LVS高可用(六)LVS+keepalived主从 篇中提到了LVS的高可用及后端的LB,不过一台LVS提供服务,另一台只做为backup,显然是种浪费,实际现网应用中比较多的用法是,两台LVS都作为MASTER节点,互相做为另一台的backup 。具体架构如下:

lvs keepalived master master
lvs keepalived master master

注:与master-backup 架构相比, master-master架构需要多加一个VIP地址。

一、IP及规划

主机名 IP地址
realserver 192.168.122.10
realserver 192.168.122.20
director 192.168.122.30
director 192.168.122.40
VIP 192.168.122.100
VIP 192.168.122.110

同上一篇,两台realserver还是安装httpd ,两台director安装ipvsadm、keepalived 。realserver的回环地址上会配置两个VIP的地址。另外操作前,需要先将几台主机的时间同步掉。

二、director主机配置

MASTER HostA主机的配置如下

 1[root@lvs-dr ~]# cat /etc/keepalived/keepalived.conf
 2vrrp_instance bl_one {
 3    state MASTER             #指定Keepalived的角色,MASTER为主服务器,BACKUP为备用服务器
 4    interface eth0           #指定HA监测的接口
 5    lvs_sync_daemon_interface eth0
 6    virtual_router_id 38     #虚拟路由标识(1-255),在一个VRRP实例中主备服务器ID必须一样
 7    priority 150             #优先级,数字越大越优先,主服务器优先级必须高于备服务器
 8    advert_int 3             #设置主备之间同步检查时间间隔,单位秒
 9    authentication {
10        auth_type PASS
11        auth_pass 1111
12    }
13    virtual_ipaddress { #定义虚拟IP地址
14      192.168.122.100
15    }
16}
17vrrp_instance bl_two {
18    state BACKUP
19    interface eth0
20    lvs_sync_daemon_interface eth0
21    virtual_router_id 48
22    priority 120
23    advert_int 3
24    authentication {
25        auth_type PASS
26        auth_pass 1111
27    }
28    virtual_ipaddress {
29      192.168.122.110
30    }
31}
32virtual_server 192.168.122.100 80 {
33    delay_loop 3                    #设置健康状态检查时间
34    lb_algo rr                      #设置负载调度算法
35    lb_kind DR                      #设置LVS实现负载均衡的机制
36    persistence_timeout 50          #会话保持时间
37    protocol TCP
38    real_server 192.168.122.10 80 {
39        weight 1
40        TCP_CHECK {
41            connect_timeout 10       #设置响应超时时间
42            nb_get_retry 3           #设置超时重试次数
43            delay_before_retry 3     #设置超时重试间隔
44            connect_port 80
45        }
46    }
47    real_server 192.168.122.20 80 {
48        weight 1
49        TCP_CHECK {
50            connect_timeout 10
51            nb_get_retry 3
52            delay_before_retry 3
53            connect_port 80
54        }
55    }
56}
57virtual_server 192.168.122.110 80 {
58    delay_loop 3
59    lb_algo rr
60    lb_kind DR
61    persistence_timeout 50
62    protocol TCP
63    real_server 192.168.122.10 80 {
64        weight 1
65        HTTP_GET {
66            url {
67                 path /index.html
68                 status_code 200
69              }
70            connect_timeout 10
71            nb_get_retry 3
72            delay_before_retry 3
73            connect_port 80
74        }
75    }
76    real_server 192.168.122.20 80 {
77        weight 1
78        HTTP_GET {
79            url {
80                 path /index.html
81                 status_code 200
82              }
83            connect_timeout 10
84            nb_get_retry 3
85            delay_before_retry 3
86            connect_port 80
87        }
88    }
89}

MASTER HostB主机的配置如下

 1[root@lvs-dr2 ~]# cat /etc/keepalived/keepalived.conf
 2vrrp_instance bl_one {
 3    state BACKUP
 4    interface eth0
 5    lvs_sync_daemon_interface eth0
 6    virtual_router_id 38
 7    priority 120
 8    advert_int 3
 9    authentication {
10        auth_type PASS
11        auth_pass 1111
12    }
13    virtual_ipaddress {
14      192.168.122.100
15    }
16}
17vrrp_instance bl_two {
18    state MASTER
19    interface eth0
20    lvs_sync_daemon_interface eth0
21    virtual_router_id 48
22    priority 150
23    advert_int 3
24    authentication {
25        auth_type PASS
26        auth_pass 1111
27    }
28    virtual_ipaddress {
29      192.168.122.110
30    }
31}
32virtual_server 192.168.122.100 80 {
33    delay_loop 3
34    lb_algo rr
35    lb_kind DR
36    persistence_timeout 50
37    protocol TCP
38    real_server 192.168.122.10 80 {
39        weight 1
40        TCP_CHECK {
41            connect_timeout 10
42            nb_get_retry 3
43            delay_before_retry 3
44            connect_port 80
45        }
46    }
47    real_server 192.168.122.20 80 {
48        weight 1
49        TCP_CHECK {
50            connect_timeout 10
51            nb_get_retry 3
52            delay_before_retry 3
53            connect_port 80
54        }
55    }
56}
57virtual_server 192.168.122.110 80 {
58    delay_loop 3
59    lb_algo rr
60    lb_kind DR
61    persistence_timeout 50
62    protocol TCP
63    real_server 192.168.122.10 80 {
64        weight 1
65        HTTP_GET {
66            url {
67                 path /index.html
68                 status_code 200
69              }
70            connect_timeout 10
71            nb_get_retry 3
72            delay_before_retry 3
73            connect_port 80
74        }
75    }
76    real_server 192.168.122.20 80 {
77        weight 1
78        HTTP_GET {
79            url {
80                 path /index.html
81                 status_code 200
82              }
83            connect_timeout 10
84            nb_get_retry 3
85            delay_before_retry 3
86            connect_port 80
87        }
88    }
89}

