nginx 를 이용 한 proxynext_upstream 선로 용재 실현

본 고 는 생산 환경 중의 한 사례 로 주로 역방향 대 리 를 통 해 여러 노선 의 용 재 를 실현 하기 위해 서 이다.기 존의 토대 위 에서 openssl, openssh, nginx 를 업그레이드 하여 일부 모듈 을 통 해 우리 의 수 요 를 실현 했다.
정상 적 인 상황 에서 역방향 에이 전 트 는 온라인 아래 호스트 에 요청 하고 스티커 모듈 을 사용 하여 session 접착 을 실현 합 니 다.온라인 아래 호스트 가 모두 끊 어 지면 502 오류 (또는 404, 구체 적 으로 환경 과 관련 이 있 습 니 다) 가 발생 합 니 다. 이 때 는 failover 아래 호스트 를 사용 하여 회선 용 재 를 실현 합 니 다.구체 적 인 용재 방식 은 여러 가 지 를 선택 할 수 있다.예 를 들 어 backup 을 사용 하여 표 지 를 한다.nginx 사용upstream_check_module 백 엔 드 호스트 건강 검진.

 
  
  
  
  
  1. nginx 
  2.  
  3. 1、 openssh 
  4. 2、 nginx 
  5. 3、 nignx  
  6.  
  7. . openssh, 。 
  8. nginx : 
  9. a、 SSL  
  10. b、 http   
  11. c、 session   nginx-sticky-module // sticky+rr ,sticky+weight  
  12. d、 nginx +  
  13. e、 geoip , CDN+GeoIP ( nginx IP, ) 
  14.  
  15.  
  16. telnet : 
  17. #yum install -y telnet-server telnet 
  18.  
  19.  
  20.  
  21. # chkconfig telnet on  
  22. # 
  23. # /etc/init.d/xinetd restart 
  24. Stopping xinetd:                                           [FAILED] 
  25. Starting xinetd:                                           [  OK  ] 
  26.  
  27. # netstat -tnlp  
  28. Active Internet connections (only servers) 
  29. Proto Recv-Q Send-Q Local Address               Foreign Address             State       PID/Program name    
  30. tcp        0      0 0.0.0.0:22                  0.0.0.0:*                   LISTEN      2632/sshd            
  31. tcp        0      0 0.0.0.0:23                  0.0.0.0:*                   LISTEN      21977/xinetd  
  32.  
  33. // IP 23  
  34.  
  35.  
  36. # useradd sshinstall 
  37. # echo "123456@sshinstall" | passwd --stdin sshinstall 
  38. Changing password for user sshinstall. 
  39. passwd: all authentication tokens updated successfully. 
  40.  
  41. sudo  
  42. echo "sshinstall ALL=(ALL) NOPASSWD:ALL" >> /etc/sudoers 
  43.  
  44.  
  45. # tar -xzf openssl-1.0.1c.tar.gz  
  46. # cd openssl-1.0.1c 
  47. # ./config enable-tl***t  --prefix=/usr/local/openssl-1.0.0c 
  48. # make  
  49. # make test 
  50. # make install 
  51.  
  52. # echo /usr/local/openssl-1.0.0c/lib/ >> /etc/ld.so.conf  
  53. # ln -s /usr/local/openssl-1.0.0c/ /usr/local/openssl 
  54.  
  55. echo ' 
  56. PATH=/usr/local/openssl/bin:$PATH 
  57. export PATH' >>   /etc/profile 
  58.  
  59. # source /etc/profile  
  60. # openssl version -a 
  61. OpenSSL 1.0.1c 10 May 2012 
  62. built on: Fri Jan  4 00:32:23 CST 2013 
  63. platform: linux-x86_64 
  64. options:  bn(64,64) rc4(16x,int) des(idx,cisc,16,int) idea(int) blowfish(idx)  
  65. compiler: gcc -DOPENSSL_THREADS -D_REENTRANT -DDSO_DLFCN -DHAVE_DLFCN_H -Wa,--noexecstack -m64 -DL_ENDIAN -DTERMIO -O3 -Wall -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_MONT5 -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DMD5_ASM -DAES_ASM -DVPAES_ASM -DBSAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM 
  66. OPENSSLDIR: "/usr/local/openssl-1.0.0c/ssl 
  67.  
