keepalived知识及单主keepalived实战

keepalived

1高可用集群

集群类型

LB负载均衡:LVS/HAPROXY/nginx (http/upstream,stream/upstream)

HA高可用集群:数据库、zookeeper,redis,keepalived通用的高可用集群

HPC:高性能集群

实现高可用:

提升系统高可用性的解决方案:降低MTTR(平均故障时间)

解决方案:建立冗余机制

active/passive主/备
active/active双主
active-->/heartbeat-->passive
active-->heartbeat-->active
VRRP

虚拟路由冗余协议,解决静态网关单点风险

物理层:路由器、三层交换机 软件层:keepalived

VRRP相关术语
虚拟路由器:virtual router
虚拟路由器标识:VRID
VIP:virtual IP
VMAC:虚拟mac
VRRP相关技术
通告:心跳,优先级,周期性
工作方式:抢占式,非抢占式
安全认证:无认证,简单字符认证:预共享密钥 ,MD5
工作模式:主/备:单虚拟路由;主/主:主/备(虚拟路由器1),备/主(虚拟路由器2)

2keepalived

keepalived介绍

vrrp协议的软件实现,原生设计目的为了高可用ipvs服务

功能:

1.基于vrrp协议完成地址流动;2.为vip地址所在的节点生成ipvs规则(在配置文件中预先定义);3.为ipvs集群的各RS做健康状态检测;4.基于脚本调用接口完成脚本中定义的功能,进而影响集群事务,依次支持nginx,haproxy等服务。

keepalived架构

1.用户空间核心组件
vrrp stack:vip消息通告
checkers:监测real server
system call:实现vrrp协议状态转换时期调用脚本的功能
SMTP:邮件组件
IPVS wrapper:生成IVS规则
Netlink reflector:网络接口
WatchDog:监控进程
2.控制组件:提供keepalived.conf的解析库

keepalived编译安装

#下载依赖软件
[root@kpa ~]# yum install gcc curl openssl-devel libnl3-devel net-snmp-devel
#下载二进制文件
[root@kpa ~]# wget https://keepalived.org/software/keepalived-2.0.20.tar.gz
#解压到指定目录
[root@kpa ~]# tar xvf keepalived-2.0.20.tar.gz -C /usr/local/src
#选项--disable-fwmark 可用于禁用iptables规则,可访止VIP无法访问,无此选项默认会启用iptables规则
[root@kpa ~]# cd /usr/local/src/keepalived-2.0.20/
#配置文件路径
[root@kpa keepalived-2.0.20]# ./configure --prefix=/usr/local/keepalived --disable-fwmark
#编译并安装
[root@kpa keepalived-2.0.20]# make && make install
[root@kpa keepalived-2.0.20]# cd
[root@kpa ~]# /usr/local/keepalived/sbin/keepalived -v
#创建配置文件
[root@kpa ~]# mkdir /etc/keepalived #没有创建的hua

[root@kpa ~]# cp /usr/local/keepalived/etc/keepalived/keepalived.conf /etc/keepalived

[root@kpa ~]# systemctl enable --now keepalived.service 
#注意事项
#不进行下面配置,结果:重启不报错,但是status状态一直dead
[root@nginx1 ~]# vim /etc/keepalived/keepalived.conf
vrrp_instance VI_1 {
    state MASTER
    interface ens160#根据自己网卡名设置
    virtual_router_id 51
    priority 100
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 1111
    }
    virtual_ipaddress {
        10.1.1.88 #改为vip
    }
}

编译安装出现错误

编译安装重启服务出错:原因 缺少配置文件路径

mkdir /etc/keepalived可以解决

在这里插入图片描述
在这里插入图片描述

keepalived配置说明

配置文件

/etc/keepalived/keepalived.conf

配置文件组成

global configuration
global definitions:定义邮件配置,route_id ,vrrp配置,多播配置等
VRRP configuration
VRRP instance(s):定义每个vrrp虚拟路由器
LVS configuration
virtual server group(s)
virtual server(s): LVS集群的VS和RS