以上创建了两个实例lb_one、lb_two ,其中A主机做为VIP1地址的master,B主机做为VIP2地址的master,A、B主机互为backup 。另外还有一个技巧点,在master-backup架构中也可以配置多个VIP地址,只需要在实例的VIP配置中增加地址、并在后面指定对应的虚地址后面的realserver即可。在主备脚架中配置多个VIP的方法如下:

1virtual_ipaddress {
2  192.168.122.100
3  192.168.122.110
4  ………………
5}

三、realserver主机配置

两台realserver主机的配置启停脚本如下:

 1[root@lvs01 ~]# cat dr_client.sh
 2#!/bin/bash
 3VIP1=192.168.122.100
 4VIP2=192.168.122.110
 5#vip's broadcast
 6BROADCAST=192.168.122.255
 7. /etc/rc.d/init.d/functions
 8case "$1" in
 9 start)
10  echo "reparing for Real Server"
11    echo "1" >/proc/sys/net/ipv4/conf/lo/arp_ignore
12    echo "2" >/proc/sys/net/ipv4/conf/lo/arp_announce
13    echo "1" >/proc/sys/net/ipv4/conf/all/arp_ignore
14    echo "2" >/proc/sys/net/ipv4/conf/all/arp_announce
15    ifconfig lo:0 $VIP1 netmask 255.255.255.255 broadcast $BROADCAST up
16    ifconfig lo:1 $VIP2 netmask 255.255.255.255 broadcast $BROADCAST up
17     /sbin/route add -host $VIP1 dev lo:0
18     /sbin/route add -host $VIP2 dev lo:0
19     ;;
20 stop)
21     ifconfig lo:0 down
22     ifconfig lo:1 down
23    echo "0" >/proc/sys/net/ipv4/conf/lo/arp_ignore
24    echo "0" >/proc/sys/net/ipv4/conf/lo/arp_announce
25    echo "0" >/proc/sys/net/ipv4/conf/all/arp_ignore
26    echo "0" >/proc/sys/net/ipv4/conf/all/arp_announce
27     ;;
28 *)
29     echo "Usage: lvs {start|stop}"
30     exit 1
31esac

四、验证

启动服务后,查看两台director和realserver主机的地址信息如下:

master hostA主机的IP信息如下:

 1[root@lvs-dr ~]# ip add show
 21: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN
 3    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
 4    inet 127.0.0.1/8 scope host lo
 5    inet6 ::1/128 scope host
 6       valid_lft forever preferred_lft forever
 72: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
 8    link/ether 52:54:00:39:42:be brd ff:ff:ff:ff:ff:ff
 9    inet 192.168.122.30/24 brd 192.168.122.255 scope global eth0
10    inet 192.168.122.100/32 scope global eth0
11    inet6 fe80::5054:ff:fe39:42be/64 scope link
12       valid_lft forever preferred_lft forever

master hostB主机的IP信息如下:

 1[root@lvs-dr2 ~]# ip add show
 21: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN
 3    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
 4    inet 127.0.0.1/8 scope host lo
 5    inet6 ::1/128 scope host
 6       valid_lft forever preferred_lft forever
 72: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
 8    link/ether 52:54:00:7b:f2:1a brd ff:ff:ff:ff:ff:ff
 9    inet 192.168.122.40/24 brd 192.168.122.255 scope global eth0
10    inet 192.168.122.110/32 scope global eth0
11    inet6 fe80::5054:ff:fe7b:f21a/64 scope link
12       valid_lft forever preferred_lft forever

realserver主机的IP信息如下:

 1[root@lvs01 ~]# ip add show
 21: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN
 3    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
 4    inet 127.0.0.1/8 scope host lo
 5    inet 192.168.122.100/32 brd 192.168.122.255 scope global lo:0
 6    inet 192.168.122.110/32 brd 192.168.122.255 scope global lo:1
 7    inet6 ::1/128 scope host
 8       valid_lft forever preferred_lft forever
 92: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
10    link/ether 52:54:00:a9:3b:6a brd ff:ff:ff:ff:ff:ff
11    inet 192.168.122.10/24 brd 192.168.122.255 scope global eth0
12    inet6 fe80::5054:ff:fea9:3b6a/64 scope link
13       valid_lft forever preferred_lft forever

以上可以看到,VIP在master节点上可以看到,另一个VIP同样只在该实例的master上可以看到,在两台realserver上的回环地址上有两个VIP地址。

分别到各VIP的主节点上通过ipvadm查看,可以获取到对的连接信息,如下:

 1[root@lvs-dr ~]# ipvsadm -Ln
 2IP Virtual Server version 1.2.1 (size=4096)
 3Prot LocalAddress:Port Scheduler Flags
 4  -> RemoteAddress:Port           Forward Weight ActiveConn InActConn
 5TCP  192.168.122.100:80 rr persistent 1
 6  -> 192.168.122.10:80            Route   1      0          12
 7  -> 192.168.122.20:80            Route   1      0          11
 8TCP  192.168.122.110:80 rr persistent 1
 9  -> 192.168.122.10:80            Route   1      0          0
10  -> 192.168.122.20:80            Route   1      0          0

更详细的测试步骤略过 。