Pacemaker添加浮动IP导致haproxy克隆资源停止

我有一个标准的2节点HAproxy负载平衡器设置与起搏器1.1(使用PC)和haproxy 1.5。 我有2个浮动IP地址与haproxy服务作为haproxy克隆资源的约束。 我需要在hparoxy-clone服务上添加一个具有相同约束的新的浮动IP。 我的第一个问题是,当我创build浮动IP资源,它开始在没有其他IP地址的节点上。 然后我运行pcs constraint colocation add haproxy-clone with floatIP_189 (floatIP_189是我的新地址)。 这不会将IP地址移动到其他节点,并且haproxy克隆资源将停止。 我可以通过重新启动两个节点上的起搏器服务来重新启动haproxy服务。

如何在不降低stream量的情况下向起搏器添加新的浮动IP,否则会中断负载平衡器上的其他站点。

下面是haproxy.cfg文件,pcs status命令的输出和pcs config命令的输出;

  [root@t-haproxylb3 haproxy]# cat haproxy.cfg peers QAHAproxypeers peer t-haproxylb3 10.xx185:1024 peer t-haproxylb4 10.xx186:1024 global log 127.0.0.1 local0 # log /dev/log local0 # log /dev/log local1 notice chroot /var/lib/haproxy stats socket /var/lib/haproxy/stats stats timeout 30s tune.ssl.default-dh-param 2048 user haproxy group haproxy daemon defaults log global mode http option httplog option dontlognull option redispatch option forwardfor option http-server-close maxconn 5000 timeout connect 5s timeout client 5h timeout server 5h timeout queue 30s timeout http-request 5s timeout http-keep-alive 15s listen stats *:1936 mode http stats enable stats hide-version stats realm Haproxy\ Statistics stats uri /haproxy_stats stats auth admin:password stats admin if TRUE frontend http_in bind *:80 ###Add new acl and use_backend entry for each new site ###new backend sections will be needed as well acl is_clients hdr(host) -i clients.qa.racingcars.com acl is_apps hdr(host) -i apps.qa.racingcars.com acl is_dad hdr(host) -i dad.qa.racingcars.com acl is_scripting hdr(host) -i scripting.qa.racingcars.com acl is_racingcarsnet hdr_end(host) -i racingcars.net use_backend http_client if is_clients use_backend http_apps if is_apps use_backend http_dad if is_dad use_backend http_scripting if is_scripting use_backend http_racingcarsnet if is_racingcarsnet option forwardfor option http-server-close frontend https_in_ssl_apps bind 10.xx187:443 ssl crt /etc/ssl/private/apps.racingcars.com.pem mode http use_backend https_ssl_apps option forwardfor option http-server-close frontend https_in_ssl_clients bind 10.xx188:443 ssl crt /etc/ssl/private/clients.racingcars.com.pem mode http use_backend https_ssl_clients option forwardfor option http-server-close frontend https_in_ssl_scripting bind 10.xx189:443 ssl crt /etc/ssl/private/clients.racingcars.com.pem mode http use_backend https_ssl_scripting option forwardfor option http-server-close frontend https_in_ssl mode http # bind *:443 ssl crt /etc/ssl/private/ no-sslv3 bind *:443 ssl crt /etc/ssl/private/ reqadd X-Forwarded-Proto:\ https ####### commented out below to enable https pass-through for apps # use_backend http_clients if { ssl_fc_sni clients.racingcars.com } # use_backend http_apps if { ssl_fc_sni apps.racingcars.com } acl is_ssl_racingcarsnet hdr_end(host) -i racingcars.net use_backend http_racingcarsnet if is_ssl_racingcarsnet backend http_clients balance source cookie SRV_ID prefix stick-table type ip size 1m expire 6h peers QAHAproxypeers stick on src ###This site does not use host header - only the page name is needed### # option httpchk HEAD /Default.aspx ###Added host header so haproxy can route around NLB - use below for checking### option httpchk HEAD /Default.aspx HTTP/1.1\r\nHost:\ clients.qa.racingcars.com server websvr03 10.xx183:80 cookie web3 weight 5 check # server websvr04 10.xx118:80 cookie web4 weight 5 check backend https_ssl_clients balance source cookie SRV_ID prefix stick-table type ip size 1m expire 6h peers QAHAproxypeers stick on src option httpchk HEAD /Default.aspx HTTP/1.1\r\nHost:\ clients.qa.racingcars.com server websvr03 10.xx183:443 cookie web3 weight 5 check ssl verify none # server websvr04 10.xx118:443 cookie web4 weight 5 check ssl verify none backend http_apps balance roundrobin stick-table type ip size 1m expire 6h peers QAHAproxypeers stick on src ###This site uses host headers so this type of check is required### option httpchk HEAD /default.htm HTTP/1.1\r\nHost:\ apps.qa.racingcars.com server websvr03 10.xx182:80 cookie web3 weight 5 check # server websvr04 10.xx116:80 cookie web4 weight 5 check backend https_ssl_apps balance roundrobin stick-table type ip size 1m expire 6h peers QAHAproxypeers stick on src ###This site uses host headers so this type of check is required### option httpchk HEAD /default.htm HTTP/1.1\r\nHost:\ apps.qa.racingcars.com server websvr03 10.xx182:443 cookie web3 weight 5 check ssl verify none # server websvr04 10.xx116:443 cookie web4 weight 5 check ssl verify none backend http_dad balance roundrobin cookie SRV_ID prefix stick-table type ip size 1m expire 6h peers QAHAproxypeers stick on src ###This site does not use host header - only the page name is needed### option httpchk HEAD /login.aspx HTTP/1.1\r\nHost:\ dad.qa.racingcars.com server websvr03 10.xx182:80 cookie web3 weight 5 check # server websvr04 10.xx116:80 cookie web4 weight 5 check backend http_scripting balance roundrobin cookie SRV_ID prefix stick-table type ip size 1m expire 6h peers QAHAproxypeers stick on src ###This site uses host header so this type of check is required### option httpchk HEAD /default.aspx HTTP/1.1\r\nHost:\ scripting.qa.racingcars.com server websvr03 10.xx184:80 cookie web3 weight 5 check # server websvr04 10.xx116:80 cookie web4 weight 5 check backend https_ssl_scripting balance source cookie SRV_ID prefix stick-table type ip size 1m expire 6h peers QAHAproxypeers stick on src option httpchk HEAD /Default.aspx HTTP/1.1\r\nHost:\ scripting.qa.racingcars.com server websvr03 10.xx184:443 cookie web3 weight 5 check ssl verify none # server websvr04 10.xx118:443 cookie web4 weight 5 check ssl verify none backend http_racingcarsnet balance roundrobin cookie SRV_ID prefix stick-table type ip size 1m expire 6h peers QAHAproxypeers stick on src ###This site uses host header so this type of check is required### option httpchk HEAD /default.aspx HTTP/1.1\r\nHost:\ test.racingcars.net # server websvr03 10.xx115:80 cookie web3 weight 5 check # server websvr04 10.xx117:80 cookie web4 weight 5 check [root@t-haproxylb3 haproxy]# pcs status Cluster name: testcluster2 Stack: corosync Current DC: t-haproxylb3 (version 1.1.15-11.el7_3.2-e174ec8) - partition with quorum Last updated: Tue Dec 20 16:55:37 2016 Last change: Tue Dec 20 14:15:59 2016 by root via cibadmin on t-haproxylb3 2 nodes and 5 resources configured Online: [ t-haproxylb3 t-haproxylb4 ] Full list of resources: Clone Set: haproxy-clone [haproxy] Started: [ t-haproxylb3 ] Stopped: [ t-haproxylb4 ] floatIP_187 (ocf::heartbeat:IPaddr2): Started t-haproxylb3 floatIP_188 (ocf::heartbeat:IPaddr2): Started t-haproxylb3 floatIP_189 (ocf::heartbeat:IPaddr2): Started t-haproxylb3 Daemon Status: corosync: active/enabled pacemaker: active/enabled pcsd: active/enabled [root@t-haproxylb3 haproxy]# pcs config Cluster Name: testcluster2 Corosync Nodes: t-haproxylb3 t-haproxylb4 Pacemaker Nodes: t-haproxylb3 t-haproxylb4 Resources: Clone: haproxy-clone Resource: haproxy (class=systemd type=haproxy) Operations: monitor interval=10s (haproxy-monitor-interval-10s) Resource: floatIP_187 (class=ocf provider=heartbeat type=IPaddr2) Attributes: ip=10.xx187 cidr_netmask=32 Operations: start interval=0s timeout=20s (floatIP_187-start-interval-0s) stop interval=0s timeout=20s (floatIP_187-stop-interval-0s) monitor interval=30s (floatIP_187-monitor-interval-30s) Resource: floatIP_188 (class=ocf provider=heartbeat type=IPaddr2) Attributes: ip=10.xx188 cidr_netmask=32 Operations: start interval=0s timeout=20s (floatIP_188-start-interval-0s) stop interval=0s timeout=20s (floatIP_188-stop-interval-0s) monitor interval=30s (floatIP_188-monitor-interval-30s) Resource: floatIP_189 (class=ocf provider=heartbeat type=IPaddr2) Attributes: ip=10.xx189 cidr_netmask=32 Operations: start interval=0s timeout=20s (floatIP_189-start-interval-0s) stop interval=0s timeout=20s (floatIP_189-stop-interval-0s) monitor interval=30s (floatIP_189-monitor-interval-30s) Stonith Devices: Fencing Levels: Location Constraints: Ordering Constraints: Colocation Constraints: haproxy-clone with floatIP_187 (score:INFINITY) (id:colocation-haproxy-clone-f loatIP_187-INFINITY) haproxy-clone with floatIP_188 (score:INFINITY) (id:colocation-haproxy-clone-f loatIP_188-INFINITY) haproxy-clone with floatIP_189 (score:INFINITY) (id:colocation-haproxy-clone-f loatIP_189-INFINITY) Ticket Constraints: Alerts: No alerts defined Resources Defaults: resource-stickiness: 100 Operations Defaults: No defaults set Cluster Properties: cluster-infrastructure: corosync cluster-name: testcluster2 dc-version: 1.1.15-11.el7_3.2-e174ec8 have-watchdog: false stonith-enabled: false Quorum: Options: 