  68. openssh  
  69. # rpm -e openssh-server-4.3p2-41.el5 --nodeps 
  70. # rpm -e openssh-4.3p2-41.el5 --nodeps 
  71. # rpm -e openssh-askpass-4.3p2-41.el5 --nodeps 
  72. # rpm -e openssh-clients-4.3p2-41.el5 --nodeps 
  73.  
  74. # rm -rf /etc/ssh/ 
  75.  
  76. openssh 
  77. # tar -xzf openssh-6.1p1.tar.gz 
  78. # cd openssh-6.1p1  
  79. # ./configure --prefix=/usr --sysconfdir=/etc/ssh --with-pam --with-ssl-dir=/usr/local/openssl-1.0.0c --with-md5-passwords --mandir=/usr/share/man  
  80. # make 
  81. # make install  
  82.  
  83. sshd  
  84.  
  85. # cp ./contrib/redhat/sshd.init /etc/init.d/sshd 
  86. # chmod u+x /etc/init.d/sshd 
  87. # chkconfig --add sshd 
  88. # chkconfig sshd on 
  89. # service sshd start 
  90. Starting sshd:  OK  ] 
  91. # ssh -v 
  92. OpenSSH_6.1p1, OpenSSL 1.0.1c 10 May 2012 
  93.  
  94. telnetserver, sshinstall  
  95. # chkconfig telnet off 
  96. # /etc/init.d/xinetd restart 
  97. Stopping xinetd:                                           [  OK  ] 
  98. Starting xinetd:                                           [  OK  ] 
  99. # netstat -tnlp  
  100. Active Internet connections (only servers) 
  101. Proto Recv-Q Send-Q Local Address               Foreign Address             State       PID/Program name    
  102. tcp        0      0 0.0.0.0:22                  0.0.0.0:*                   LISTEN      29602/sshd           
  103.  
  104. # userdel -r sshinstall  
  105.  
  106. Nginx 
  107. # tar zxvf libunwind-0.99.tar.gz 
  108. # cd libunwind-0.99/ 
  109. # CFLAGS=-fPIC ./configure && make CFLAGS=-fPIC 
  110. # make CFLAGS=-fPIC install 
  111.  
  112. # tar xzf google-perftools-1.6.tar.gz 
  113. # cd google-perftools-1.6 
  114. # ./configure  
  115. # make && make install  
  116.  
  117. # tar -xzf pcre-8.12.tar.gz  
  118. # cd pcre-8.12 
  119. # ./configure && make && make install  
  120.  
  121. geoip 
  122. # wget http://geolite.maxmind.com/download/geoip/api/c/GeoIP.tar.gz 
  123. # tar -xzf GeoIP.tar.gz  
  124. # cd GeoIP-1.4.8/ 
  125. # ./configure && make && make install 
  126. # wget http://geolite.maxmind.com/download/geoip/database/GeoLiteCountry/GeoIP.dat.gz 
  127. # gunzip GeoIP.dat.gz  
  128. # echo '/usr/local/lib' > /etc/ld.so.conf.d/geoip.conf 
  129. # ldconfig 
  130.  
  131. , nginx ,  
  132. # unzip nginx_upstream_jvm_route.zip    //tomcat session 
  133. Archive:  nginx_upstream_jvm_route.zip 
  134.    creating: nginx-upstream-jvm-route/ 
  135.    creating: nginx-upstream-jvm-route/nginx_upstream_jvm_route/ 
  136.   inflating: nginx-upstream-jvm-route/nginx_upstream_jvm_route/CHANGES   
  137.   inflating: nginx-upstream-jvm-route/nginx_upstream_jvm_route/config   
  138.   inflating: nginx-upstream-jvm-route/nginx_upstream_jvm_route/jvm_route.patch   // ,  
  139.   inflating: nginx-upstream-jvm-route/nginx_upstream_jvm_route/ngx_http_upstream_jvm_route_module.c   
  140.   inflating: nginx-upstream-jvm-route/nginx_upstream_jvm_route/README   
  141.  