配置语法说明

全局配置
#/etc/keepalived/keepalived.conf 
global_defs {
 notification_email {
 root@localhost #keepalived 发生故障切换时邮件发送的目标邮箱,可以按行区分写
多个
 root@wangxiaochun.com 
  29308620@qq.com 
 }
 notification_email_from keepalived@localhost  #发邮件的地址
 smtp_server 127.0.0.1     #邮件服务器地址
 smtp_connect_timeout 30   #邮件服务器连接timeout
 router_id ka1.example.com #每个keepalived主机唯一标识,建议使用当前主机名,如果多节点重
名可能会影响切换脚本执行
 vrrp_skip_check_adv_addr  #对所有通告报文都检查,会比较消耗性能,启用此配置后,如果收到的
通告报文和上一个报文是同一个路由器,则跳过检查,默认值为全检查
 vrrp_strict #严格遵守VRRP协议,启用此项后以下状况将无法启动服务:1.无VIP地址 2.配置了单播邻
居 3.在VRRP版本2中有IPv6地址,开启动此项并且没有配置vrrp_iptables时会自动开启iptables防火
墙规则,默认导致VIP无法访问,建议不加此项配置
vrrp_garp_interval 0 #gratuitous ARP messages 报文发送延迟,0表示不延迟
vrrp_gna_interval 0  #unsolicited NA messages (不请自来)消息发送延迟
vrrp_mcast_group4 224.0.0.18 #指定组播IP地址范围:224.0.0.0到239.255.255.255,默认
值:224.0.0.18 
vrrp_iptables        #此项和vrrp_strict同时开启时,则不会添加防火墙规则,如果无配置vrrp_strict项,则无需启用此项配置
}
配置虚拟路由器
vrrp_instance <STRING> { #<String>为vrrp的实例名,一般为业务名称
配置参数
......
 }
 #配置参数: 
state MASTER|BACKUP#当前节点在此虚拟路由器上的初始状态,状态为MASTER或者BACKUP
interface IFACE_NAME #绑定为当前虚拟路由器使用的物理接口,如:eth0,bond0,br0,可以和VIP不
在一个网卡
virtual_router_id VRID #每个虚拟路由器唯一标识,范围:0-255,每个虚拟路由器此值必须唯一,否则服务无法启动,同属一个虚拟路由器的多个keepalived节点必须相同,务必要确认在同一网络中此值必须唯一
priority 100 #当前物理节点在此虚拟路由器的优先级,范围:1-254,每个keepalived主机节点此
值不同
advert_int 1 #vrrp通告的时间间隔,默认1s
authentication { #认证机制
auth_type AH|PASS   #AH为IPSEC认证(不推荐),PASS为简单密码(建议使用)
auth_pass <PASSWORD> #预共享密钥,仅前8位有效,同一个虚拟路由器的多个keepalived节点必
须一样
}
virtual_ipaddress { #虚拟IP,生产环境可能指定上百个IP地址
<IPADDR>/<MASK> brd <IPADDR> dev <STRING> scope <SCOPE> label <LABEL>
 192.168.200.100 #指定VIP,不指定网卡,默认为eth0,注意:不指定/prefix,默认
为/32
192.168.200.101/24 dev eth1   #指定VIP的网卡,建议和interface指令指定的网卡不在一个
网卡
192.168.200.102/24 dev eth2 label eth2:1 #指定VIP的网卡label 
}
track_interface { #配置监控网络接口,一旦出现故障,则转为FAULT状态实现地址转移
eth0
eth
启用keepalived日志功能
[root@backup-kpa2 ~]# vim /usr/local/keepalived/etc/sysconfig/keepalived 
KEEPALIVED_OPTIONS="-D -S 6" 
[root@kpa2 ~]# vim /etc/rsyslog.conf
local6.*   /var/log/keepalived.log

keepalived独立子配置文件

当生产环境复杂时, /etc/keepalived/keepalived.conf 文件中内容过多,不易管理,可以将不同集 群的配置,比如:不同集群的VIP配置放在独立的子配置文件中