您应该在cib(pacemakerconfiguration)的离线副本上工作,然后只有在您准备好时才将其推入群集。 这应该是你想要做的:

从集群中取出configuration到一个xml文件中:

 # pcs cluster cib cib_virtip.xml 

然后将您的虚拟IP资源添加到文件中:

 # pcs -f cib_virtip.xml resource create floatIP_190 ocf:heartbeat:IPaddr2 \ ip=10.xx190 cidr_netmask=32 \ op monitor interval=20s timeout=20s \ start interval=0s timeout=20s \ stop interval=0s timeout=20s 

将约束添加到文件中:

 # pcs -f cib_virtip.xml constraint colocation add haproxy-clone with floatIP_190 # pcs -f cib_virtip.xml constraint order floatIP_190 then haproxy-clone 

注意:你会想为它们添加sorting约束,对吧?

如果您在推送新的CIB之前手动将IP地址添加到适当的接口(下一步),则Pacemaker应该在系统启动之前探测系统以确定事物的位置并且不需要采取任何措施(不会停止haproxy)新的VIP。

确认你没有搞错,然后把它推入集群:

 # pcs cluster verify cib_virtip.xml # pcs cluster cib-push cib_virtip.xml 

我不确定你会如何将ha-proxy绑定到地址上; 也许有一个“重新加载”或“调整”types的命令。 希望有所帮助。