  142. # unzip master.zip  //nginx_upsteam check_module 
  143. # tar -xzf nginx-sticky-module-1.1.tar.gz  //session 
  144. # tar -xzf nginx-1.2.6.tar.gz    
  145. # cd nginx-1.2.6 
  146.  
  147. # patch -p0 < /root/upgrade/nginx-upstream-jvm-route/nginx_upstream_jvm_route/jvm_route.patch  
  148. patching file src/http/ngx_http_upstream.c 
  149. Hunk #1 succeeded at 4117 (offset 380 lines). 
  150. Hunk #3 succeeded at 4249 (offset 380 lines). 
  151. Hunk #5 succeeded at 4348 (offset 380 lines). 
  152. patching file src/http/ngx_http_upstream.h 
  153. Hunk #1 succeeded at 90 (offset 5 lines). 
  154. Hunk #3 succeeded at 118 (offset 5 lines). 
  155.  
  156. # patch -p1 < /root/upgrade/nginx_upstream_check_module-master/check_1.2.6+.patch  
  157. patching file src/http/modules/ngx_http_upstream_ip_hash_module.c 
  158. patching file src/http/modules/ngx_http_upstream_least_conn_module.c 
  159. patching file src/http/ngx_http_upstream_round_robin.c 
  160. patching file src/http/ngx_http_upstream_round_robin.h 
  161.  
  162. # ./configure --prefix=/usr/local/nginx  --user=nobody --group=nobody  --with-http_stub_status_module --with-http_gzip_static_module --with-http_realip_module --with-http_sub_module --with-http_geoip_module  --with-http_ssl_module  --with-http_ssl_module --with-openssl=/root/upgrade/openssl-1.0.1c --with-pcre=/root/upgrade/pcre-8.12 --add-module=/root/upgrade/nginx-upstream-jvm-route/nginx_upstream_jvm_route/  --add-module=/root/upgrade/nginx_upstream_check_module-master/ --add-module=/root/upgrade/nginx-sticky-module-1.1/ --with-google_perftools_module 
  163. # make && make install  
  164.  
  165. # /usr/local/nginx/sbin/nginx -v 
  166. nginx version: nginx/1.2.6 
  167.  
  168. nginx , nginx . 
  169. # ps aux | grep master 
  170. root     13589  0.0  0.0  26772  3884 ?        S     2012   0:01 nginx: master process /usr/local/nginx/sbin/nginx 
  171. root     20834  0.0  0.0  61140   768 pts/4    S+   17:14   0:00 grep master 
  172.  
  173.  
  174. # kill -USR2 13589 
  175. # ps aux | grep master 
  176. root     13589  0.0  0.0  26772  3884 ?        S     2012   0:01 nginx: master process /usr/local/nginx/sbin/nginx 
  177. root     21395  0.5  0.0  40272  3504 ?        S    17:16   0:00 nginx: master process /usr/local/nginx/sbin/nginx 
  178. root     21416  0.0  0.0  61140   768 pts/4    S+   17:16   0:00 grep master 
  179.  
  180. # kill -WINCH 13589   // WINCH nginx nginx  
  181. # kill -QUIT 13589  //  nginx   
  182. # ps aux |grep master 
  183. root     21395  0.0  0.0  40272  3504 ?        S    17:16   0:00 nginx: master process /usr/local/nginx/sbin/nginx 
  184. root     21749  0.0  0.0  61140   772 pts/4    S+   17:16   0:00 grep master 
  185.  
  186.  
  187. # rm -rf /usr/local/nginx/sbin/nginx.old  
  188.  
  189. # /usr/local/nginx/sbin/nginx -v 
  190. nginx version: nginx/1.2.6 
  191.  
  192. , ! 
