這篇“如何用Keepalived+Nginx+Tomcat實(shí)現(xiàn)高可用Web集群”文章的知識(shí)點(diǎn)大部分人都不太理解,所以小編給大家總結(jié)了以下內(nèi)容,內(nèi)容詳細(xì),步驟清晰,具有一定的借鑒價(jià)值,希望大家閱讀完這篇文章能有所收獲,下面我們一起來看看這篇“如何用Keepalived+Nginx+Tomcat實(shí)現(xiàn)高可用Web集群”文章吧。
創(chuàng)新互聯(lián)一直在為企業(yè)提供服務(wù),多年的磨煉,使我們?cè)趧?chuàng)意設(shè)計(jì),全網(wǎng)營(yíng)銷推廣到技術(shù)研發(fā)擁有了開發(fā)經(jīng)驗(yàn)。我們擅長(zhǎng)傾聽企業(yè)需求,挖掘用戶對(duì)產(chǎn)品需求服務(wù)價(jià)值,為企業(yè)制作有用的創(chuàng)意設(shè)計(jì)體驗(yàn)。核心團(tuán)隊(duì)擁有超過10余年以上行業(yè)經(jīng)驗(yàn),涵蓋創(chuàng)意,策化,開發(fā)等專業(yè)領(lǐng)域,公司涉及領(lǐng)域有基礎(chǔ)互聯(lián)網(wǎng)服務(wù)成都機(jī)柜租用、重慶App定制開發(fā)、手機(jī)移動(dòng)建站、網(wǎng)頁設(shè)計(jì)、網(wǎng)絡(luò)整合營(yíng)銷。
keepalived+nginx+tomcat 實(shí)現(xiàn)高可用web集群
一、nginx的安裝過程
1.下載nginx安裝包,安裝依賴環(huán)境包
(1)安裝 c++編譯環(huán)境
yum -y install gcc #c++
(2)安裝pcre
yum -y install pcre-devel
(3)安裝zlib
yum -y install zlib-devel
(4)安裝nginx
定位到nginx 解壓文件位置,執(zhí)行編譯安裝命令
[root@localhost nginx-1.12.2]# pwd /usr/local/nginx/nginx-1.12.2 [root@localhost nginx-1.12.2]# ./configure && make && make install
(5)啟動(dòng)nginx
安裝完成后先尋找那安裝完成的目錄位置
[root@localhost nginx-1.12.2]# whereis nginx nginx: /usr/local/nginx [root@localhost nginx-1.12.2]#
進(jìn)入nginx子目錄sbin啟動(dòng)nginx
[root@localhost sbin]# ls nginx [root@localhost sbin]# ./nginx & [1] 5768 [root@localhost sbin]#
查看nginx是否啟動(dòng)
或通過進(jìn)程查看nginx啟動(dòng)情況
[root@localhost sbin]# ps -aux|grep nginx root 5769 0.0 0.0 20484 608 ? ss 14:03 0:00 nginx: master process ./nginx nobody 5770 0.0 0.0 23012 1620 ? s 14:03 0:00 nginx: worker process root 5796 0.0 0.0 112668 972 pts/0 r+ 14:07 0:00 grep --color=auto nginx [1]+ 完成 ./nginx [root@localhost sbin]#
到此nginx安裝完成并啟動(dòng)成功。
(6)nginx快捷啟動(dòng)和開機(jī)啟動(dòng)配置
編輯nginx快捷啟動(dòng)腳本【 注意nginx安裝路徑 , 需要根據(jù)自己的nginx路徑進(jìn)行改動(dòng) 】
[root@localhost init.d]# vim /etc/rc.d/init.d/nginx
#!/bin/sh # # nginx - this script starts and stops the nginx daemon # # chkconfig: - 85 15 # description: nginx is an http(s) server, http(s) reverse \ # proxy and imap/pop3 proxy server # processname: nginx # config: /etc/nginx/nginx.conf # config: /usr/local/nginx/conf/nginx.conf # pidfile: /usr/local/nginx/logs/nginx.pid # source function library. . /etc/rc.d/init.d/functions # source networking configuration. . /etc/sysconfig/network # check that networking is up. [ "$networking" = "no" ] && exit 0 nginx="/usr/local/nginx/sbin/nginx" prog=$(basename $nginx) nginx_conf_file="/usr/local/nginx/conf/nginx.conf" [ -f /etc/sysconfig/nginx ] && . /etc/sysconfig/nginx lockfile=/var/lock/subsys/nginx make_dirs() { # make required directories user=`$nginx -v 2>&1 | grep "configure arguments:" | sed 's/[^*]*--user=\([^ ]*\).*/\1/g' -` if [ -z "`grep $user /etc/passwd`" ]; then useradd -m -s /bin/nologin $user fi options=`$nginx -v 2>&1 | grep 'configure arguments:'` for opt in $options; do if [ `echo $opt | grep '.