:21 brd ff:ff:ff:ff:ff:ff inet 172.16.8.18/16 brd 172.16.255.255 scope global eth0 inet 172.16.8.200/32 scope global eth0 已经生效 inet6 fe80::20c:29ff:fe6a:5121/64 scope link valid_lft forever preferred_lft forever

5.下面我们把备的masterdown掉看看是否会转移

root@www ~]# cd /etc/keepalived/[root@www keepalived]# touch  down[root@www keepalived]# ip addr show2: eth0: 
mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:0c:29:6a:51:21 brd ff:ff:ff:ff:ff:ff inet 172.16.8.18/16 brd 172.16.255.255 scope global eth0 inet6 fe80::20c:29ff:fe6a:5121/64 scope link valid_lft forever preferred_lft forever

172.16.8.200 的虚拟ip已经看不到了

6.下面在主的上面看看是否转移过来

[root@yulong keepalived]# ip addr show2: eth0: 
mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:0c:29:0e:d7:4d brd ff:ff:ff:ff:ff:ff inet 172.16.8.17/16 brd 172.16.255.255 scope global eth0 inet 172.16.8.100/32 scope global eth0 inet 172.16.8.200/32 scope global eth0 inet6 fe80::20c:29ff:fe0e:d74d/64 scope link valid_lft forever preferred_lft forever

两个虚拟ip都在,证明是正常的,此次双主模型搞定!