keepalived实现nginx负载均衡机高可用

系统主机名IP部署服务
Rocky-9.3lb1192.168.117.10(nginx、keepalived)
Rocky-9.3lb2192.168.117.11(nginx、keepalived)
Rocky-9.3rs1192.168.117.12(httpd)
Rocky-9.3rs2192.168.117.13(httpd)

192.168.117.12端

[root@rs1 ~]# yum -y install vim httpd
[root@rs1 ~]# systemctl enable --now httpd
Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service →
/usr/lib/systemd/system/httpd.service.
[root@rs1 ~]# cd /var/www/html/
[root@rs1 html]# echo 'rs1' > index.html

192.168.117.13端

[root@rs2 ~]# yum -y install vim httpd
[root@rs2 ~]# systemctl enable --now httpd
Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service →
/usr/lib/systemd/system/httpd.service.
[root@rs2 ~]# cd /var/www/html/
[root@rs2 html]# echo 'rs2' > index.html

192.168.117.10端

[root@lb1 ~]# yum -y install vim nginx
[root@lb1 ~]# systemctl enable --now nginx
[root@lb1 ~]# yum -y install keepalived
[root@lb1 ~]# cd /etc/nginx/
[root@lb1 nginx]# vim nginx.conf
    upstream webs {
        server 192.168.117.12;
        server 192.168.117.13;
    }

    server {
        listen       80;
        listen       [::]:80;
        server_name  _;
        root         /usr/share/nginx/html;

        location / {
        proxy_pass http://webs;
        }
[root@lb1 nginx]# systemctl restart nginx
[root@lb1 nginx]# curl 192.168.117.10
rs1
[root@lb1 nginx]# curl 192.168.117.10
rs2
[root@lb1 keepalived]# mkdir /scripts
[root@lb1 keepalived]# cd /scripts/
[root@lb1 scripts]#  vim check_nginx.sh
#!/bin/bash
nginx_status=$(ps -ef|grep -Ev "grep|$0"|grep '\bnginx\b'|wc -l)
if [ $nginx_status -lt 1 ];then
        systemctl stop keepalived
fi
[root@lb1 scripts]# chmod +x check_nginx.sh
[root@lb1 ~]# cd /etc/keepalived/
[root@lb1 keepalived]# mv keepalived.conf keepalived.conf.bak
[root@lb1 keepalived]# ls
keepalived.conf.bak
[root@lb1 keepalived]# vim keepalived.conf
! Configuration File for keepalived

global_defs {
        router_id lb1
}

vrrp_script nginx_check {
     script "/scripts/check_nginx.sh"
     interval 1
     weight -20
}

vrrp_instance VI_1 {
    state BACKUP
    interface ens160
    virtual_router_id 120
    priority 150
    nopreempt    //不抢占
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 000000
        }

virtual_ipaddress {
    192.168.117.200
    }
}

track_script {
    nginx_check
   }
}

virtual_server 192.168.117.200 80 {
    delay_loop 6
    lb_algo rr
    lb_kind DR
    persistence_timeout 50
    protocol TCP

real_server 192.168.117.10 80 {
    weight 1
    TCP_CHECK {
    connect_port 80
    connect_timeout 3
    nb_get_retry 3
    delay_before_retry 3
    }
}

real_server 192.168.117.11 80 {
    weight 1
    TCP_CHECK {
    connect_port 80
    connect_timeout 3
    nb_get_retry 3
    delay_before_retry 3
      }
   }
}
[root@lb1 keepalived]# systemctl enable --now keepalived
Created symlink /etc/systemd/system/multi-user.target.wants/keepalived.service →
/usr/lib/systemd/system/keepalived.service.