*-temp-path'` ]; then value=`echo $opt | cut -d "=" -f 2` if [ ! -d "$value" ]; then # echo "creating" $value mkdir -p $value && chown -r $user $value fi fi done } start() { [ -x $nginx ] || exit 5 [ -f $nginx_conf_file ] || exit 6 make_dirs echo -n $"starting $prog: " daemon $nginx -c $nginx_conf_file retval=$? echo [ $retval -eq 0 ] && touch $lockfile return $retval } stop() { echo -n $"stopping $prog: " killproc $prog -quit retval=$? echo [ $retval -eq 0 ] && rm -f $lockfile return $retval } restart() { #configtest || return $? stop sleep 1 start } reload() { #configtest || return $? echo -n $"reloading $prog: " killproc $nginx -hup retval=$? echo } force_reload() { restart } configtest() { $nginx -t -c $nginx_conf_file } rh_status() { status $prog } rh_status_q() { rh_status >/dev/null 2>&1 } case "$1" in start) rh_status_q && exit 0 $1 ;; stop) rh_status_q || exit 0 $1 ;; restart|configtest) $1 ;; reload) rh_status_q || exit 7 $1 ;; force-reload) force_reload ;; status) rh_status ;; condrestart|try-restart) rh_status_q || exit 0 ;; *) echo $"usage: $0 {start|stop|status|restart|condrestart|try-restart|reload|force-reload|configtest}" exit 2 esac
為啟動(dòng)腳本授權(quán) 并加入開機(jī)啟動(dòng)
[root@localhost init.d]# chmod -r 777 /etc/rc.d/init.d/nginx [root@localhost init.d]# chkconfig nginx
啟動(dòng)nginx
[root@localhost init.d]# ./nginx start
將nginx加入系統(tǒng)環(huán)境變量
[root@localhost init.d]# echo 'export path=$path:/usr/local/nginx/sbin'>>/etc/profile && source /etc/profile
nginx命令 [ service nginx (start|stop|restart) ]
[root@localhost init.d]# service nginx start starting nginx (via systemctl): [ 確定 ]
tips: 快捷命令
service nginx (start|stop|restart)
二、keepalived安裝和配置
1.安裝keepalived依賴環(huán)境
yum install -y popt-devel yum install -y ipvsadm yum install -y libnl* yum install -y libnf* yum install -y openssl-devel
2.編譯keepalived并安裝
[root@localhost keepalived-1.3.9]# ./configure [root@localhost keepalived-1.3.9]# make && make install
3.將keepalive 安裝成系統(tǒng)服務(wù)
[root@localhost etc]# mkdir /etc/keepalived [root@localhost etc]# cp /usr/local/keepalived/etc/keepalived/keepalived.conf /etc/keepalived/
手動(dòng)復(fù)制默認(rèn)的配置文件到默認(rèn)路徑
[root@localhost etc]# mkdir /etc/keepalived [root@localhost etc]# cp /usr/local/keepalived/etc/sysconfig/keepalived /etc/sysconfig/ [root@localhost etc]# cp /usr/local/keepalived/etc/keepalived/keepalived.conf /etc/keepalived/
為keepalived 創(chuàng)建軟鏈接
[root@localhost sysconfig]# ln -s /usr/local/keepalived/sbin/keepalived /usr/sbin/
設(shè)置keepalived開機(jī)自啟動(dòng)
[root@localhost sysconfig]# chkconfig keepalived on 注意:正在將請(qǐng)求轉(zhuǎn)發(fā)到“systemctl enable keepalived.service”。 created symlink from /etc/systemd/system/multi-user.target.wants/keepalived.service to /usr/lib/systemd/system/keepalived.service
啟動(dòng)keepalived服務(wù)
[root@localhost keepalived]# keepalived -d -f /etc/keepalived/keepalived.conf
關(guān)閉keepalived服務(wù)
[root@localhost keepalived]# killall keepalived
三、集群規(guī)劃和搭建
環(huán)境準(zhǔn)備:
centos 7.2
keepalived version 1.4.0 - december 29, 2017
nginx version: nginx/1.12.2
tomcat version:8
集群規(guī)劃清單
虛擬機(jī) | ip | 說明 |
---|---|---|
keepalived+nginx1[master] | 192.168.43.101 | nginx server 01 |
keeepalived+nginx[backup] | 192.168.43.102 | nginx server 02 |
tomcat01 | 192.168.43.103 | tomcat web server01 |
tomcat02 | 192.168.43.104 | tomcat web server02 |
vip | 192.168.43.150 | 虛擬漂移ip |
1.更改tomcat默認(rèn)歡迎頁面,用于標(biāo)識(shí)切換web
更改tomcatserver01 節(jié)點(diǎn)root/index.jsp 信息,加入tomcatip地址,并加入nginx值,即修改節(jié)點(diǎn)192.168.43.103信息如下:
${pagecontext.servletcontext.serverinfo}(192.168.224.103)<%=request.getheader("x-nginx")%>
更改tomcatserver02 節(jié)點(diǎn)root/index.jsp信息,加入tomcatip地址,并加入nginx值,即修改節(jié)點(diǎn)192.168.43.104信息如下:
${pagecontext.servletcontext.serverinfo}(192.168.224.104)<%=request.getheader("x-nginx")%>
2.啟動(dòng)tomcat服務(wù),查看tomcat服務(wù)ip信息,此時(shí)nginx未啟動(dòng),因此request-header沒有nginx信息。
3.配置nginx代理信息
1.配置master節(jié)點(diǎn)[192.168.43.101]代理信息
upstream tomcat { server 192.168.43.103:8080 weight=1; server 192.168.43.104:8080 weight=1; } server{ location / { proxy_pass http://tomcat; proxy_set_header x-nginx "nginx-1"; } #......其他省略 }
2.配置backup節(jié)點(diǎn)[192.168.43.102]代理信息
upstream tomcat { server 192.168.43.103:8080 weight=1; server 192.168.43.104:8080 weight=1; } server{ location / { proxy_pass http://tomcat; proxy_set_header x-nginx "nginx-2"; } #......其他省略 }
3.啟動(dòng)master 節(jié)點(diǎn)nginx服務(wù)
[root@localhost init.d]# service nginx start starting nginx (via systemctl): [ 確定 ]
此時(shí)訪問 192.168.43.101 可以看到103和104節(jié)點(diǎn)tcomat交替顯示,說明nginx服務(wù)已經(jīng)將請(qǐng)求負(fù)載到了2臺(tái)tomcat上。
4.同理配置backup[192.168.43.102] nginx信息,啟動(dòng)nginx后,訪問192.168.43.102后可以看到backup節(jié)點(diǎn)已起到負(fù)載的效果。
4.配置keepalived 腳本信息
1. 在master節(jié)點(diǎn)和slave節(jié)點(diǎn) /etc/keepalived目錄下添加check_nginx.sh 文件,用于檢測(cè)nginx的存貨狀況,添加keepalived.conf文件
check_nginx.sh文件信息如下:
#!/bin/bash #時(shí)間變量,用于記錄日志 d=`date --date today +%y%m%d_%h:%m:%s` #計(jì)算nginx進(jìn)程數(shù)量 n=`ps -c nginx --no-heading|wc -l` #如果進(jìn)程為0,則啟動(dòng)nginx,并且再次檢測(cè)nginx進(jìn)程數(shù)量, #如果還為0,說明nginx無法啟動(dòng),此時(shí)需要關(guān)閉keepalived if [ $n -eq "0" ]; then /etc/rc.d/init.d/nginx start n2=`ps -c nginx --no-heading|wc -l` if [ $n2 -eq "0" ]; then echo "$d nginx down,keepalived will stop" >> /var/log/check_ng.log systemctl stop keepalived fi fi
添加完成后,為check_nginx.sh 文件授權(quán),便于腳本獲得執(zhí)行權(quán)限。
[root@localhost keepalived]# chmod -r 777 /etc/keepalived/check_nginx.sh
2.在master 節(jié)點(diǎn) /etc/keepalived目錄下,添加keepalived.conf 文件,具體信息如下:
vrrp_script chk_nginx { script "/etc/keepalived/check_nginx.sh" //檢測(cè)nginx進(jìn)程的腳本 interval 2 weight -20 } global_defs { notification_email { //可以添加郵件提醒 } } vrrp_instance vi_1 { state master #標(biāo)示狀態(tài)為master 備份機(jī)為backup interface ens33 #設(shè)置實(shí)例綁定的網(wǎng)卡(ip addr查看,需要根據(jù)個(gè)人網(wǎng)卡綁定) virtual_router_id 51 #同一實(shí)例下virtual_router_id必須相同 mcast_src_ip 192.168.43.101 priority 250 #master權(quán)重要高于backup 比如backup為240 advert_int 1 #master與backup負(fù)載均衡器之間同步檢查的時(shí)間間隔,單位是秒 nopreempt #非搶占模式 authentication { #設(shè)置認(rèn)證 auth_type pass #主從服務(wù)器驗(yàn)證方式 auth_pass 123456 } track_script { check_nginx } virtual_ipaddress { #設(shè)置vip 192.168.43.150 #可以多個(gè)虛擬ip,換行即可 } }
3.在backup節(jié)點(diǎn) etc/keepalived目錄下添加 keepalived.conf 配置文件
信息如下:
vrrp_script chk_nginx { script "/etc/keepalived/check_nginx.sh" //檢測(cè)nginx進(jìn)程的腳本 interval 2 weight -20 } global_defs { notification_email { //可以添加郵件提醒 } } vrrp_instance vi_1 { state backup #標(biāo)示狀態(tài)為master 備份機(jī)為backup interface ens33 #設(shè)置實(shí)例綁定的網(wǎng)卡(ip addr查看) virtual_router_id 51 #同一實(shí)例下virtual_router_id必須相同 mcast_src_ip 192.168.43.102 priority 240 #master權(quán)重要高于backup 比如backup為240 advert_int 1 #master與backup負(fù)載均衡器之間同步檢查的時(shí)間間隔,單位是秒 nopreempt #非搶占模式 authentication { #設(shè)置認(rèn)證 auth_type pass #主從服務(wù)器驗(yàn)證方式 auth_pass 123456 } track_script { check_nginx } virtual_ipaddress { #設(shè)置vip 192.168.43.150 #可以多個(gè)虛擬ip,換行即可 } }
tips: 關(guān)于配置信息的幾點(diǎn)說明
state - 主服務(wù)器需配成master,從服務(wù)器需配成backup
interface - 這個(gè)是網(wǎng)卡名,我使用的是vm12.0的版本,所以這里網(wǎng)卡名為ens33
mcast_src_ip - 配置各自的實(shí)際ip地址
priority - 主服務(wù)器的優(yōu)先級(jí)必須比從服務(wù)器的高,這里主服務(wù)器配置成250,從服務(wù)器配置成240
virtual_ipaddress - 配置虛擬ip(192.168.43.150)
authentication - auth_pass主從服務(wù)器必須一致,keepalived靠這個(gè)來通信
virtual_router_id - 主從服務(wù)器必須保持一致
5.集群高可用(ha)驗(yàn)證
step1 啟動(dòng)master機(jī)器的keepalived和 nginx服務(wù)
[root@localhost keepalived]# keepalived -d -f /etc/keepalived/keepalived.conf [root@localhost keepalived]# service nginx start
查看服務(wù)啟動(dòng)進(jìn)程
[root@localhost keepalived]# ps -aux|grep nginx root 6390 0.0 0.0 20484 612 ? ss 19:13 0:00 nginx: master process /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf nobody 6392 0.0 0.0 23008 1628 ? s 19:13 0:00 nginx: worker process root 6978 0.0 0.0 112672 968 pts/0 s+ 20:08 0:00 grep --color=auto nginx
查看keepalived啟動(dòng)進(jìn)程
[root@localhost keepalived]# ps -aux|grep keepalived root 6402 0.0 0.0 45920 1016 ? ss 19:13 0:00 keepalived -d -f /etc/keepalived/keepalived.conf root 6403 0.0 0.0 48044 1468 ? s 19:13 0:00 keepalived -d -f /etc/keepalived/keepalived.conf root 6404 0.0 0.0 50128 1780 ? s 19:13 0:00 keepalived -d -f /etc/keepalived/keepalived.conf root 7004 0.0 0.0 112672 976 pts/0 s+ 20:10 0:00 grep --color=auto keepalived
使用 ip add 查看虛擬ip綁定情況,如出現(xiàn)192.168.43.150 節(jié)點(diǎn)信息則綁定到master節(jié)點(diǎn)
