实验说明:
server | ip | 角色 |
---|---|---|
server1 | 172.25.3.1 | salt-master |
server2 | 172.25.3.2 | salt-minion(nginx+keepalived) |
server3 | 172.25.3.3 | salt-minion(apache+keepalived) |
部署实现(pillar的两种使用方法)
(1) salt-minion 节点配置
- 在salt-minion端配置
[root@server4 apache]# vi /etc/salt/minion
master: 172.25.3.1
[root@server4 apache]# systemctl start salt-minion
- master授权
[root@server1 salt]# salt-key -A
(2)创建nginx、apache、keepalived角色,开始部署keepalived
nginx:
- 创建nginx角色
[root@server1 salt]# mkdir nginx
[root@server1 salt]# cd nginx
[root@server1 nginx]# pwd
/srv/salt/nginx
[root@server1 nginx]# mkdir files
[root@server1 nginx]# ls
files install.sls
- 编写install.sls nginx安装文件
[root@server1 nginx]# vi install.sls
nginx-install:
pkg.installed: ##nginx依赖包的安装
- pkgs:
- gcc
- openssl-devel
- pcre-devel
file.managed: ##安装包的获取
- name: /mnt/nginx-1.17.4.tar.gz
- source: salt://nginx/files/nginx-1.17.4.tar.gz
cmd.run: ##nginx的安装编译
- name: cd /mnt && tar zxf nginx-1.17.4.tar.gz && cd nginx-1.17.4 && sed -i.bak 's/CFLAGS="$CFLAGS -g"/#CFLAGS="$CFLAGS -g"/g' auto/cc/gcc && ./configure --prefix=/usr/local/nginx --with-http_ssl_module &> /dev/null && make &> /dev/null && make install &> /dev/null && useradd -s /sbin/nologin nginx
- creates: /usr/local/nginx
- nginx的systemd设定 服务的配置(安装配置一体化)
[root@server1 nginx]# vi service.sls
include:
- nginx.install ##将安装文件导入
/usr/local/nginx/conf/nginx.conf:
file.managed:
- source: salt://nginx/files/nginx.conf
nginx-service:
file.managed:
- name: /usr/lib/systemd/system/nginx.service ##systemctl 设定
- source: salt://nginx/files/nginx.service
service.running:
- name: nginx
- reload: true
- watch:
- file: /usr/local/nginx/conf/nginx.conf
- nginx需要文件的准备
[root@server1 nginx]# ls
files install.sls service.sls
[root@server1 nginx]# cd files
[root@server1 files]# ls
nginx-1.17.4.tar.gz nginx.conf nginx.service
[root@server1 files]# pwd
/srv/salt/nginx/files
[root@server1 files]# vi nginx.service
[Unit]
Description=The NGINX HTTP and reverse proxy server
After=syslog.target network.target remote-fs.target nss-lookup.target
[Service]
Type=forking
PIDFile=/usr/local/nginx/logs/nginx.pid
ExecStartPre=/usr/local/nginx/sbin/nginx -t
ExecStart=/usr/local/nginx/sbin/nginx
ExecReload=/usr/local/nginx/sbin/nginx -s reload
ExecStop=/bin/kill -s QUIT $MAINPID
PrivateTmp=true
[Install]
WantedBy=multi-user.target
[root@server1 files]# vi nginx.conf ##配置文件修改
2 user nginx nginx;
3 worker_processes auto;
apache:
- apache角色的创建
[root@server1 salt]# mkdir apache
[root@server1 salt]# cd apache
[root@server1 apache]# pwd
/srv/salt/apache
[root@server1 apache]# mkdir files
[root@server1 apache]# ls
files install.sls
- apache部署文件(apache.sls)的编写
[root@server1 apache]# vi apache.sls
apache-install: ##唯一性声明
pkg.installed: ##调用模块
- pkgs:
- httpd
- httpd-tools
file.managed:
- name: /etc/httpd/conf/httpd.conf
- source: salt://apache/files/httpd.conf
service.running:
- name: httpd
- reload: true
- watch: ##监控当apache配置文件发生改变,就reload重启服务
- file: apache-install
- apache 需要文件的配置
[root@server1 files]# pwd
/srv/salt/apache/files
[root@server1 files]# ls
httpd.conf
keepalived:
- 创建keepalived角色
[root@server1 salt]# pwd
/srv/salt
[root@server1 salt]# mkdir keepalived
[root@server1 salt]# ls
apache haproxy keepalived nginx top.sls
[root@server1 salt]# cd keepalived/
[root@server1 keepalived]# mkdir files
[root@server1 keepalived]# ls
files
- 编写keepalived安装文件
方法一:
[root@server1 keepalived]# vi install.sls
keepalived-install:
pkg.installed:
- pkgs:
- keepalived
file.managed:
- name: /etc/keepalived/keepalived.conf
- source: salt://keepalived/files/keepalived.conf
- template: jinja ##使用jinjia 模板
{% if grains['fqdn'] == 'server4' %}
- STATE: MASTER
- PRIORITY: 100
{% elif grains['fqdn'] == 'server5' %}
- STATE: BACKUP
- PRIORITY: 50
{% endif %}
service.running:
- name: keepalived
- reload: true
- watch:
- file: keepalived-install
方法二:
[root@server1 keepalived]# cd /srv/pillar/
[root@server1 pillar]# ls
top.sls web.sls
[root@server1 pillar]# vim keepalived.sls
{% if grains['fqdn'] == 'server2' %}
state: MASTER
priv: 100
{% elif grains['fqdn'] == 'server3' %}
state: BACKUP
priv: 50
{% endif %}
[root@server1 pillar]# vim top.sls
base:
'*':
- web
- keepalived
[root@server1 keepalived]# pwd
/srv/salt/keepalived
[root@server1 keepalived]# vi install.sls
keepalived-install:
pkg.installed:
- pkgs:
- keepalived
file.managed:
- name: /etc/keepalived/keepalived.conf
- source: salt://keepalived/files/keepalived.conf
- template: jinja ##使用jinjia 模板
- context:
STATE: {{ pillar['state'] }}
PRIORITY: {{ pillar['priv'] }}
service.running:
- name: keepalived
- reload: true
- watch:
- file: keepalived-install
- keepalived配置文件参数修改
[root@server1 files]# pwd
/srv/salt/keepalived/files
[root@server1 files]# vi keepalived.conf
! Configuration File for keepalived
global_defs {
notification_email {
root@localhost
}
notification_email_from keepalived@localhost
smtp_server 127.0.0.1
smtp_connect_timeout 30
router_id LVS_DEVEL
}
vrrp_instance VI_1 {
state {{ STATE }}
interface eth0
virtual_router_id 51
priority {{ PRIORITY }}
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
172.25.3.100
}
}
}
(3)编写角色执行顶级top.sls文件
[root@server1 salt]# pwd
/srv/salt
[root@server1 salt]# vim top.sls
base:
'server2':
- nginx.service
- keepalived.install
'server3':
- apache.apache
- keepalived.install
(4)执行部署
[root@server1 salt]# salt '*' state.highstate
(5)效果实现
vip在server2(master)上,在浏览器中访问vip:
当master宕机:
vip飘移
[root@server2 nginx-1.17.4]# systemctl stop keepalived