Tecnologia da Informação - TI : Pen

Total de visualizações de página

Mostrando postagens com marcador Pen. Mostrar todas as postagens
Mostrando postagens com marcador Pen. Mostrar todas as postagens

segunda-feira, 25 de abril de 2016

Pen : MariaDB Load Balancing


Pen : MariaDB Load Balancing
2015/06/10
 
Configure Pen to Load Balance to 2 MariaDB backends.
       |
-------+-----------------------------------------------
       |
       +-------------------+--------------------+
       |10.0.0.30          |10.0.0.51           |10.0.0.52
 +-----+------+    +-------+------+     +-------+------+
 |  Frontend  |    |   Backend#1  |     |   Backend#2  |
 | Pen Server |    |    MariaDB   |     |    MariaDB   |
 +------------+    +--------------+     +--------------+

[1]Configure Pen. Before this section, configure basic settings, refer to here.
[root@dlp ~]# 
vi /etc/pen.conf
# create new

LOGFILE=/var/log/pen.log
WEBFILE=/var/www/pen/webstats.html
MAX_CONNECTIONS=256
ROUNDROBIN=true
# listening port

PORT=3306
# number of backends

BACKEND=2
# define backend servers

SERVER1=10.0.0.51:3306
SERVER2=10.0.0.52:3306
[root@dlp ~]# 
systemctl restart pen 
[2]Make sure all works fine to access to the frontend server from a Client with SQL like follows.
[root@desktop ~]# 
mysql -u keystone -p -h 10.0.0.30 keystone -e "select * from table01;" 

Enter password:
+------+-------------------+
| id   | name              |
+------+-------------------+
|    1 | db01.server.world |
+------+-------------------+

[root@desktop ~]# 
mysql -u keystone -p -h 10.0.0.30 keystone -e "select * from table01;" 

Enter password:
+------+-------------------+
| id   | name              |
+------+-------------------+
|    1 | db02.server.world |
+------+-------------------+

Pen : Refer to the Statics


Pen : Refer to the Statics
2015/06/10
 
Configure Pen to refer to the Statics.
[1]
Install httpd, refer to here.
Furthermore, port 80 is used by pen, so change the port of httpd from 80 to another port. This example uses 8081.
[2]Configure Pen.
[root@dlp ~]# 
cp /usr/share/doc/pen-*/penstats /var/www/pen 

[root@dlp ~]# 
vi /var/www/pen/penstats
# line 4,5: change

PIDFILE=
/var/run/pen.pid

WEBFILE=
/var/www/pen/webstats.html
[root@dlp ~]# 
vi /etc/httpd/conf.d/pen.conf
# change like follows

Alias
 /pen/ /var/www/pen/
<Directory /var/www/pen/>
    DirectoryIndex 
webstats.html

    
#
Options ExecCGI
    <IfModule mod_authz_core.c>
        # Apache 2.4
        
# add access permission

        Require local
        Require ip 10.0.0.0/24
    </IfModule>
[root@dlp ~]# 
systemctl restart httpd 

[root@dlp ~]# 
chmod 755 /var/www/pen/penstats 
# generate statics

[root@dlp ~]# 
/var/www/pen/penstats > /dev/null 

# add to Cron

[root@dlp ~]# 
echo '*/5 * * * * /var/www/pen/penstats > /dev/null' > /etc/cron.d/pend 
[3]Access to "http://(Pen server's hostname or IP address):(httpd listening port)/pen/", then it's possible to refer statics of Pen like follows.

Pen : SSL Settings


Pen : SSL Settings
2015/06/10
 
Configure Pen with SSL.
The connection between Pen and Clients are encrypted with SSL. ( Pen - backends are normal )
This example based on the environment like follows.
        |
--------+--------------------------------------------------------------------
        |
        +-------------------+--------------------+--------------------+
        |10.0.0.30          |10.0.0.51           |10.0.0.52           |10.0.0.53
 +------+-----+     +-------+------+     +-------+------+     +-------+------+
 |  Frontend  |     |   Backend#1  |     |   Backend#2  |     |   Backend#3  |
 | Pen Server |     |  Web Server  |     |  Web Server  |     |  Web Server  |
 +------------+     +--------------+     +--------------+     +--------------+

[1]Create SSL certificates.
[root@dlp ~]# 
cd /etc/pki/tls/certs 

[root@dlp certs]# 
openssl req -x509 -nodes -newkey rsa:2048 -keyout /etc/pki/tls/certs/pen.pem -out /etc/pki/tls/certs/pen.pem -days 365 

Generating a 2048 bit RSA private key
......++++++
.......++++++
writing new private key to '/etc/pki/tls/certs/pen.pem'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [AU]:
JP
# country

State or Province Name (full name) [Some-State]:
Hiroshima
   
# state

Locality Name (eg, city) []:
Hiroshima
# city

Organization Name (eg, company) [Internet Widgits Pty Ltd]:
Server World
   
# company

Organizational Unit Name (eg, section) []:
IT Solution
   
# department

Common Name (eg, YOUR name) []:
dlp.server.world
   
# server's FQDN

Email Address []:
xxx@server.world
# admin email
[root@dlp certs]# 
chmod 600 pen.pem 
[2]Configure Pen for SSL.
[root@dlp ~]# 
vi /etc/pen.conf
# change port and specify certificates

PORT=
443
SSLCERTS=/etc/pki/tls/certs/pen.pem
[root@dlp ~]# 
systemctl restart pen 
[3]Make sure all works fine to access to the frontend server from a Client with HTTPS like follows.