[root@kpa1 ~]# mkdir /etc/keepalived/conf.d
[root@kpa1 ~]# vim /etc/keepalived/keepalived.conf
global_defs {
   notification_email {
   root@localhost
        }
   notification_email_from keepalived@localhost
   smtp_server 127.0.0.1
   smtp_connect_timeout 30
   router_id kpa1.sxh.com
   vrrp_skip_check_adv_addr
   vrrp_garp_interval 0
   vrrp_gna_interval 0
   varrp_mcast_group4 224.0.0.18
}
include /etc/keepalived/conf.d/*.conf   #将VRRP相关配置放在子配置文件中
[root@kpa1 ~]# vim /etc/keepalived/conf.d/cluster1.conf

3实现VRRP

非抢占模式

默认为抢占模式 preempt,即当高优先级的主机恢复在线后,会抢占低先级的主机的master角色,造成 网络抖动,建议设置为非抢占模式 nopreempt ,即高优先级主机恢复后,并不会抢占低优先级主机的 master 角色

注意: 非抢占模式下,如果原主机down机, VIP迁移至的新主机, 后续新主机也发生down时,仍会将VIP迁移回原主机 
注意:要关闭 VIP抢占,必须将各 Keepalived 服务器 state 配置为 BACKUP

抢占延迟模式

抢占延迟模式,即优先级高的主机恢复后,不会立即抢回VIP,而是延迟一段时间(默认300s)再抢回 VIP

注意:需要各keepalived服务器state为BACKUP,并且不要启用 vrrp_strict

单播配置

默认keepalived主机之间利用组播相互通告消息,会造成网络拥塞,可以替换成单播,减少网络流量
注意:启用 vrrp_strict 时,不能启用单播

通知脚本配置

当keepalived的状态变化时,可以自动触发脚本的执行,比如:发邮件通知用户 默认以用户keepalived_script身份执行脚本,如果此用户不存在,以root执行脚本

通知脚本类型

1.当前节点成为主节点时触发的脚本
2.当前节点转为备节点时触发的脚本
3.当前节点转为“失败”状态时触发的脚本 
通用格式的通知触发机制,一个脚本可完成以上三种状态的转换时的通知
notify <STRING>|<QUOTED-STRING>
当停止VRRP时触发的脚本
notify_stop <STRING>|<QUOTED-STRING>

脚本的调用方法

在 vrrp_instance VI_1 语句块的末尾加下面行
notify_master "/etc/keepalived/notify.sh master"
notify_backup "/etc/keepalived/notify.sh backup"
notify_fault "/etc/keepalived/notify.sh fault"

综合实验

keepalived单主架构

1。master配置

[root@kpa1 ~]# vim /etc/keepalived/keepalived.conf
global_defs {
   notification_email {
   root@localhost#keepalived发生故障时邮件发送的对象,可以按行区分写多个
        }
   notification_email_from keepalived@localhost
   smtp_server 127.0.0.1
   smtp_connect_timeout 30
   router_id kpa1.sxh.com
   vrrp_skip_check_adv_addr#所有报文都检查比较消耗性能,此配置为如果收到的报文和上一个报文是同一个路由器则跳过检查报文中的源地址
   vrrp_garp_interval 0#ARP报文发送延迟
   vrrp_gna_interval 0#消息发送延迟
   varrp_mcast_group4 224.0.0.18 
   #默认组播IP地址,可指定组播范围:224.0.0.0到239.255.255.255
}

vrrp_instance VI_1 {
    state MASTER #在另一个节点上为BACKUP
    interface ens160
    virtual_router_id 66#每个虚拟路由器必须唯一,同属于一个虚拟路由器的多个Keepalived节点必须相同
    priority 100 #在另一个节点上为80
    advert_int 1
    authentication {
        auth_type PASS #预共享密钥认证,同一个虚拟路由器的keepalived节点必须一样
        auth_pass 12345678
    }
    virtual_ipaddress {
10.1.1.88
}
}

2.BACKUP配置

[root@kpa2 ~]# vim /etc/keepalived/keepalived.conf
! Configuration File for keepalived
global_defs {
   notification_email {
   root@localhost
        }
   notification_email_from keepalived@localhost
   smtp_server 127.0.0.1
   smtp_connect_timeout 30
   router_id kpa2.sxh.com
   vrrp_skip_check_adv_addr
   vrrp_garp_interval 0
   vrrp_gna_interval 0
   varrp_mcast_group4 224.0.0.18
}

vrrp_instance VI_1 {
    state BACKUP
    interface ens160
    virtual_router_id 66
    priority 80
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 12345678
    }
    virtual_ipaddress {
10.1.1.88
}
}

