{"id":2989,"date":"2022-08-30T11:43:48","date_gmt":"2022-08-30T02:43:48","guid":{"rendered":"https:\/\/weseek.co.jp\/tech\/?p=2989"},"modified":"2023-04-17T10:26:39","modified_gmt":"2023-04-17T01:26:39","slug":"ubuntu-20-04-%e3%81%a7-keepalived-%e3%82%92%e5%90%8c%e4%b8%80%e7%ad%90%e4%bd%93%e3%81%a7%e7%94%a8%e3%81%84%e3%81%a6%e5%86%97%e9%95%b7%e6%a7%8b%e6%88%90-%e8%b2%a0%e8%8d%b7%e5%88%86%e6%95%a3%e3%81%99","status":"publish","type":"post","link":"https:\/\/weseek.co.jp\/tech\/2989\/","title":{"rendered":"Ubuntu 20.04 \u3067 Keepalived \u3092\u540c\u4e00\u7b50\u4f53\u3067\u7528\u3044\u3066\u5197\u9577\u69cb\u6210\/\u8ca0\u8377\u5206\u6563\u3059\u308b"},"content":{"rendered":"<h1>\u306f\u3058\u3081\u306b<\/h1>\n<p>\u3053\u3093\u306b\u3061\u306f\u3001WESEEK \u306b\u3066\u30a8\u30f3\u30b8\u30cb\u30a2\u3092\u3057\u3066\u3044\u308b\u85e4\u6fa4\u3067\u3059\u3002<br \/>\n\u3053\u306e\u8a18\u4e8b\u3067\u306f keepalived \u3068 real server \u3092\u540c\u4e00\u7b50\u4f53\u306b\u306e\u305b\u3001 VRRP(Virtual Router Redundancy Protocol) \u306b\u3088\u308b\u5197\u9577\u69cb\u6210, LVS \u306b\u3088\u308b\u8ca0\u8377\u5206\u6563\u3092\u884c\u3046\u65b9\u6cd5\u306b\u3064\u3044\u3066\u89e3\u8aac\u3057\u307e\u3059\u3002<\/p>\n<p>\u5197\u9577\u69cb\u6210\/\u8ca0\u8377\u5206\u6563\u3092\u884c\u3046\u65b9\u6cd5\u306f\u3044\u304f\u3064\u304b\u3042\u308a\u307e\u3059\u304c\u3001\u4eca\u56de\u306f keepalived \u3092\u4f7f\u3063\u3066\u5b9f\u73fe\u3057\u307e\u3059\u3002<\/p>\n<p><!--more--><\/p>\n\n<h1>keepalived \u306e\u30e1\u30ea\u30c3\u30c8\/\u30c7\u30e1\u30ea\u30c3\u30c8<\/h1>\n<p>keepalived \u3092\u4f7f\u3046\u30e1\u30ea\u30c3\u30c8\u3068\u3057\u3066<\/p>\n<ul>\n<li>\u7121\u6599<\/li>\n<li>LVS \u304c\u30ab\u30fc\u30cd\u30eb\u7a7a\u9593\u3067\u51e6\u7406\u3059\u308b\u306e\u3067\u6bd4\u8f03\u7684\u65e9\u3044\u3002<\/li>\n<\/ul>\n<p>\u307e\u305f\u3001\u30c7\u30e1\u30ea\u30c3\u30c8\u3068\u3057\u3066\u306f<\/p>\n<ul>\n<li>nginx \u7b49\u3067\u884c\u308f\u308c\u308b\u3088\u3046\u306a L7 header \u306b\u3088\u308b\u51e6\u7406\u7b49\u304c\u3067\u304d\u306a\u3044<\/li>\n<\/ul>\n<p>\u306a\u3069\u304c\u3042\u308a\u307e\u3059<\/p>\n<h1>\u524d\u63d0\u77e5\u8b58<\/h1>\n<p>\u69cb\u7bc9\u306e\u8a71\u3092\u30e1\u30a4\u30f3\u3068\u3059\u308b\u306e\u3067\u6982\u8981\u306e\u307f\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<h2>VRRP(Virtual Router Redundancy Protocol)<\/h2>\n<p>VRRP \u306f\u30b5\u30fc\u30d0\u3084\u30c7\u30d5\u30a9\u30eb\u30c8\u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u7b49\u3092\u5197\u9577\u5316\u3059\u308b\u305f\u3081\u306e\u30d7\u30ed\u30c8\u30b3\u30eb\u3067\u3059\u3002<br \/>\n\u8907\u6570\u53f0\u3042\u308b VRRP \u3092\u9069\u7528\u3057\u305f\u30b5\u30fc\u30d0\u306b\u5bfe\u3057\u3066\u540c\u4e00\u306e\u4eee\u60f3 IP (VIP)\u3092\u5272\u308a\u5f53\u3066\u308b\u3053\u3068\u3067\u4e00\u53f0\u306e\u30b5\u30fc\u30d0\u306e\u3088\u3046\u306b\u898b\u305b\u304b\u3051\u308b\u3053\u3068\u304c\u51fa\u6765\u307e\u3059\u3002<br \/>\n\u3042\u308b 1 \u53f0\u306e\u30b5\u30fc\u30d0\u304c master \u3068\u306a\u308a VIP \u3078\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u53d7\u3051\u4ed8\u3051\u307e\u3059\u3002\u4ed6\u306e\u30b5\u30fc\u30d0\u306f