  193. # /usr/local/nginx/sbin/nginx -V 
  194. nginx version: nginx/1.2.6 
  195. built by gcc 4.1.2 20080704 (Red Hat 4.1.2-52) 
  196. TLS SNI support enabled  // SSL  
  197. configure arguments: --prefix=/usr/local/nginx --user=nobody --group=nobody --with-http_stub_status_module --with-http_gzip_static_module --with-http_realip_module --with-http_sub_module --with-http_geoip_module --with-http_ssl_module --with-http_ssl_module --with-openssl=/root/upgrade/openssl-1.0.1c --with-pcre=/root/upgrade/pcre-8.12 --add-module=/root/upgrade/nginx-upstream-jvm-route/nginx_upstream_jvm_route/ --add-module=/root/upgrade/nginx_upstream_check_module-master/ --add-module=/root/upgrade/nginx-sticky-module-1.1/ --with-google_perftools_module 
  198.  
  199. : 
  200. , (A\B ),A 、B 。 
  201. :  , A , A , B 。 session 。 ,session 。 , nginx_upstream_jvm_route( tomcat\resin , ),nginx-sticky-module-1.1.  。 
  202.  
  203. : 
  204. 1、  
  205. :  , , 。 
  206. : A ,B ( , )
  207. : 
  208. upstream.conf 
  209. // 
  210.         upstream online { 
  211.         server 172.28.10.161:8080 max_fails=0 fail_timeout=3s ; 
  212.         server 172.28.10.163:8080  backup; 
  213.      
  214.         check interval=3000 rise=2 fall=1 timeout=1000 type=http; 
  215.         check_http_send "GET / HTTP/1.0\r
    \r
    "; 
  216.         check_http_expect_alive http_2xx http_3xx; 
  217.         } 
  218.  
  219. 2、  
  220. :  , , . 
  221. :A、C 、B . 
  222. : 
  223. server.conf 
  224. // 
  225. server { 
  226.         ...... 
  227.         location / { 
  228.         proxy_pass http://online; 
  229.         } 
  230.         error_page  404 502 = @backup; // 502 online upstream , 502, 404 
  231.          
  232.         location @failover { 
  233.             proxy_pass http://backup; 
  234.         } 
  235.  
  236.         location /status { 
  237.                 check_status; 
  238.                 access_log   off; 
  239.                 allow all;  // IP  
  240.         } 
  241.         ...... 
  242. } 
  243.  
  244. upstream.conf 
  245. // 
  246.     proxy_next_upstream  http_404 http_502;  // 404 max_fails  
  247.         upstream online { 
  248.         sticky; 
  249.         server 172.28.70.161:8080 max_fails=0 fail_timeout=3s ; 
  250.         server 172.28.70.163:8080  max_fails=0 fail_timeout=3s ; 
  251.      
  252.         check interval=3000 rise=2 fall=1 timeout=1000 type=http; 
  253.         check_http_send "GET / HTTP/1.0\r
    \r
    "; 
  254.         check_http_expect_alive http_2xx http_3xx; 
  255.         } 
  256.  
  257.         upstream backup { 
  258.         server 172.28.22.29:7777  max_fails=0 fail_timeout=3s; 
  259.         } 
  260.  
  261.   upstream ,
  262. 2013/01/12 22:57:37 [error] 7627#0: *23641 no live upstreams while connecting to upstream, client: 100.120.111.94, server: *.mydomain.com, request: "GET http://www.mydomain.com/.....( ) HTTP/1.1", upstream: "http://online/.....( ), host: "www.mydomain.com", referrer: "http://www.mydomain.com/.....( )" 

 마지막 으로 지적 해 야 할 것 은 백 엔 드 로그 기록 문제 입 니 다!이것 은 nginx 업그레이드 설치 시 고려 되 었 습 니 다. http 증가realip_모듈 모듈.
본 고 는 '잠입 기술 의 해양' 블 로그 에서 나 온 것 으로 작가 에 게 연락 하 세 요!

좋은 웹페이지 즐겨찾기