首先需要服务器关都闭防火墙和selinux
1,准备四台nginx服务器,两台做代理,两台做后端真实服务器。
2,配置两台真实服务器
第一台:
[root@vm-4 ~]# systemctl start nginx
[root@vm-4 ~]# systemctl enable nginx
[root@vm-4 conf.d]# echo "server111" > /usr/share/nginx/html/index.html
测试:
[root@vm-4 conf.d]# curl localhost
server111
第二台:
[root@vm-5 ~]# systemctl start nginx
[root@vm-5 ~]# systemctl enable nginx
[root@vm-5 conf.d]# echo "server222" > /usr/share/nginx/html/index.html
测试:
[root@vm-5 conf.d]# curl localhost
server222
3,配置两台nginx代理服务器
[root@vm-2 ~]# systemctl start nginx
[root@vm-2 ~]# systemctl enable nginx
[root@vm-2 ~]# cd /etc/nginx/conf.d/
[root@vm-2 conf.d]# cp default.conf proxy.conf
[root@vm-2 conf.d]# mv default.conf default.conf.bak
[root@vm-2 conf.d]# vi upstream.conf
upstream nginx_pool {
server 10.30.161.241:80 weight=1 max_fails=2 fail_timeout=2;
server 10.30.161.242:80 weight=1 max_fails=2 fail_timeout=2;
}
[root@vm-2 conf.d]# vi proxy.conf
location / {
proxy_pass http://nginx_pool;
proxy_redirect default;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header REMOTE-HOST $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
将nginx的配置文件拷贝到另一台代理服务器中:
[root@vm-2 conf.d]# scp proxy.conf upstream.conf 10.30.161.214:/etc/nginx/conf.d/
分别重启nginx:
systemctl restart nginx
4, 两台代理服务器分别安装软件
master:
[root@vm-2 conf.d]# yum install -y keepalived
[root@vm-2 conf.d]# cp /etc/keepalived/keepalived.conf /etc/keepalived/keepalived.conf.bak
[root@vm-2 conf.d]# vim /etc/keepalived/keepalived.conf
配置keepalived,将里面内容全部删除,添加下列内容:
! Configuration File for keepalived
global_defs {
router_id director1 #辅助改为director2
}
vrrp_instance VI_1 {
state MASTER #定义主还是备
interface ens33 #VIP绑定接口
virtual_router_id 80 #整个集群的调度器一致
priority 100 #back改为50
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
10.30.161.200/24 #设置VIP
}
}
backup:
[root@yum_nginx ~]# cp /etc/keepalived/keepalived.conf
[root@yum_nginx ~]# vi /etc/keepalived/keepalived.conf
配置keepalived,将里面内容全部删除,添加下列内容:
! Configuration File for keepalived
global_defs {
router_id directory2
}
vrrp_instance VI_1 {
state BACKUP
interface ens33
nopreempt
virtual_router_id 80
priority 50
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
10.30.161.200/24
}
}
5、两台代理服务器分别启动keepalived
[root@yum_nginx ~]# systemctl enable keepalived.service
[root@yum_nginx ~]# systemctl start keepalived.service
6、检测是否成功
在master上 ip a 可显示VIP为10.30.161.200/24
2: ens33: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
link/ether 00:0c:29:29:a6:12 brd ff:ff:ff:ff:ff:ff
inet 10.30.161.51/24 brd 10.30.161.255 scope global dynamic ens33
valid_lft 168379sec preferred_lft 168379sec
inet 10.30.161.200/24 scope global secondary ens33
valid_lft forever preferred_lft forever
inet6 fe80::8cfe:8d87:6478:baee/64 scope link
valid_lft forever preferred_lft forever
inet6 fe80::d9c7:8228:5b45:afed/64 scope link tentative dadfailed
valid_lft forever preferred_lft forever
用curl访问VIP,正常轮询
[root@vm-5 conf.d]# curl 10.30.161.200
server111
[root@vm-5 conf.d]# curl 10.30.161.200
server222
[root@vm-5 conf.d]# curl 10.30.161.200
server111
[root@vm-5 conf.d]# curl 10.30.161.200
server222
测试当一台master故障
[root@vm-2 conf.d]# systemctl stop keepalived
ip a 发现VIP偏移到backup代理服务器上
到此:
可以解决心跳故障keepalived
但不能解决Nginx服务故障
扩展对调度器Nginx健康检查(可选)两台都设置
思路:
让Keepalived以一定时间间隔执行一个外部脚本,脚本的功能是当Nginx失败,则关闭本机的Keepalived
(1) script[root@nginx-proxy-master ~]# vim /etc/keepalived/check_nginx_status.sh
#!/bin/bash
#+检查nginx进程是否存在
counter=$(ps -C nginx –no-heading|wc -l) #此行有服务名
if [ “${counter}” = “0” ]; then
#尝试启动一次nginx,停止5秒后再次检测
systemctl start nginx #启动服务
sleep 5
counter=$(ps -C nginx –no-heading|wc -l) #此行有服务名
if [ “${counter}” = “0” ]; then
#如果启动没成功,就杀掉keepalive触发主备切换
service keepalived stop
fi
fi
[root@nginx-proxy-master ~]# chmod a+x /etc/keepalived/check_nginx_status.sh
(2). keepalived使用script
! Configuration File for keepalived
global_defs {
router_id director1
}
vrrp_script check_nginx { #健康检测模块调用
script "/etc/keepalived/check_nginx_status.sh" #指定脚本
interval 5 #检查频率,秒
}
vrrp_instance VI_1 {
state MASTER
interface ens33
virtual_router_id 80
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
192.168.246.16/24
}
track_script { 引用脚本
check_nginx
}
}
注:必须先启动nginx,再启动keepalived