抓包分析

[root@kpa2 ~]# tcpdump -i ens160 -nn host 224.0.0.18
-n关闭ip地址反查域名
-nn取消反向dns的过程,立即打印抓包,并用数字显示ip端口之类的
i  网口编号数字或者网口别名  ,指定抓包的端口号和名称进行抓包
[root@kpa2 ~]# tcpdump -i ens160 -nn host 224.0.0.18
dropped privs to tcpdump
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ens160, link-type EN10MB (Ethernet), capture size 262144 bytes
14:57:25.300512 IP 10.1.1.162 > 224.0.0.18: VRRPv2, Advertisement, vrid 51, prio 100, authtype none, intvl 1s, length 20
14:57:25.748292 IP 10.1.1.161 > 224.0.0.18: VRRPv2, Advertisement, vrid 66, prio 100, authtype simple, intvl 1s, length 20
14:57:26.300769 IP 10.1.1.162 > 224.0.0.18: VRRPv2, Advertisement, vrid 51, prio 100, authtype none, intvl 1s, length 20
14:57:26.746514 IP 10.1.1.161 > 224.0.0.18: VRRPv2, Advertisement, vrid 66, prio 100, authtype simple, intvl 1s, length 20
14:57:27.302115 IP 10.1.1.162 > 224.0.0.18: VRRPv2, Advertisement, vrid 51, prio 100, authtype none, intvl 1s, length 20
14:57:27.747547 IP 10.1.1.161 > 224.0.0.18: VRRPv2, Advertisement, vrid 66, prio 100, authtype simple, intvl 1s, 

VIP单播配置

1.master配置
[root@kpa1 ~]# vim /etc/keepalived/keepalived.conf 

   smtp_server 127.0.0.1
   smtp_connect_timeout 30
   router_id kpa1.sxh.com
   vrrp_skip_check_adv_addr
   vrrp_garp_interval 0
   vrrp_gna_interval 0
   varrp_mcast_group4 224.0.0.18
}
include /etc/keepalived/conf.d/*.conf
vrrp_instance VI_1 {
    state MASTER
    interface ens160
    virtual_router_id 66
    priority 100
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 12345678
    }
    virtual_ipaddress {
10.1.1.88
}
        unicast_src_ip 10.1.1.1.161  #本机IP
        unicast_peer{
        10.1.1.162  #指向对方主机IP地址
        }
}
2.backup配置
[root@kpa2 ~]# vim /etc/keepalived/keepalived.conf 

        }
   notification_email_from keepalived@localhost
   smtp_server 127.0.0.1
   smtp_connect_timeout 30
   router_id kpa2.sxh.com
   vrrp_skip_check_adv_addr
   vrrp_garp_interval 0
   vrrp_gna_interval 0
   varrp_mcast_group4 224.0.0.18
}

vrrp_instance VI_1 {
    state BACKUP
    interface ens160
    virtual_router_id 66
    priority 80
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 12345678
    }
    virtual_ipaddress {
10.1.1.88
}
        unicast_src_ip 10.1.1.162  #本机IP
        unicast_peer {
        10.1.1.161  #指向对方主机IP
        }
}
3.抓包分析
[root@kpa1 ~]# tcpdump -i ens160 -nn src host 10.1.1.161 and dst 10.1.1.162
dropped privs to tcpdump
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ens160, link-type EN10MB (Ethernet), capture size 262144 bytes
15:52:48.226434 IP 10.1.1.161 > 10.1.1.162: VRRPv2, Advertisement, vrid 66, prio 100, authtype simple, intvl 1s, length 20
15:52:49.227488 IP 10.1.1.161 > 10.1.1.162: VRRPv2, Advertisement, vrid 66, prio 100, authtype simple, intvl 1s, length 20
15:52:50.228497 IP 10.1.1.161 > 10.1.1.162: VRRPv2, Advertisement, vrid 66, prio 100, authtype simple, intvl 1s, length 20
15:52:51.229598 IP 10.1.1.161 > 10.1.1.162: VRRPv2, Advertisement, vrid 66, prio 100, authtype simple, intvl 1s, 

