HAProxy高可用架构搭建指南
一、架构与规划
二、基础部署步骤
yum install -y haproxy keepalived && systemctl enable haproxy keepalivedglobal log /dev/log local0 maxconn 10000 user haproxy group haproxy daemon nbproc 4 cpu-map 1 0 2 1 3 2 4 3defaults mode http timeout connect 5s timeout client 30s timeout server 30s option httplog option dontlognull option http-server-close retries 3frontend http-in bind :80 bind :443 ssl crt /etc/haproxy/certs/example.com.pem alpn h2,http/1.1 ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256acl allowed_ips src 192.168.1.0/24 tcp-request connection reject if !allowed_ipsdefault_backend serversbackend servers balance leastconn server web1 192.168.1.101:80 check inter 2s rise 2 fall 3 server web2 192.168.1.102:80 check inter 2s rise 2 fall 3listen stats bind :8080 stats enable stats uri /haproxy?stats stats auth admin:SecurePassword stats hide-versionvrrp_script chk_haproxy { script "systemctl is-active haproxy" interval 1 fall 2 rise 2 }vrrp_instance VI_1 { state MASTER interface eth0 virtual_router_id 51 priority 100 advert_int 1 authentication { auth_type PASS auth_pass YourSecurePassword } virtual_ipaddress { 192.168.1.200/24 } track_script { chk_haproxy } }state改为BACKUP,priority设为90(低于主),其余与主一致systemctl start haproxy keepalivedip addr show eth0 | grep 192.168.1.200curl -I http://192.168.1.200 与 curl -Ik https://192.168.1.200。三、生产优化与安全
tune.ssl.default-dh-param 2048、tune.bufsize 32768、tune.maxrewrite 1024option redispatch、retries 3、maxconn(按内存与压测调优,常见为8000–12000)net.ipv4.ip_nonlocal_bind = 1(允许绑定非本地地址,便于VIP)net.core.somaxconn = 65535、net.ipv4.tcp_tw_reuse = 1、net.ipv4.tcp_max_syn_backlog = 10240haproxy soft nofile 65535、haproxy hard nofile 131072firewall-cmd --permanent --add-service=http --add-service=httpsfirewall-cmd --permanent --add-rich-rule='rule protocol value="vrrp" accept' && firewall-cmd --reload四、监控与日志
:8080/haproxy?stats(建议改端口并启用强认证)listen stats bind :9101 mode http stats enable stats uri /metrics stats auth prometheus:Password123local0.* /var/log/haproxy/haproxy.log五、验证与常见问题
systemctl stop keepalived,在备节点执行ip addr show eth0确认VIP漂移curl http://VIP 与 curl -Ik https://VIPab -n 100000 -c 1000 http://VIP/vrrp_script返回值与路径(如/usr/bin/killall)、virtual_router_id一致性、advert_int与认证配置;优先用systemctl is-active haproxy提升可靠性bind为*0.0.0.0/或包含VIP,而非仅绑定某物理IP;检查本机转发与后端健康killall -0,需安装psmisc;脚本建议使用绝对路径避免环境差异。免责声明:本站发布的内容(图片、视频和文字)以原创、转载和分享为主,文章观点不代表本网站立场,如果涉及侵权请联系站长邮箱:is@yisu.com进行举报,并提供相关证据,一经查实,将立刻删除涉嫌侵权内容。