首先须要服务器关都闭防火墙和selinuxhtml
1,准备四台nginx服务器,两台作代理,两台作后端真实服务器。linux
2,配置两台真实服务器
第一台:nginx
[root@vm-4 ~]# systemctl start nginx [root@vm-4 ~]# systemctl enable nginx [root@vm-4 conf.d]# echo "server111" > /usr/share/nginx/html/index.html 测试: [root@vm-4 conf.d]# curl localhost server111
第二台:vim
[root@vm-5 ~]# systemctl start nginx [root@vm-5 ~]# systemctl enable nginx [root@vm-5 conf.d]# echo "server222" > /usr/share/nginx/html/index.html 测试: [root@vm-5 conf.d]# curl localhost server222
3,配置两台nginx代理服务器 后端
[root@vm-2 ~]# systemctl start nginx [root@vm-2 ~]# systemctl enable nginx [root@vm-2 ~]# cd /etc/nginx/conf.d/ [root@vm-2 conf.d]# cp default.conf proxy.conf [root@vm-2 conf.d]# mv default.conf default.conf.bak [root@vm-2 conf.d]# vi upstream.conf upstream nginx_pool { server 10.30.161.241:80 weight=1 max_fails=2 fail_timeout=2; server 10.30.161.242:80 weight=1 max_fails=2 fail_timeout=2; } [root@vm-2 conf.d]# vi proxy.conf location / { proxy_pass http://nginx_pool; proxy_redirect default; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header REMOTE-HOST $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; }
将nginx的配置文件拷贝到另外一台代理服务器中:bash
[root@vm-2 conf.d]# scp proxy.conf upstream.conf 10.30.161.214:/etc/nginx/conf.d/ 分别重启nginx: systemctl restart nginx
4, 两台代理服务器分别安装软件服务器
master: [root@vm-2 conf.d]# yum install -y keepalived [root@vm-2 conf.d]# cp /etc/keepalived/keepalived.conf /etc/keepalived/keepalived.conf.bak [root@vm-2 conf.d]# vim /etc/keepalived/keepalived.conf
配置keepalived,将里面内容所有删除,添加下列内容:curl
! Configuration File for keepalived global_defs { router_id director1 #辅助改成director2 } vrrp_instance VI_1 { state MASTER #定义主仍是备 interface ens33 #VIP绑定接口 virtual_router_id 80 #整个集群的调度器一致 priority 100 #back改成50 advert_int 1 authentication { auth_type PASS auth_pass 1111 } virtual_ipaddress { 10.30.161.200/24 #设置VIP } } backup: [root@yum_nginx ~]# cp /etc/keepalived/keepalived.conf [root@yum_nginx ~]# vi /etc/keepalived/keepalived.conf 配置keepalived,将里面内容所有删除,添加下列内容: ! Configuration File for keepalived global_defs { router_id directory2 } vrrp_instance VI_1 { state BACKUP interface ens33 nopreempt virtual_router_id 80 priority 50 advert_int 1 authentication { auth_type PASS auth_pass 1111 } virtual_ipaddress { 10.30.161.200/24 } }
五、两台代理服务器分别启动keepalivedide
[root@yum_nginx ~]# systemctl enable keepalived.service [root@yum_nginx ~]# systemctl start keepalived.service
六、检测是否成功测试
在master上 ip a 可显示VIP为10.30.161.200/24 2: ens33: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:0c:29:29:a6:12 brd ff:ff:ff:ff:ff:ff inet 10.30.161.51/24 brd 10.30.161.255 scope global dynamic ens33 valid_lft 168379sec preferred_lft 168379sec inet 10.30.161.200/24 scope global secondary ens33 valid_lft forever preferred_lft forever inet6 fe80::8cfe:8d87:6478:baee/64 scope link valid_lft forever preferred_lft forever inet6 fe80::d9c7:8228:5b45:afed/64 scope link tentative dadfailed valid_lft forever preferred_lft forever
用curl访问VIP,正常轮询
[root@vm-5 conf.d]# curl 10.30.161.200 server111 [root@vm-5 conf.d]# curl 10.30.161.200 server222 [root@vm-5 conf.d]# curl 10.30.161.200 server111 [root@vm-5 conf.d]# curl 10.30.161.200 server222 测试当一台master故障 [root@vm-2 conf.d]# systemctl stop keepalived ip a 发现VIP偏移到backup代理服务器上
到此:
能够解决心跳故障keepalived
但不能解决Nginx服务故障
扩展对调度器Nginx健康检查(可选)两台都设置
思路:
让Keepalived以必定时间间隔执行一个外部脚本,脚本的功能是当Nginx失败,则关闭本机的Keepalived
(1) script
[root@nginx-proxy-master ~]# vim /etc/keepalived/check_nginx_status.sh
#!/bin/bash
#+检查nginx进程是否存在
counter=$(ps -C nginx --no-heading|wc -l) #此行有服务名
if [ "${counter}" = "0" ]; then
#尝试启动一次nginx,中止5秒后再次检测
systemctl start nginx #启动服务
sleep 5
counter=$(ps -C nginx --no-heading|wc -l) #此行有服务名
if [ "${counter}" = "0" ]; then
#若是启动没成功,就杀掉keepalive触发主备切换
service keepalived stop
fi
fi
[root@nginx-proxy-master ~]# chmod a+x /etc/keepalived/check_nginx_status.sh
(2). keepalived使用script
! Configuration File for keepalived global_defs { router_id director1 } vrrp_script check_nginx { #健康检测模块调用 script "/etc/keepalived/check_nginx_status.sh" #指定脚本 interval 5 #检查频率,秒 } vrrp_instance VI_1 { state MASTER interface ens33 virtual_router_id 80 priority 100 advert_int 1 authentication { auth_type PASS auth_pass 1111 } virtual_ipaddress { 192.168.246.16/24 } track_script { 引用脚本 check_nginx } }
注:必须先启动nginx,再启动keepalived