Puppet單臺架構擴展(nginx/apache + passenger)

系統環境:rhel6.5puppet 3.7.4

                    Master server1.example.com(192.168.88.128)

                    Agent server2.example.com(192.168.88.129)

原理:使用apachenginx代替puppet原生態的Webrick以提升master的吞吐量,master上啓webserver以負責監聽8140端口並處理客戶端的請求、file文件以及驗證的客戶端請求,將編譯部分代理轉發到後端的master。極大擴展master能夠管理的節點的數量。

Apache+passenger

一.安裝apachepassenger

yum install httpd httpd-devel  mod_ssl  gcc gcc-c++ ruby-devel rubygems

安裝passenger

gem installrack passenger(安裝過程較慢)#rack 用來讓webserverpuppet交換請求和相應的一些                                         常用API

passenger-install-apache2-module   #安裝apache模版

#有時gem安裝失敗,基本是網絡原因,更換gem倉庫

gem sources –-remove https://rubygems.org/

gem sources -a  http://ruby.taobao.org/                    #淘寶的gem鏡像源

二.配置apache

[root@server1 rack]# pwd

/usr/share/puppet/ext/rack                                #配置文件模板位置

[root@server1 rack]# passenger-config   --root #passengerroot 目錄

/usr/lib/ruby/gems/1.8/gems/passenger-5.0.6

mkdir /etc/puppet/rack/

cd /etc/puppet/rack

cp example-passenger-vhost.conf/etc/httpd/conf.d/passenger.conf

cp config.ru   /etc/puppet/rack/

[root@server1 rack]# ll

-rw-r--r-- 1 puppet puppet 1229 Apr 19 09:21 config.ru

drwxr-xr-x 2 root   root  4096 Apr 19 09:20 public

drwxr-xr-x 2 root   root  4096 Apr 19 09:22 tmp

[root@server1 rack]# cat/etc/httpd/conf.d/passenger.conf

# This Apache 2 virtual host config showshow to use Puppet as a Rack

# application via Passenger. See

#http://docs.puppetlabs.com/guides/passenger.html for more information.

LoadModule passenger_module/usr/lib/ruby/gems/1.8/gems/passenger-5.0.6/buildout/apache2/mod_passenger.so

PassengerRoot /usr/lib/ruby/gems/1.8/gems/passenger-5.0.6

PassengerDefaultRuby /usr/bin/ruby             # passenger-install-apache2-module提供的模塊

 

# You can also use the included config.rufile to run Puppet with other Rack

# servers instead of Passenger.

 

# you probably want to tune these settings

PassengerHighPerformance on

PassengerMaxPoolSize 12

PassengerPoolIdleTime 1500

# PassengerMaxRequests 1000

PassengerStatThrottleRate 120

#RackAutoDetectOff

#RailsAutoDetectOff

 

Listen 8140

 

<VirtualHost *:8140>

       SSLEngine on

       SSLProtocol             ALL -SSLv2-SSLv3

       SSLCipherSuite         EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!IDEA:!ECDSA:kEDH:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA

       SSLHonorCipherOrder     on

 

       SSLCertificateFile      /var/lib/puppet/ssl/certs/server1.example.com.pem

       SSLCertificateKeyFile   /var/lib/puppet/ssl/private_keys/server1.example.com.pem

       SSLCertificateChainFile /var/lib/puppet/ssl/ca/ca_crt.pem

       SSLCACertificateFile    /var/lib/puppet/ssl/ca/ca_crt.pem

       # If Apache complains about invalid signatures on the CRL, you can trydisabling

       # CRL checking by commenting the next line, but this is not recommended.

       SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem

       # Apache 2.4 introduces the SSLCARevocationCheck directive and sets itto none

       # which effectively disables CRL checking; if you are using Apache 2.4+you must

       # specify 'SSLCARevocationCheck chain' to actually use the CRL.

       # SSLCARevocationCheck chain

       SSLVerifyClient optional

       SSLVerifyDepth  1

       # The `ExportCertData` option is needed for agent certificate expirationwarnings

       SSLOptions +StdEnvVars +ExportCertData

 

       # This header needs to be set if using a loadbalancer or proxy

       RequestHeader unset X-Forwarded-For

 

       RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e

       RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e

       RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e

 

       DocumentRoot /etc/puppet/rack/public/

       RackBaseURI /

       <Directory /etc/puppet/rack/>

                Options None

                AllowOverride None

                Order allow,deny

                allow from all

       </Directory>

</VirtualHost>

Stop puppetmaster(8140) ;start httpd;

檢測:端口;在agent上測試:puppet agent --server=server1.example.com --test

Master日誌:

[root@server1 rack]# cat  /etc/httpd/logs/access_log

192.168.88.129 - - [19/Apr/2015:09:45:49+0800] "GET /production/node/server2.example.com?fail_on_404=true&transaction_uuid=9823f7a3-0603-48c4-8c27-613697be985cHTTP/1.1" 200 4437 "-" "-"

192.168.88.129 - - [19/Apr/2015:09:45:51+0800] "GET/production/file_metadatas/pluginfacts?checksum_type=md5&ignore=.svn&ignore=CVS&ignore=.git&recurse=true&links=manageHTTP/1.1" 200283 "-" "-"

192.168.88.129 - - [19/Apr/2015:09:45:51+0800] "GET/production/file_metadatas/plugins?checksum_type=md5&ignore=.svn&ignore=CVS&ignore=.git&recurse=true&links=manageHTTP/1.1" 200 283 "-" "-"

192.168.88.129 - - [19/Apr/2015:09:45:51+0800] "POST /production/catalog/server2.example.com HTTP/1.1" 20040146 "-" "-"

192.168.88.129 - - [19/Apr/2015:09:45:53+0800] "PUT/production/report/server2.example.com HTTP/1.1" 200 8 "-""

查看passenger狀態:passenger-status

 


Nginx+passenger

yum install -y gcc gcc-c++ curl-devel zlib-devel openssl-develruby-devel

gem install rack passenger

passenger-install-nginx-module
腳本會自動安裝nginx支持,按提示操作,基本就是一路回車。(中間選1自動下載安裝,選2爲安裝本地nginx)

http {

    passenger_root/usr/lib/ruby/gems/1.8/gems/passenger-5.0.6;

    passenger_ruby/usr/bin/ruby;                     #默認已配置好

 

 

 

server {

listen 8140;

server_name server1.example.com;

root /etc/puppet/rack/public;

passenger_enabled on;

#passenger5.0後換成這個命令,之前的是

#passenger_set_cgi_param HTTP_X_CLIENT_DN           $ssl_client_s_dn;

#passenger_set_cgi_param HTTP_X_CLIENT_VERIFY    $ssl_client_verify;

passenger_set_headerX_CLIENT_DN $ssl_client_s_dn;

passenger_set_headerX_CLIENT_VERIFY $ssl_client_verify;

ssl on;

ssl_session_timeout 5m;

ssl_certificate        /var/lib/puppet/ssl/certs/server1.example.com.pem;

ssl_certificate_key    /var/lib/puppet/ssl/private_keys/server1.example.com.pem;

ssl_client_certificate  /var/lib/puppet/ssl/ca/ca_crt.pem;

ssl_crl        /var/lib/puppet/ssl/ca/ca_crl.pem;

ssl_verify_client        optional;

ssl_ciphers     SSLv2:-LOW:-EXPORT:RC4+RSA;

ssl_prefer_server_ciphers       on;

ssl_verify_depth        1;

ssl_session_cache      shared:SSL:128m;

}

 

啓動nginx即可;

 

 


發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章