状态切换的通知脚本

QQ邮箱配置
[root@kpa1 ~]# vim /etc/mail.rc
set from=3059955740@qq.com
set smtp=smtp.qq.com
set smtp-auth-user=3059955740@qq.com
set smtp-auth-password=zoboduhoqcqcdfhf
set smtp-auth=login
[root@kpa1 ~]# yum -y install mailx
#发送邮件测试
[root@kpa1 ~]# echo "Test Mail 30599555740" |mail -s warning 3059955740@qq.com

创建通知脚本

[root@kpa1 ~]# cat /etc/keepalived/notify.sh 
#!/bin/bash
contact='3059955740@qq.com'
notify() {
	mailsubject="(hostname) to be $1,vip floating"
	mailbody="$(date +'%F %T'): vrrp transition, $(hostname) changed to be $1"
	echo "$mailbody" |mail -s "$mailsubject" $contact
}
case $1 in
master)
	notify master
	;;
backup)
	notify backup
	;;
fault)
	notify fault
	;;
*)
	echo "Usage: $(basename $0) {master|backup|fault}"
	exit 1
	;;
esac
[root@kpa1 ~]# chmod a+x /etc/keepalived/notify.sh 
[root@kpa1 ~]# vim /etc/keepalived/keepalived.conf
vrrp_instance VI_1 {
    state MASTER
    interface ens160
    virtual_router_id 66
    priority 100
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 12345678
    }
    virtual_ipaddress {
10.1.1.88
}
        unicast_src_ip 10.1.1.1.161
        unicast_peer{
        10.1.1.162
        }

notify_master "/etc/keepalived/notify.sh master"
notify_backup "/etc/keepalived/notify.sh backup"
notify_fault "/etc/keepalived/notify.sh fault"
}
[root@kpa2 ~]# vim /etc/keepalived/keepalived.conf 
! Configuration File for keepalived
global_defs {
   notification_email {
   root@localhost
        }
   notification_email_from keepalived@localhost
   smtp_server 127.0.0.1
   smtp_connect_timeout 30
   router_id kpa2.sxh.com
   vrrp_skip_check_adv_addr
   vrrp_garp_interval 0
   vrrp_gna_interval 0
   varrp_mcast_group4 224.0.0.18
}

vrrp_instance VI_1 {
    state BACKUP
    interface ens160
    virtual_router_id 66
    priority 80
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 12345678
    }
    virtual_ipaddress {
10.1.1.88

notify_master "/etc/keepalived/notify.sh master"
notify_backup "/etc/keepalived/notify.sh backup"
notify_fault "/etc/keepalived/notify.sh fault"
}
        unicast_src_ip 10.1.1.162
        10.1.1.161
}

验证邮件通知

#关闭master keepalived
[root@kpa1 ~]# systemctl stop keepalived.service

在这里插入图片描述

在这里插入图片描述

  • 5
    点赞
  • 10
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
keepalived mysql双主是一种实现MySQL数据库高可用性的方案。它的基本思路是通过keepalived配置虚拟IP,将两台MySQL数据库互为主从关系,保证数据的一致性。当其中一台MySQL数据库宕机后,应用能够自动切换到另外一台MySQL数据库,从而保证系统的高可用性。\[1\]在配置过程中,需要确保两台MySQL数据库的数据完全一样,并且需要进行一些操作,如重启mysql服务等。\[2\]这样,两台MySQL服务器就可以同时作为主节点和从节点,实现双主双活的功能,每个数据库都可以作为主数据库使用,并将对数据库操作的数据同步至另外一台MySQL服务器中。\[3\] #### 引用[.reference_title] - *1* [mysql双主之keepalived](https://blog.csdn.net/m0_46648661/article/details/121803916)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v91^control_2,239^v3^insert_chatgpt"}} ] [.reference_item] - *2* *3* [Mysql集群之mysql双主双活+keepalived实现高可用_mysql+keepalived搭建教程](https://blog.csdn.net/a360284634/article/details/89892028)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v91^control_2,239^v3^insert_chatgpt"}} ] [.reference_item] [ .reference_list ]

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值