系统 | 主机名 | IP | 部署服务 |
---|---|---|---|
Rocky-9.3 | lb1 | 192.168.117.10 | (nginx、keepalived) |
Rocky-9.3 | lb2 | 192.168.117.11 | (nginx、keepalived) |
Rocky-9.3 | rs1 | 192.168.117.12 | (httpd) |
Rocky-9.3 | rs2 | 192.168.117.13 | (httpd) |
192.168.117.12端
[root@rs1 ~]# yum -y install vim httpd
[root@rs1 ~]# systemctl enable --now httpd
Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service →
/usr/lib/systemd/system/httpd.service.
[root@rs1 ~]# cd /var/www/html/
[root@rs1 html]# echo 'rs1' > index.html
192.168.117.13端
[root@rs2 ~]# yum -y install vim httpd
[root@rs2 ~]# systemctl enable --now httpd
Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service →
/usr/lib/systemd/system/httpd.service.
[root@rs2 ~]# cd /var/www/html/
[root@rs2 html]# echo 'rs2' > index.html
192.168.117.10端
[root@lb1 ~]# yum -y install vim nginx
[root@lb1 ~]# systemctl enable --now nginx
[root@lb1 ~]# yum -y install keepalived
[root@lb1 ~]# cd /etc/nginx/
[root@lb1 nginx]# vim nginx.conf
upstream webs {
server 192.168.117.12;
server 192.168.117.13;
}
server {
listen 80;
listen [::]:80;
server_name _;
root /usr/share/nginx/html;
location / {
proxy_pass http://webs;
}
[root@lb1 nginx]# systemctl restart nginx
[root@lb1 nginx]# curl 192.168.117.10
rs1
[root@lb1 nginx]# curl 192.168.117.10
rs2
[root@lb1 keepalived]# mkdir /scripts
[root@lb1 keepalived]# cd /scripts/
[root@lb1 scripts]# vim check_nginx.sh
#!/bin/bash
nginx_status=$(ps -ef|grep -Ev "grep|$0"|grep '\bnginx\b'|wc -l)
if [ $nginx_status -lt 1 ];then
systemctl stop keepalived
fi
[root@lb1 scripts]# chmod +x check_nginx.sh
[root@lb1 ~]# cd /etc/keepalived/
[root@lb1 keepalived]# mv keepalived.conf keepalived.conf.bak
[root@lb1 keepalived]# ls
keepalived.conf.bak
[root@lb1 keepalived]# vim keepalived.conf
! Configuration File for keepalived
global_defs {
router_id lb1
}
vrrp_script nginx_check {
script "/scripts/check_nginx.sh"
interval 1
weight -20
}
vrrp_instance VI_1 {
state BACKUP
interface ens160
virtual_router_id 120
priority 150
nopreempt //不抢占
advert_int 1
authentication {
auth_type PASS
auth_pass 000000
}
virtual_ipaddress {
192.168.117.200
}
}
track_script {
nginx_check
}
}
virtual_server 192.168.117.200 80 {
delay_loop 6
lb_algo rr
lb_kind DR
persistence_timeout 50
protocol TCP
real_server 192.168.117.10 80 {
weight 1
TCP_CHECK {
connect_port 80
connect_timeout 3
nb_get_retry 3
delay_before_retry 3
}
}
real_server 192.168.117.11 80 {
weight 1
TCP_CHECK {
connect_port 80
connect_timeout 3
nb_get_retry 3
delay_before_retry 3
}
}
}
[root@lb1 keepalived]# systemctl enable --now keepalived
Created symlink /etc/systemd/system/multi-user.target.wants/keepalived.service →
/usr/lib/systemd/system/keepalived.service.