backup \u3068\u306a\u308a\u3001master\u3001backup \u304c\u76f8\u4e92\u306b\u6b7b\u6d3b\u76e3\u8996\u3057\u3042\u3046\u3053\u3068\u3067 master \u304c\u6b7b\u3093\u3060\u969b\u306b\u306f backup \u304c master \u306b\u6607\u683c\u3059\u308b\u3053\u3068\u3067\u5197\u9577\u6027\u304c\u4fdd\u305f\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u4eca\u56de\u306e\u69cb\u6210\u3067\u306f keepalived \u304c\u6301\u3063\u3066\u3044\u308b VRRP \u306e\u6a5f\u80fd\u3092\u5229\u7528\u3057\u307e\u3059<\/p>\n<h2>LVS(Linux Virtual Server)<\/h2>\n<p>LVS \u3068\u306f L4 \u8ca0\u8377\u5206\u6563\u6a5f\u80fd\u3092\u63d0\u4f9b\u3059\u308b\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3067\u3059\u3002<br \/>\nIPVS(IP Virtual Server) \u3068\u3044\u3046 Linux \u30ab\u30fc\u30cd\u30eb\u30e2\u30b8\u30e5\u30fc\u30eb\u3067\u63d0\u4f9b\u3055\u308c\u305f\u6a5f\u80fd\u3092\u3082\u3068\u306b\u52d5\u4f5c\u3059\u308b\u306e\u3067\u6bd4\u8f03\u7684\u901f\u3044\u3067\u3059\u3002<br \/>\nLVS \u306e\u69cb\u6210\u3068\u3057\u3066 NAT \u3068 DR \u304c\u3042\u308a\u307e\u3059\u3002\u4ee5\u4e0b\u3067\u306f\u305d\u306e\u6982\u8981\u3068\u30e1\u30ea\u30c3\u30c8\/\u30c7\u30e1\u30ea\u30c3\u30c8\u306b\u3064\u3044\u3066\u8ff0\u3079\u307e\u3059\u3002<br \/>\n\u307e\u305f\u3001\u5b9f\u969b\u306b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u3044\u308b\u30b5\u30fc\u30d0\u3092 real server \u3068\u547c\u3073\u307e\u3059\u3002<\/p>\n<h3>NAT<\/h3>\n<p>VIP \u5b9b\u306e\u30d1\u30b1\u30c3\u30c8\u3092\u53d7\u3051\u53d6\u3063\u305f LVS \u306f real server \u3078\u30d1\u30b1\u30c3\u30c8\u3092\u9069\u5207\u306b(\u30e9\u30a6\u30f3\u30c9\u30ed\u30d3\u30f3\u7b49)\u9001\u4fe1\u3057\u3001real server \u306f\u30d1\u30b1\u30c3\u30c8\u3092\u51e6\u7406\u3057\u3001\u518d\u3073 LVS \u3078\u9001\u4fe1\u3057\u307e\u3059\u3002<br \/>\n\u5fdc\u7b54\u306e\u30d1\u30b1\u30c3\u30c8\u3092\u53d7\u3051\u53d6\u3063\u305f LVS \u306f\u9001\u4fe1\u5143\u30a2\u30c9\u30ec\u30b9\u3092 LVS \u306e\u3082\u306e\u306b\u5909\u63db\u3057\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3078\u9001\u4fe1\u3057\u307e\u3059\u3002<\/p>\n<p>\u3064\u307e\u308a LVS \u304c NAT \u30d1\u30b1\u30c3\u30c8\u3092\u8ee2\u9001\u3059\u308b\u69cb\u6210\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<h4>\u30e1\u30ea\u30c3\u30c8<\/h4>\n<ul>\n<li>DR \u306b\u6bd4\u3079\u3066\u8a2d\u5b9a\u304c\u697d<\/li>\n<li>real server \u306f\u5916\u90e8\u3068\u758e\u901a\u304c\u306a\u304f\u3066\u3082 LVS \u306e\u3042\u308b\u30b5\u30fc\u30d0\u304c\u758e\u901a\u3092\u6301\u3066\u3070\u826f\u3044<\/li>\n<\/ul>\n<h4>\u30c7\u30e1\u30ea\u30c3\u30c8<\/h4>\n<ul>\n<li>LVS \u3078\u8ca0\u8377\u304c\u96c6\u4e2d\u3059\u308b<\/li>\n<\/ul>\n<h3>DR<\/h3>\n<p>VIP \u5b9b\u306e\u30d1\u30b1\u30c3\u30c8\u3092\u53d7\u3051\u53d6\u3063\u305f LVS \u306f real server \u3078\u30d1\u30b1\u30c3\u30c8\u3092\u9069\u5207\u306b(\u30e9\u30a6\u30f3\u30c9\u30ed\u30d3\u30f3\u7b49)\u9001\u4fe1\u3057\u3001real server \u306f\u76f4\u63a5\u30d1\u30b1\u30c3\u30c8\u3092\u51e6\u7406\u3057\u3066\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3078\u8fd4\u3057\u307e\u3059\u3002<\/p>\n<h4>\u30e1\u30ea\u30c3\u30c8<\/h4>\n<ul>\n<li>NAT \u3068\u9055\u3044 LVS \u3078\u8fd4\u3055\u306a\u3044\u306e\u3067 LVS \u306e\u8ca0\u8377\u304c\u4f4e\u3044<\/li>\n<\/ul>\n<h4>\u30c7\u30e1\u30ea\u30c3\u30c8<\/h4>\n<ul>\n<li>\u7279\u306b\u540c\u4e00\u7b50\u4f53\u3067\u306f\u7279\u6b8a\u306a\u8a2d\u5b9a\u304c\u5fc5\u8981<\/li>\n<\/ul>\n<p>\u4eca\u56de\u306f\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3001\u5b9f\u30b5\u30fc\u30d0\u3001LVS \u304c\u540c\u4e00\u30bb\u30b0\u30e1\u30f3\u30c8\u306b\u3042\u308b\u5834\u5408\u3092\u60f3\u5b9a\u3057\u3001\u3053\u3061\u3089\u306e DR \u306e\u65b9\u5f0f\u3092\u63a1\u7528\u3057\u307e\u3059\u3002<\/p>\n<h1>Amazon EC2 \u3067\u691c\u8a3c<\/h1>\n<ul>\n<li>EC2 \u3067\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3092 3 \u53f0\u5efa\u3066\u308b\n<ul>\n<li>\u30b9\u30da\u30c3\u30af\n<ul>\n<li>Canonical, Ubuntu, 22.04 LTS, amd64 jammy image build on 2022-06-09<\/li>\n<li>64bit (x86)<\/li>\n<li>t2.micro<\/li>\n<li>storage: 8GiB gp2<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>VPC \u3067\u540c\u4e00\u30b5\u30d6\u30cd\u30c3\u30c8\u306b\u4f5c\u6210\u5f8c\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b0\u30eb\u30fc\u30d7\u7b49\u3067\u76f8\u4e92\u306b\u901a\u4fe1\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3057\u3087\u3046<\/li>\n<\/ul>\n<h1>\u4eca\u56de\u306e\u69cb\u6210<\/h1>\n<p>\u4eca\u56de\u306e\u30b7\u30b9\u30c6\u30e0\u69cb\u6210\u3067\u3059\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306f VIP \u3078\u30ea\u30af\u30a8\u30b9\u30c8\u3059\u308b\u3053\u3068\u3067 keepalived \u306b\u3088\u3063\u3066 VRRP master \u3068\u306a\u3063\u3066\u3044\u308b\u30ce\u30fc\u30c9\u3078\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u5c4a\u304d\u307e\u3059\u3002<br \/>\n\u305d\u306e\u5f8c LVS \u306b\u3088\u3063\u3066\u5404\u30ce\u30fc\u30c9\u306e application \u3078\u9069\u5207\u306b\u632f\u308a\u5206\u3051\u3089\u308c\u307e\u3059\u3002<\/p>\n<p>\u4eca\u56de\u306e\u8a18\u4e8b\u3067\u306f real server \u3092 vrrp_instance \u306b\u5c5e\u3059\u308b\u30ce\u30fc\u30c9, application \u3092 real server \u4e0a\u3067 8000\u756a\u30dd\u30fc\u30c8\u3067\u52d5\u304f http server \u3068\u3057\u3066\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<p>\u6ce8: \u4eca\u56de\u306e\u69cb\u6210\u3067\u306f VRRP \u30b0\u30eb\u30fc\u30d7\u306b\u5c5e\u3059\u308b\u30ce\u30fc\u30c9\u5185\u90e8\u304b\u3089\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u6b63\u5e38\u306b\u51e6\u7406\u3067\u304d\u307e\u305b\u3093\u3002<br \/>\n\u6ce8: application \u3092 docker \u3067\u8d77\u52d5\u3059\u308b\u3068\u6b63\u5e38\u306b\u632f\u308a\u5206\u3051\u304c\u51fa\u6765\u306a\u3044\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002\u4eca\u5f8c\u6642\u9593\u304c\u3042\u308c\u3070\u5bfe\u51e6\u6cd5\u3092\u8abf\u3079\u3066\u8ffd\u8a18\u3057\u307e\u3059\u3002<\/p>\n<p><img src=\"https:\/\/weseek.co.jp\/tech\/wp-content\/uploads\/2022\/08\/techblog-keepalived-2.png\" alt=\"\" \/><\/p>\n<h1>keepalived \u5c0e\u5165<\/h1>\n<p>\u4ee5\u4e0b\u304b\u3089\u306f\u5b9f\u969b\u306e\u8a2d\u5b9a\u65b9\u6cd5\u3068\u8a2d\u5b9a\u9805\u76ee\u306b\u3064\u3044\u3066\u89e3\u8aac\u3057\u307e\u3059\u3002<\/p>\n<h2>\u5404\u30ce\u30fc\u30c9\u5171\u901a<\/h2>\n<p>\u5404\u30ce\u30fc\u30c9\u3067\u5171\u901a\u306b\u5b9f\u884c\u3057\u3066\u304f\u3060\u3055\u3044\u3002<br \/>\n\u305f\u3060\u3057\u3001keepalived.conf \u306e priority \u306e\u307f\u5909\u66f4\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<h3>keepalived \u95a2\u9023\u306e\u8a2d\u5b9a<\/h3>\n<pre><code>$ sudo apt-get update\n$ sudo apt-get install -y keepalived\n$ keepalived --version\n# \u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u51fa\u6765\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d<\/code><\/pre>\n<p>\u3053\u3053\u307e\u3067\u3067 keepalived \u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u304c\u5b8c\u4e86<\/p>\n<pre><code>$ sudo vi \/etc\/keepalived\/keepalived.conf\n# \u4ee5\u4e0b\u306e\u30b3\u30f3\u30d5\u30a3\u30b0\u3092\u5165\u308c\u308b\n# priority \u306f\u30ce\u30fc\u30c9\u3054\u3068\u306b\u5909\u3048\u3066\u304f\u3060\u3055\u3044<\/code><\/pre>\n<pre><code>global_defs {\n    enable_script_security\n}\n\nvrrp_instance LVS_SETTINGS {\n    state BACKUP # state \u306f priority \u3092\u898b\u3066\u81ea\u52d5\u3067 MASTER BACKUP \u5207\u308a\u66ff\u3048\u3092\u3057\u3066\u304f\u308c\u308b\u306e\u3067\u5168\u3066 BACKUP \u3067\u6307\u5b9a\n    interface eth0 # \u53d7\u3051\u4ed8\u3051\u308b\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u3092\u6307\u5b9a\n    virtual_router_id 50 # VRRP \u306b\u5c5e\u3059\u308b\u30b0\u30eb\u30fc\u30d7\u3092\u30e6\u30cb\u30fc\u30af\u306b\u6307\u5b9a\u3059\u308b id\n    priority 100 # Master state \u306b\u3059\u308b\u30ce\u30fc\u30c9\u306e\u512a\u5148\u5ea6(\u30ce\u30fc\u30c9\u3054\u3068\u306b\u5909\u66f4\u3057\u3066\u304f\u3060\u3055\u3044)\n    advert_int 1 # VRRP \u306b\u3088\u308b\u751f\u5b58\u78ba\u8a8d\u30d1\u30b1\u30c3\u30c8\u306e\u9593\u9694\n    notify_master &quot;\/etc\/keepalived\/notify_master.sh&quot; # \u5f8c\u8ff0\n    notify_backup &quot;\/etc\/keepalived\/notify_backup.sh&quot; # \u5f8c\u8ff0\n    virtual_ipaddress {\n        10.0.0.5 # VIP \u3092\u6307\u5b9a\u3057\u3066\u304f\u3060\u3055\u3044\n    }\n}\n\ninclude virtualserver-backup.conf # \u5f8c\u8ff0<\/code><\/pre>\n<pre><code>$ sudo vi \/etc\/keepalived\/virtualserver-backup.conf\n# \u7a7a\u3067 ok<\/code><\/pre>\n<ul>\n<li>global_defs\n<ul>\n<li>\u5404\u30ce\u30fc\u30c9\u5171\u6709\u306e\u8a2d\u5b9a\u3092\u5165\u308c\u308b\u3068\u3053\u308d<\/li>\n<li>enable_script_security: \u4eca\u56de\u306f master\/backup \u3067\u8a2d\u5b9a\u3092\u5207\u308a\u66ff\u3048\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u8d70\u3089\u305b\u308b\u306e\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a root \u3067\u5b9f\u884c\u51fa\u6765\u306a\u3044\u3088\u3046\u306b\u3057\u3066\u3044\u308b<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<pre><code>$ sudo vi \/etc\/keepalived\/virtualserver-master.conf\n# \u4ee5\u4e0b\u306e\u30b3\u30f3\u30d5\u30a3\u30b0\u3092\u5165\u308c\u308b<\/code><\/pre>\n<pre><code>virtual_server 10.0.0.5 8000 { # \u5bfe\u8c61\u306e VIP \u3092\u6307\u5b9a\n    delay_loop 6 # \u30a2\u30d7\u30ea\u306e\u751f\u5b58\u78ba\u8a8d\u9593\u9694\n    lb_algo rr # \u8ca0\u8377\u5206\u6563\u624b\u6cd5\n    lb_kind DR # \u30d1\u30b1\u30c3\u30c8\u8ee2\u9001\u65b9\u5f0f\n    protocol TCP # \u5bfe\u8c61\u306e\u30d7\u30ed\u30c8\u30b3\u30eb\n\n    real_server 10.0.0.12 8000 {\n        weight 1 # \u8ca0\u8377\u5206\u6563\u3067\u4f7f\u3046\u91cd\u307f\n        HTTP_GET { # \u751f\u5b58\u78ba\u8a8d\u306e\u30d7\u30ed\u30c8\u30b3\u30eb\n            url {\n                path \/health # \u751f\u5b58\u78ba\u8a8d\u306e\u30d1\u30b9\n            }\n            connect_timeout 10\n        }\n    }\n    real_server 10.0.0.14 8000 {\n        weight 1\n        HTTP_GET {\n            url {\n                path \/health\n            }\n            connect_timeout 10\n        }\n    }\n}<\/code><\/pre>\n<pre><code>$ sudo vi \/etc\/keepalived\/notify_master.sh\n# \u4ee5\u4e0b\u306e\u30b3\u30f3\u30d5\u30a3\u30b0\u3092\u5165\u308c\u308b<\/code><\/pre>\n<pre><code>#!\/bin\/bash -u\n\nsudo sed -i -e &quot;s\/include virtualserver-backup.conf\/include virtualserver-master.conf\/g&quot; \/etc\/keepalived\/keepalived.conf\nsudo service keepalived reload<\/code><\/pre>\n<p>state \u304c MASTER \u306b\u306a\u3063\u305f\u3068\u304d\u306b virtualserver-master.conf \u3092\u4f7f\u3046\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u3067\u3001virtualserver \u3092\u9069\u7528\u3059\u308b\u3002<\/p>\n<pre><code>$ sudo vi \/etc\/keepalived\/notify_backup.sh\n# \u4ee5\u4e0b\u306e\u30b3\u30f3\u30d5\u30a3\u30b0\u3092\u5165\u308c\u308b<\/code><\/pre>\n<pre><code>#!\/bin\/bash -u\n\nRELOAD_FLG=0\ngrep &quot;include virtualserver-backup.conf&quot; \/etc\/keepalived\/keepalived.conf &gt; \/dev\/null # Normally the exit status is 0 if a line is selected, 1 if no lines were selected, and 2 if an error occurred. see: man grep\nif [ $? -ne 0 ] ; then\n  RELOAD_FLG=1\nfi\nsudo sed -i -e &quot;s\/include virtualserver-master.conf\/include virtualserver-backup.conf\/g&quot; \/etc\/keepalived\/keepalived.conf\n\n# reload \u306e\u30bf\u30a4\u30df\u30f3\u30b0\u3067 BACKUP state \u306b\u79fb\u884c\u3057\u3066\u518d\u5ea6\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u5b9f\u884c\u3055\u308c\u308b\u305f\u3081\u3001\u7121\u9650\u5b9f\u884c\u3092\u9632\u3050\u305f\u3081\u306b\u30c1\u30a7\u30c3\u30af\u3092\u884c\u3046\nif [ ${RELOAD_FLG} -eq 1 ] ; then\n  sudo service keepalived reload\nfi<\/code><\/pre>\n<p>state \u304c BACKUP \u306b\u306a\u3063\u305f\u3068\u304d\u306b virtualserver-backup.conf \u3092\u4f7f\u3046\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u3067\u3001virtualserver \u306e\u8a2d\u5b9a\u3092\u524a\u9664\u3059\u308b\u3002<\/p>\n<p>\u4eca\u56de\u306f\u540c\u4e00\u7b50\u4f53\u306b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068 keepalived(LVS) \u3092\u8f09\u305b\u308b\u69cb\u6210\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u305d\u306e\u5834\u5408 backup \u3067 LVS \u3092\u8d77\u52d5\u3057\u3066\u3044\u308b\u3068 master \u306e LVS \u306b\u3088\u3063\u3066 backup \u3078\u632f\u308a\u5206\u3051\u3089\u308c\u305f\u30d1\u30b1\u30c3\u30c8\u304c\u518d\u3073 LVS \u306b\u6355\u307e\u308a\u5225\u306e\u30ce\u30fc\u30c9\u3078\u632f\u308a\u5206\u3051\u3089\u308c\u30eb\u30fc\u30d7\u3057\u307e\u3059\u3002<br \/>\n\u305d\u306e\u305f\u3081\u3001notify_master\/backup (VRRP state \u304c\u5207\u308a\u66ff\u308f\u3063\u305f\u969b\u306b\u5b9f\u884c\u3055\u308c\u308b\u30b9\u30af\u30ea\u30d7\u30c8)\u306b\u3088\u3063\u3066 keepalived \u306e\u8a2d\u5b9a\u3092\u66f8\u304d\u63db\u3048\u3066\u3044\u307e\u3059\u3002<\/p>\n<h3>keepalived \u304c script \u3092\u5b9f\u884c\u3059\u308b user \u3092\u4f5c\u6210<\/h3>\n<p>master\/backup \u5207\u308a\u66ff\u3048\u6642\u306b keepalived \u304c script \u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306e\u30e6\u30fc\u30b6\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<pre><code>$ sudo useradd keepalived_script\n$ sudo visudo\n# \u4ee5\u4e0b\u3092\u8ffd\u8a18\n# keepalived_script ALL=(ALL:ALL) NOPASSWD: ALL<\/code><\/pre>\n<p>\u30b9\u30af\u30ea\u30d7\u30c8\u3078\u5b9f\u884c\u3059\u308b\u6a29\u9650\u3092\u3064\u3051\u307e\u3059\u3002<\/p>\n<pre><code>$ cd \/etc\/keepalived\n$ sudo chmod u+x notify_backup.sh notify_master.sh\n$ sudo chown keepalived_script:keepalived_script notify_backup.sh notify_master.sh<\/code><\/pre>\n<h1>DR \u7528\u306e\u8a2d\u5b9a<\/h1>\n<p>\u540c\u4e00\u7b50\u4f53\u3067 DR \u3092\u4f7f\u3046\u5834\u5408\u3044\u304f\u3064\u304b\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306e\u8a2d\u5b9a\u304c\u5fc5\u8981\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<h2>sysctl.conf<\/h2>\n<pre><code>sudo vi \/etc\/sysctl.d\/98-keepalived.conf\n# \u30d5\u30a1\u30a4\u30eb\u540d\u306f\u30a2\u30eb\u30d5\u30a1\u30d9\u30c3\u30c8\u9806\u306b\u8aad\u307f\u8fbc\u307e\u308c\u308b\u306e\u3067\u305d\u3053\u307e\u3067\u6c17\u306b\u3057\u306a\u304f\u3066\u3082\u5927\u4e08\u592b\u3067\u3059\n# \u4ee5\u4e0b\u306e\u8a2d\u5b9a\u3092\u5165\u308c\u308b<\/code><\/pre>\n<pre><code># Do not rename this file so it is run at the end of \/etc\/sysctl.d\/*.conf files load.\n# Run `sysctl -p` to apply\n\n# \u30d1\u30b1\u30c3\u30c8\u3092\u8ee2\u9001\u3059\u308b\u305f\u3081\u306b IP \u30d5\u30a9\u30fc\u30ef\u30fc\u30c9\u3092\u8a31\u53ef\nnet.ipv4.ip_forward = 1\n\n# ARP \u30ea\u30af\u30a8\u30b9\u30c8\u304c eth0 \u306b\u6765\u305f\u3068\u304d\u306b eth0 \u306b vip \u304c\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u306a\u304b\u3063\u305f\u3068\u3057\u3066\u3082\u3001\n# lo \u306b vip \u304c\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u308b\u3068 ARP \u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u8fd4\u3057\u3066\u3057\u307e\u3046\u305f\u3081\u3001\n# \u305d\u308c\u3092\u9632\u3050\u305f\u3081\u306b eth0 \u306b\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u306a\u3044\u30a2\u30c9\u30ec\u30b9\u306b\u5bfe\u3059\u308b ARP \u30ea\u30af\u30a8\u30b9\u30c8\u306b\u306f\u5fdc\u7b54\u3057\u306a\u3044\u3088\u3046\u306b\u3057\u3066\u3044\u308b\n# see: https:\/\/www.valinux.co.jp\/technologylibrary\/document\/linux\/arp0001\/\nnet.ipv4.conf.eth0.arp_ignore = 1\nnet.ipv4.conf.eth0.arp_announce = 2\n\n# LVS \u9593\u3067\u306e\u901a\u4fe1\u3068\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3068\u306e\u901a\u4fe1\u3067\u7570\u306a\u308b NIC \u3092\u4f7f\u7528\u3059\u308b\u5834\u5408\u306f rp_filter \u3092\u7121\u52b9\u5316(0)\u306b\n# net.ipv4.conf.eth0.rp_filter = 0<\/code><\/pre>\n<pre><code>$ sudo sysctl -p\n# \u9069\u7528\u3059\u308b<\/code><\/pre>\n<h2>lo \u306b VIP \u3092\u3064\u3051\u308b<\/h2>\n<p>DR \u3092\u540c\u4e00\u7b50\u4f53\u3067\u7528\u3044\u308b\u5834\u5408\u3001real server \u304c VIP \u5b9b\u306e\u901a\u4fe1\u3092\u51e6\u7406\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<br \/>\nSTATE \u304c MASTER \u3067\u3042\u308b real server \u306f keepalived \u306b\u3088\u3063\u3066 NIC \u306b VIP \u304c\u5272\u308a\u5f53\u3066\u3089\u308c\u308b\u306e\u3067\u3059\u304c\u3001STATE \u304c BACKUP \u3067\u3042\u308b real server \u3067\u306f NIC \u306b VIP \u304c\u5272\u308a\u5f53\u3066\u3089\u308c\u306a\u3044\u306e\u3067\u3001\u4eca\u56de\u306f lo \u306b VIP \u3092\u5272\u308a\u5f53\u3066\u308b\u3053\u3068\u3067 VIP \u5b9b\u306e\u30d1\u30b1\u30c3\u30c8\u3092\u51e6\u7406\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/p>\n<pre><code>$ sudo vi \/etc\/netplan\/99_lo_config.yaml\n# \u4ee5\u4e0b\u306e\u30b3\u30f3\u30d5\u30a3\u30b0\u3092\u5165\u308c\u308b<\/code><\/pre>\n<pre><code># This config is used for applying vip to lo interface.\n# By this, each real server is able to use vip as its own ip address.\n# Run `netplan apply` to apply\nnetwork:\n  version: 2\n  renderer: networkd\n  ethernets:\n    lo:\n      addresses:\n      - 10.0.0.5\/32<\/code><\/pre>\n<pre><code>$ sudo netplan apply\n# \u9069\u7528\u3059\u308b<\/code><\/pre>\n<p>\u4ee5\u4e0b\u306e\u3088\u3046\u306b lo \u306b\u3000VIP (10.0.0.5) \u304c\u3064\u3044\u3066\u3044\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u308c\u3070 ok \u3067\u3059\u3002<\/p>\n<pre><code>ubuntu@ip-10-0-0-12:~$ ip a show lo\n1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000\n    link\/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00\n    inet 127.0.0.1\/8 scope host lo\n       valid_lft forever preferred_lft forever\n    inet 10.0.0.5\/32 scope global lo\n       valid_lft forever preferred_lft forever\n    inet6 ::1\/128 scope host \n       valid_lft forever preferred_lft forever<\/code><\/pre>\n<h1>\u691c\u8a3c<\/h1>\n<p>\u6700\u521d\u306b keepalived \u3092\u518d\u8d77\u52d5\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre><code>$ sudo systemctl restart keepalived\n# keepalived \u306e\u518d\u8d77\u52d5<\/code><\/pre>\n<h2>\u9069\u5f53\u306a\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092 8000 \u756a\u3067\u8d77\u52d5<\/h2>\n<p>\u672c\u984c\u3068\u306f\u5916\u308c\u308b\u306e\u3067\u8a73\u3057\u304f\u306f\u8aac\u660e\u3057\u307e\u305b\u3093\u304c\u3001\u53c2\u8003\u307e\u3067\u306b\u4eca\u56de\u4f7f\u7528\u3057\u305f\u30b5\u30f3\u30d7\u30eb\u3092\u8f09\u305b\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<p>test-webserver.rb<\/p>\n<pre><code>require &#039;webrick&#039;\n\nsrv = WEBrick::HTTPServer.new(\n  DocumentRoot: &#039;.