http://blog.csdn.net/zzban1111/article/details/15504783
说明:
一、目 的:本文实现的Linux集群是基于Keepalived-1.2.9软件实现,
二、难 点:实现虚拟IP(VIP)自动切换的同时,还要同时实现虚拟MAC地址(VMAC)的切换,即无论集群中的Host如何切换,对外访问的IP和MAC始终不变
三、适用环境:当对外路由或交换机绑定主机MAC时适用
四、整合资源: nginx-1.2.9
五、说 明:若无须对外绑定MAC地址,则大可简化如下配置
1. 环境及软件:
1) 系统:Debian6 amd64
2) 内核:linux 3.2.0-0.bpo.4-amd64
3) 软件:keepalived-1.2.9 nginx-1.2.9
2. 网卡配置说明:
MASTER设备IP: eth0: 10.10.1.2/24
BACKUP设备IP: eth0: 10.10.1.3/24
VIP: 192.168.1.10/24
3. nginx安装步骤:
参见我的另一篇文件《Nginx的安装与配置》
4. keepalived安装步骤:
1)升级当前Debian系统内核linux 2.6.32(升级内核的原因是因为我测试时总是出问题,keepalived官方文档要求有内核的patch,不过没看懂,索性升级为最新版本)
a) 修改Debian源文件/etc/apt/sources.list,添加一个向后兼容的源(源地址如下)
deb http://ftp.cn.debian.org/debian-backports squeeze-backports main contrib non-free
b) 更新Debian源文件关联并升级系统内核至3.2.0(如下标记的linux内核包版本随着时间的推移可能会有所变化,可通过如下命令进行查询:aptitude search linux-*)
# aptitude update
# aptitude -t squeeze-backports install linux-image-3.2.0-0.bpo.4-amd64
如果编译NVDIA的官方驱动的话,还要装:
# aptitude -t squeeze-backports install linux-headers-3.2.0.bpo.4-amd64
2) 安装keepalived-1.2.9
a) 首先要安装keepalived所依赖的组件
# aptitude install make gcc libpopt-dev libnl-dev libcurl4-openssl-dev
b) 将keepalived-1.2.9.tar.gz文件拷贝到/usr/local/soft下,解压,编译并安装到/usr/local/keepalived
# mkdir /usr/local/soft
通过ftp将文件拷贝至/usr/local/soft
# cd /usr/local/soft
# tar zxvf keepalived-1.2.9.tar.gz
# cd keepalived-1.2.9
# ./configure --prefix=/usr/local/keepalived
# make && make install
c) 重置keepalived相关文件,以便开机自动启动
# cp /usr/local/keepalived/sbin/keepalived /usr/sbin
# mkdir /etc/sysconfig
# cp /usr/local/keepalived/etc/sysconfig/keepalived /etc/sysconfig
# cp /usr/local/keepalived/etc/rc.d/init.d/keepalived /etc/init.d/
d) 修改keepalived启动脚本
# nano /etc/init.d/keepalived
修改/etc/init.d/keepalived文件,部分片段如下(蓝色标记为注释内容,红色标记为修改内容):
……
#. /etc/rc.d/init.d/functions
. /lib/lsb/init-functions
# Source configuration file (we set KEEPALIVED_OPTIONS there)
. /etc/sysconfig/keepalived
RETVAL=0
prog="keepalived"
start() {
echo -n $"Starting $prog: "
# keepalived ${KEEPALIVED_OPTIONS}
keepalived -D
RETVAL=$?
echo
[ $RETVAL -eq 0 ] && touch /var/lock/$prog
}
stop() {
echo -n $"Stopping $prog: "
killproc keepalived
RETVAL=$?
echo
[ $RETVAL -eq 0 ] && rm -f /var/lock/$prog
}
……
condrestart)
if [ -f /var/lock/$prog ]; then
stop
start
fi
;;
……
e) 在/etc/keepalived下创建keepalived配置文件keepalived.conf
# mkdir /etc/keepalived
# nano /etc/keepalived/keepalived.conf
global_defs {
notification_email {
tiddy@example.com
}
notification_email_from keepalived@example.com
smtp_server 192.168.1.5
smtp_connect_timeout 30
router_id LVS_DEVEL_11 #与backup配置不相同的任意合法字符串
}
vrrp_script chk_http_port {
script "/data/checkNginx.sh" #监控脚本
interval 2 #监控脚本检测周期
weight 2 #目前搞不清楚
}
vrrp_instance VI_1 {
state MASTER #backup机器配置为BACKUP
interface eth0 #绑定的网卡名称
virtual_router_id 250 #必须与backup机器配置相同
use_vmac #名字可为任意合法字符串(默认字符串 vrrp.${virtual_router_id} 此处默认使用vrrp.250)
priority 200 #优先级,要比backup机器高至少50
advert_int 1
authentication {
auth_type PASS #授权类型,必须与backup相同
auth_pass 1111 #授权密码,必须与backup相同
}
track_script {
chk_http_port #执行监控的服务名称
}
virtual_ipaddress {
192.168.1.10/24 #虚拟ip地址,必须与backup相同
}
nopreempt #不抢占IP,即当keepalived发生切换后,如果master服务器恢复正常后,backup不会自动重新切换回master,
#这样避免来回切换带来的系统开销,同时也避免了IP切换带来的系统不稳定性
}
3) 监控脚本/data/checkNginx.sh内容
#!/bin/bash
# 监控脚本功能概述:首先检查进程中的nginx进程数目,如果不存在(即为0),则表示nginx未开启,然后开启nginx,3秒后重新检查nginx进程数,若仍为0,
# 则表示nginx无法正常启动,此时强制停止keepalived进程,让虚拟ip切换到backup服务器上
A=`ps -C nginx --no-header |wc -l` ## 查看是否有 nginx进程 把值赋给变量A(注意:这里不是单引号,而是主键盘数字1左边的键"点")
if [ $A -eq 0 ];then ## 如果没有nginx进程,即值为零
/usr/local/nginx/sbin/nginx
sleep 3
if [ `ps -C nginx --no-header |wc -l` -eq 0 ];then
pkill keepalived ## 则结束 keepalived 进程,使得服务器切换到BACKUP服务器上
fi
fi
4) 启动keepalived
# invoke-rc.d keepalived start
5) 测试keepalived
a) MASTER启动时,查看日志/var/log/messages,显示keepalived进入MASTER状态同理,BACKUP机器将进入BACKUP状态
b) 当MASTER机器down掉时,查看BACKUP机器日志,显示keepalived进入MASTER,当MASTER重新启动时,MASTER机器进入MASTER状态而BACKUP机器keepalived重新进入BACKUP状态,此时表示keepalived安装测试已成功!