192.168.11端
[root@lb2 ~]# yum -y install vim nginx
[root@lb2 ~]# systemctl enable --now nginx
[root@lb2 ~]# yum -y install keepalived
[root@lb2 nginx]# vim nginx.conf
upstream webs {
server 192.168.117.12;
server 192.168.117.13;
}
server {
listen 80;
listen [::]:80;
server_name _;
root /usr/share/nginx/html;
location / {
proxy_pass http://webs;
}
[root@lb2 nginx]# systemctl restart nginx
[root@lb2 nginx]# curl 192.168.117.11
rs1
[root@lb2 nginx]# curl 192.168.117.11
rs2
[root@lb2 ~]# mkdir /scripts
[root@lb2 ~]# cd /scripts/
[root@lb2 scripts]# vim notify.sh
#!/bin/bash
case "$1" in
master)
nginx_status=$(ps -ef|grep -Ev "grep|$0"|grep '\bnginx\b'|wc -l)
if [ $nginx_status -lt 1 ];then
systemctl start nginx
fi
;;
backup)
nginx_status=$(ps -ef|grep -Ev "grep|$0"|grep '\bnginx\b'|wc -l)
if [ $nginx_status -gt 0 ];then
systemctl stop nginx
fi
;;
*)
echo "Usage:$0 master|backup"
;;
esac
[root@lb2 scripts]# chmod +x notify.sh
[root@lb2 ~]# cd /etc/keepalived/
[root@lb2 keepalived]# mv keepalived.conf keepalived.conf.bak
[root@lb2 keepalived]# ls
keepalived.conf.bak
[root@lb2 keepalived]# vim keepalived.conf
! Configuration File for keepalived
global_defs {
router_id lb2
}
vrrp_instance VI_1 {
state BACKUP
interface ens160
virtual_router_id 120
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass 000000
}
virtual_ipaddress {
192.168.117.200
}
notify_master "/scripts/notify.sh master"
notify_backup "/scripts/notify.sh backup"
}
virtual_server 192.168.117.200 80 {
delay_loop 6
lb_algo rr
lb_kind DR
persistence_timeout 50
protocol TCP
real_server 192.168.117.10 80 {
weight 1
TCP_CHECK {
connect_port 80
connect_timeout 3
nb_get_retry 3
delay_before_retry 3
}
}
real_server 192.168.117.11 80 {
weight 1
TCP_CHECK {
connect_port 80
connect_timeout 3
nb_get_retry 3
delay_before_retry 3
}
}
}
[root@lb2 keepalived]# systemctl enable --now keepalived
Created symlink /etc/systemd/system/multi-user.target.wants/keepalived.service →
/usr/lib/systemd/system/keepalived.service.
测试
lb1
[root@lb1 ~]# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 00:0c:29:60:f3:c5 brd ff:ff:ff:ff:ff:ff
altname enp3s0
inet 192.168.117.10/24 brd 192.168.117.255 scope global noprefixroute ens160
valid_lft forever preferred_lft forever
inet 192.168.117.200/32 scope global ens160
valid_lft forever preferred_lft forever
inet6 fe80::20c:29ff:fe60:f3c5/64 scope link noprefixroute
valid_lft forever preferred_lft forever
[root@lb1 ~]# systemctl stop nginx
[root@lb1 ~]# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 00:0c:29:60:f3:c5 brd ff:ff:ff:ff:ff:ff
altname enp3s0
inet 192.168.117.10/24 brd 192.168.117.255 scope global noprefixroute ens160
valid_lft forever preferred_lft forever
inet6 fe80::20c:29ff:fe60:f3c5/64 scope link noprefixroute
valid_lft forever preferred_lft forever
[root@lb1 ~]# curl 192.168.116.200
rs1
[root@lb1 ~]# curl 192.168.116.200
rs2
lb2
[root@lb2 scripts]# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 00:0c:29:0f:bd:fb brd ff:ff:ff:ff:ff:ff
altname enp3s0
inet 192.168.117.11/24 brd 192.168.117.255 scope global noprefixroute ens160
valid_lft forever preferred_lft forever
inet 192.168.117.200/32 scope global ens160
valid_lft forever preferred_lft forever
inet6 fe80::20c:29ff:fe0f:bdfb/64 scope link noprefixroute
valid_lft forever preferred_lft forever
[root@lb2 ~]# curl 192.168.116.200
rs1
[root@lb2 ~]# curl 192.168.116.200
rs2
lb1恢复
[root@lb1 ~]# systemctl start nginx keepalived