\/&#039;,\n  BindAddress: &quot;0.0.0.0&quot;,\n  Port: 8000,\n)\n\nsrv.mount(&#039;\/&#039;, WEBrick::HTTPServlet::FileHandler, &#039;index.html&#039;)\nsrv.start<\/code><\/pre>\n<p>index.html<\/p>\n<pre><code>hello world (real server (\u533a\u5225\u3059\u308b\u305f\u3081\u306b\u30ce\u30fc\u30c9\u3054\u3068\u306b\u5225\u306e\u6587\u5b57\u3092\u5165\u308c\u3066\u304f\u3060\u3055\u3044))<\/code><\/pre>\n<p>\u4e0a\u8a18\u3092 ruby \u3067\u5b9f\u884c<\/p>\n<h2>\u307e\u305a\u8a2d\u5b9a\u304c\u3046\u307e\u304f\u3044\u3063\u3066\u3044\u308b\u304b\u3069\u3046\u304b\u78ba\u8a8d<\/h2>\n<pre><code>$ sudo journalctl -u keepalived<\/code><\/pre>\n<p>Entering MASTER\/BACKUP STATE<br \/>\n\u306e\u3088\u3046\u306a\u8a18\u8ff0\u304c\u3042\u308c\u3070 ok \u3067\u3059\u3002<\/p>\n<h2>VIP \u5b9b\u306e\u901a\u4fe1\u304c\u5197\u9577\/\u8ca0\u8377\u5206\u6563\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b<\/h2>\n<h3>\u691c\u8a3c\u7528\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u304b\u3089 VIP \u3078\u5411\u3051\u3066 curl \u3057\u3001\u8ca0\u8377\u5206\u6563\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b<\/h3>\n<pre><code>$ curl http:\/\/10.0.0.5:8000\/\nhello world(real server 1)\n$ curl http:\/\/10.0.0.5:8000\/\nhello world(real server 2)\n$ curl http:\/\/10.0.0.5:8000\/\nhello world(real server 1)\n$ curl http:\/\/10.0.0.5:8000\/\nhello world(real server 2)<\/code><\/pre>\n<p>\u4ee5\u4e0a\u306e\u3088\u3046\u306b\u4ea4\u4e92\u306b real server \u3078\u9001\u3089\u308c\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3067\u304d\u308c\u3070\u3000ok \u3067\u3059\u3002<\/p>\n<h3>real server \u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u843d\u3068\u3057\u3001\u5197\u9577\u5316\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b<\/h3>\n<p>real server \u3067\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u843d\u3068\u3057\u3066\u3001\u524d\u9805\u76ee\u540c\u69d8 curl \u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p>\u751f\u304d\u3066\u3044\u308b\u65b9\u306e real server \u306e\u901a\u4fe1\u306e\u307f\u304c\u8fd4\u3063\u3066\u304f\u308c\u3070 ok \u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u306f\u3058\u3081\u306b \u3053\u3093\u306b\u3061\u306f\u3001WESEEK \u306b\u3066\u30a8\u30f3\u30b8\u30cb\u30a2\u3092\u3057\u3066\u3044\u308b\u85e4\u6fa4\u3067\u3059\u3002 \u3053\u306e\u8a18\u4e8b\u3067\u306f keepalived \u3068 real server \u3092\u540c\u4e00\u7b50\u4f53\u306b\u306e\u305b\u3001 VRRP(Virtual Router Redundancy P<\/p>\n","protected":false},"author":23,"featured_media":3501,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[64,93],"tags":[],"_links":{"self":[{"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/posts\/2989"}],"collection":[{"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/comments?post=2989"}],"version-history":[{"count":37,"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/posts\/2989\/revisions"}],"predecessor-version":[{"id":4008,"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/posts\/2989\/revisions\/4008"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/media\/3501"}],"wp:attachment":[{"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/media?parent=2989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/categories?post=2989"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/weseek.co.jp\/tech\/wp-json\/wp\/v2\/tags?post=2989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}