[root@localhost keepalived]# ip add 1: lo:mtu 65536 qdisc noqueue state unknown qlen 1 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: ens33: mtu 1500 qdisc pfifo_fast state up qlen 1000 link/ether 00:0c:29:91:bf:59 brd ff:ff:ff:ff:ff:ff inet 192.168.43.101/24 brd 192.168.43.255 scope global ens33 valid_lft forever preferred_lft forever inet 192.168.43.150/32 scope global ens33 valid_lft forever preferred_lft forever inet6 fe80::9abb:4544:f6db:8255/64 scope link valid_lft forever preferred_lft forever inet6 fe80::b0b3:d0ca:7382:2779/64 scope link tentative dadfailed valid_lft forever preferred_lft forever inet6 fe80::314f:5fe7:4e4b:64ed/64 scope link tentative dadfailed valid_lft forever preferred_lft forever 3: virbr0: mtu 1500 qdisc noqueue state down qlen 1000 link/ether 52:54:00:2b:74:aa brd ff:ff:ff:ff:ff:ff inet 192.168.122.1/24 brd 192.168.122.255 scope global virbr0 valid_lft forever preferred_lft forever 4: virbr0-nic: mtu 1500 qdisc pfifo_fast master virbr0 state down qlen 1000 link/ether 52:54:00:2b:74:aa brd ff:ff:ff:ff:ff:ff
step 2 啟動(dòng)backup節(jié)點(diǎn)nginx服務(wù)和keepalived服務(wù),查看服務(wù)啟動(dòng)情況,如backup節(jié)點(diǎn)出現(xiàn)了虛擬ip,則keepalvied配置文件有問題,此情況稱為腦裂。
[root@localhost keepalived]# clear [root@localhost keepalived]# ip add 1: lo:mtu 65536 qdisc noqueue state unknown qlen 1 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: ens33: mtu 1500 qdisc pfifo_fast state up qlen 1000 link/ether 00:0c:29:14:df:79 brd ff:ff:ff:ff:ff:ff inet 192.168.43.102/24 brd 192.168.43.255 scope global ens33 valid_lft forever preferred_lft forever inet6 fe80::314f:5fe7:4e4b:64ed/64 scope link valid_lft forever preferred_lft forever 3: virbr0: mtu 1500 qdisc noqueue state down qlen 1000 link/ether 52:54:00:2b:74:aa brd ff:ff:ff:ff:ff:ff inet 192.168.122.1/24 brd 192.168.122.255 scope global virbr0 valid_lft forever preferred_lft forever 4: virbr0-nic: mtu 1500 qdisc pfifo_fast master virbr0 state down qlen 1000 link/ether 52:54:00:2b:74:aa brd ff:ff:ff:ff:ff:ff
step 3 驗(yàn)證服務(wù)
瀏覽并多次強(qiáng)制刷新地址: http://192.168.43.150 ,可以看到103和104多次交替顯示,并顯示nginx-1,則表明 master節(jié)點(diǎn)在進(jìn)行web服務(wù)轉(zhuǎn)發(fā)。
step 4 關(guān)閉master keepalived服務(wù)和nginx服務(wù),訪問web服務(wù)觀察服務(wù)轉(zhuǎn)移情況
[root@localhost keepalived]# killall keepalived [root@localhost keepalived]# service nginx stop
此時(shí)強(qiáng)制刷新192.168.43.150發(fā)現(xiàn) 頁面交替顯示103和104并顯示nginx-2 ,vip已轉(zhuǎn)移到192.168.43.102上,已證明服務(wù)自動(dòng)切換到備份節(jié)點(diǎn)上。
step 5 啟動(dòng)master keepalived 服務(wù)和nginx服務(wù)
此時(shí)再次驗(yàn)證發(fā)現(xiàn),vip已被master重新奪回,并頁面交替顯示 103和104,此時(shí)顯示nginx-1
四、keepalived搶占模式和非搶占模式
keepalived的ha分為搶占模式和非搶占模式,搶占模式即master從故障中恢復(fù)后,會(huì)將vip從backup節(jié)點(diǎn)中搶占過來。非搶占模式即master恢復(fù)后不搶占backup升級(jí)為master后的vip。
非搶占模式配置:
1> 在vrrp_instance塊下兩個(gè)節(jié)點(diǎn)各增加了nopreempt指令,表示不爭(zhēng)搶vip
2> 節(jié)點(diǎn)的state都為backup 兩個(gè)keepalived節(jié)點(diǎn)都啟動(dòng)后,默認(rèn)都是backup狀態(tài),雙方在發(fā)送組播信息后,會(huì)根據(jù)優(yōu)先級(jí)來選舉一個(gè)master出來。由于兩者都配置了nopreempt,所以master從故障中恢復(fù)后,不會(huì)搶占vip。這樣會(huì)避免vip切換可能造成的服務(wù)延遲。
以上就是關(guān)于“如何用Keepalived+Nginx+Tomcat實(shí)現(xiàn)高可用Web集群”這篇文章的內(nèi)容,相信大家都有了一定的了解,希望小編分享的內(nèi)容對(duì)大家有幫助,若想了解更多相關(guān)的知識(shí)內(nèi)容,請(qǐng)關(guān)注創(chuàng)新互聯(lián)行業(yè)資訊頻道。