Pen : HTTP Load Balancing


Pen : HTTP Load Balancing
2015/06/10
 
Install pen which is lightweight simple Load Balancing software.
It is TCP protocol based, so it's possible to balance not only HTTP but SMTP, FTP, LDAP and so on.
This example is based on the environment like follows.
        |
--------+--------------------------------------------------------------------
        |
        +-------------------+--------------------+--------------------+
        |10.0.0.30          |10.0.0.51           |10.0.0.52           |10.0.0.53
 +------+-----+     +-------+------+     +-------+------+     +-------+------+
 |  Frontend  |     |   Backend#1  |     |   Backend#2  |     |   Backend#3  |
 | Pen Server |     |  Web Server  |     |  Web Server  |     |  Web Server  |
 +------------+     +--------------+     +--------------+     +--------------+

 
Configure Pen to load balance to Backend#1, Backend#2, Backend#3 web servers.
[1]Install Pen.
# install from EPEL

[root@dlp ~]# 
yum --enablerepo=epel -y install pen
[2]Configure Pen.
[root@dlp ~]# 
vi /etc/pen.conf
# create new

# log file

LOGFILE=/var/log/pen.log
# statics report file

WEBFILE=/var/www/pen/webstats.html
# max connections

MAX_CONNECTIONS=256
# send X-Forwarded-For header

XFORWARDEDFOR=true
# Round-Robin mode

ROUNDROBIN=true
# listening port

PORT=80
# number of backends

BACKEND=3
# define backend servers

SERVER1=10.0.0.51:80
SERVER2=10.0.0.52:80
SERVER2=10.0.0.53:80
# create an init script

[root@dlp ~]# 
vi /etc/rc.d/init.d/pend
#!/bin/bash

# pend: Start/Stop Pend
# chkconfig: - 90 10
# description: Pen is a light weight simple load balancer.
# pidfile: /var/run/pen.pid

. /etc/rc.d/init.d/functions
. /etc/pen.conf

LOCKFILE="/var/lock/subsys/pen"
PID=/var/run/pen.pid
PROG=/usr/bin/pen
PROGNAME=Pend

RETVAL=0
start() {
    SERVER=`grep "^SERVER" /etc/pen.conf | cut -d= -f2`
    [ $XFORWARDEDFOR = "true" ] && SERVER="-H $SERVER"
    [ $ROUNDROBIN = "true" ] && SERVER="-r $SERVER"
    [ $SSLCERTS ] && SERVER="-E $SSLCERTS $SERVER"

    echo -n $"Starting $PROGNAME: "
    daemon $PROG $PORT -w $WEBFILE -x $MAX_CONNECTIONS -p $PID -l $LOGFILE -S $BACKEND $SERVER
    RETVAL=$?
    echo
    [ $RETVAL -eq 0 ] && touch $LOCKFILE
    return $RETVAL
}
stop() {
    echo -n $"Stopping $PROGNAME: "
    killproc $PROG
    RETVAL=$?
    echo
    [ $RETVAL -eq 0 ] && rm -f $PID $LOCKFILE
    return $RETVAL
}
case "$1" in
    start)
        start
        ;;
    stop)
        stop
        ;;
    status)
        status -p "$PID" -l $PROG $PROGNAME
        ;;
    restart)
        stop
        start
        ;;
    *)
        echo $"Usage: $0 {start|stop|status|restart}"
        exit 1
esac
exit $?

[root@dlp ~]# 
chmod 755 /etc/rc.d/init.d/pend
# create a Systemd setting file

[root@dlp ~]# 
vi /usr/lib/systemd/system/pen.service
[Unit]
Description=Pend service
After=network.target

[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/etc/rc.d/init.d/pend start
ExecStop=/etc/rc.d/init.d/pend stop

[Install]
WantedBy=multi-user.target

[root@dlp ~]# 
systemctl start pen 

[root@dlp ~]# 
systemctl enable pen 
[3]Configure httpd on backend servers to record logs of X-Forwarded-For.
[root@www ~]# 
vi /etc/httpd/conf/httpd.conf
# line 196: change

LogFormat "
\"%{X-Forwarded-For}i\"
 %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
[root@www ~]# 
systemctl restart httpd 
[4]Make sure all works fine to access to the frontend server from a Client with HTTP like follows.

Console Sony Playstation 5 Edição Slim Disk 1tb Branco + Controle Sem Fio Dualsense Ps5 Branco

https://meli.la/1pJv7oL LINK ->  https://meli.la/1pJv7oL  Características do produto Capacidade 1 TB Com Wi-Fi Sim Tipo de console De ...