192.168.11端

[root@lb2 ~]# yum -y install vim nginx
[root@lb2 ~]# systemctl enable --now nginx
[root@lb2 ~]# yum -y install keepalived
[root@lb2 nginx]# vim nginx.conf
    upstream webs {
        server 192.168.117.12;
        server 192.168.117.13;
    }

    server {
        listen       80;
        listen       [::]:80;
        server_name  _;
        root         /usr/share/nginx/html;

        location / {
        proxy_pass http://webs;
        }
[root@lb2 nginx]# systemctl restart nginx
[root@lb2 nginx]# curl 192.168.117.11
rs1
[root@lb2 nginx]# curl 192.168.117.11
rs2
[root@lb2 ~]# mkdir /scripts
[root@lb2 ~]# cd /scripts/
[root@lb2 scripts]# vim notify.sh
#!/bin/bash
case "$1" in
  master)
        nginx_status=$(ps -ef|grep -Ev "grep|$0"|grep '\bnginx\b'|wc -l)
        if [ $nginx_status -lt 1 ];then
          systemctl start nginx
        fi
  ;;
  backup)
        nginx_status=$(ps -ef|grep -Ev "grep|$0"|grep '\bnginx\b'|wc -l)
        if [ $nginx_status -gt 0 ];then
          systemctl stop nginx
  fi
  ;;
  *)
        echo "Usage:$0 master|backup"
  ;;
esac
[root@lb2 scripts]# chmod +x notify.sh
[root@lb2 ~]# cd /etc/keepalived/
[root@lb2 keepalived]# mv keepalived.conf keepalived.conf.bak
[root@lb2 keepalived]# ls
keepalived.conf.bak
[root@lb2 keepalived]# vim keepalived.conf
! Configuration File for keepalived

global_defs {
        router_id lb2
}

vrrp_instance VI_1 {
    state BACKUP
    interface ens160
    virtual_router_id 120
    priority 100
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 000000
        }

virtual_ipaddress {
    192.168.117.200
    }
    notify_master "/scripts/notify.sh master"
    notify_backup "/scripts/notify.sh backup"
}

virtual_server 192.168.117.200 80 {
    delay_loop 6
    lb_algo rr
    lb_kind DR
    persistence_timeout 50
    protocol TCP

real_server 192.168.117.10 80 {
    weight 1
    TCP_CHECK {
    connect_port 80
    connect_timeout 3
    nb_get_retry 3
    delay_before_retry 3
    }
}

real_server 192.168.117.11 80 {
    weight 1
    TCP_CHECK {
    connect_port 80
    connect_timeout 3
    nb_get_retry 3
    delay_before_retry 3
      }
   }
}
[root@lb2 keepalived]# systemctl enable --now keepalived
Created symlink /etc/systemd/system/multi-user.target.wants/keepalived.service →
/usr/lib/systemd/system/keepalived.service.

测试

lb1
[root@lb1 ~]# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:0c:29:60:f3:c5 brd ff:ff:ff:ff:ff:ff
    altname enp3s0
    inet 192.168.117.10/24 brd 192.168.117.255 scope global noprefixroute ens160
       valid_lft forever preferred_lft forever
    inet 192.168.117.200/32 scope global ens160
       valid_lft forever preferred_lft forever
    inet6 fe80::20c:29ff:fe60:f3c5/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever
[root@lb1 ~]# systemctl stop nginx
[root@lb1 ~]# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:0c:29:60:f3:c5 brd ff:ff:ff:ff:ff:ff
    altname enp3s0
    inet 192.168.117.10/24 brd 192.168.117.255 scope global noprefixroute ens160
       valid_lft forever preferred_lft forever
    inet6 fe80::20c:29ff:fe60:f3c5/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever
[root@lb1 ~]# curl 192.168.116.200
rs1
[root@lb1 ~]# curl 192.168.116.200
rs2

lb2
[root@lb2 scripts]# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:0c:29:0f:bd:fb brd ff:ff:ff:ff:ff:ff
    altname enp3s0
    inet 192.168.117.11/24 brd 192.168.117.255 scope global noprefixroute ens160
       valid_lft forever preferred_lft forever
    inet 192.168.117.200/32 scope global ens160
       valid_lft forever preferred_lft forever
    inet6 fe80::20c:29ff:fe0f:bdfb/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever
[root@lb2 ~]# curl 192.168.116.200
rs1
[root@lb2 ~]# curl 192.168.116.200
rs2

lb1恢复
[root@lb1 ~]# systemctl start nginx keepalived
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值