Chuyển đến nội dung chính

レッスン 6: etcd クラスターのインストールと構成

etcd クラスター 3 ノードをダウンロード、インストール、構成し、systemd サービスを作成し、etcdctl コマンドで正常性をチェックします。

🔒 DevSecOps — レッスン 6 レッスン 6: etcd クラスターのインストールと構成

Patroni と PostgreSQL の高可用性etcd

パート 2: インストールと構成

xdev.asia_

目標_

このレッスンの後、次のことを学びます:

  • Patroni アーキテクチャにおける etcd の役割を理解する_
  • etcd を 3 ノードにダウンロードしてインストールする
  • Raft で etcd クラスターを構成するコンセンサス_
  • etcd の systemd サービスを作成_
  • etcd クラスターの正常性を確認_
  • 基本的な etcdctl コマンドのバージョンを使用

1。 etcd_

1.1 の紹介。 etcd とは何ですか?

etcd は、Raft コンセンサス アルゴリズムを使用した、信頼性の高い分散型キー/値ストアです。 CoreOS によって開発され、現在は CNCF (Cloud Native Computing Foundation) のプロジェクトです。

主な機能:

  • 🔐 強い一貫性: との一貫性を確保します。 Raft
  • 🚀 Fast: ミリ秒未満の読み取りレイテンシ
  • 🔄 分散: マルチノード クラスターを実行クォーラム
  • 📡 監視メカニズム: 変更のリアルタイム通知
  • 🔒 TTL サポート: 自動キー有効期限切れ (リーダー用)ロック)
  • 🌐 gRPC + HTTP API: 簡単な統合

1.2。 Patroni アーキテクチャの etcd

┌──────────────────────────────────┐
│      etcd Cluster (3 nodes)      │
│  ┌─────┐   ┌─────┐   ┌─────┐    │
│  │etcd1│───│etcd2│───│etcd3│    │
│  └──┬──┘   └──┬──┘   └──┬──┘    │
│     │         │         │         │
│     └─────────┴─────────┘         │
│        Raft Consensus             │
└──────────────────────────────────┘
│        │        │
┌────┴────┐  │  ┌─────┴─────┐
▼         ▼  ▼  ▼           ▼
┌─────────┐ ┌─────────┐ ┌─────────┐
│Patroni 1│ │Patroni 2│ │Patroni 3│
└─────────┘ └─────────┘ └─────────┘

etcd 保存されたアーカイブ:

  • /service/postgres/leader: リーダー ロック (TTL) 30代)
  • /service/postgres/members/: ノード情報_
  • /service/postgres/config: クラスター構成_
  • /service/postgres/initialize: ブートストラップ状態_
  • /service/postgres/failover: フェイルオーバー手順_

2. etcd

2.1 をダウンロードしてインストールします。アーキテクチャに関する考慮事項

クラスター サイズの推奨事項:

  • 3 ノード: 運用環境の推奨事項、許容値 1失敗
  • 5 ノード: 高可用性、2 つの障害を許容
  • 7+ ノード: ほとんどの用途には過剰ですケース_

導入トポロジ:HTMLTAG_172__CODEBLOCK_1

このラボではオプション 2(同じ場所)を使用して、リソースを保存します。

2.2。 Ubuntu/Debian に etcd をインストール

すべての 3 ノードで実行.

ステップ 1: etcd b をダウンロードするinary

# Set version
ETCD_VER=v3.5.11

Download

wget https://github.com/etcd-io/etcd/releases/download/${ETCD_VER}/etcd-${ETCD_VER}-linux-amd64.tar.gz

Extract

tar xzvf etcd-${ETCD_VER}-linux-amd64.tar.gz

Move binaries to PATH

sudo mv etcd-${ETCD_VER}-linux-amd64/etcd /usr/local/bin/ sudo mv etcd-${ETCD_VER}-linux-amd64/etcdctl /usr/local/bin/ sudo mv etcd-${ETCD_VER}-linux-amd64/etcdutl /usr/local/bin/

Verify

etcd --version etcdctl version

出力:

etcd Version: 3.5.11
Git SHA: ...
Go Version: go1.20.12

ステップ 2: etcd ユーザーとディレクトリを作成_

# Tạo user
sudo useradd -r -s /bin/false etcd

Tạo directories

sudo mkdir -p /var/lib/etcd sudo mkdir -p /etc/etcd

Set ownership

sudo chown -R etcd:etcd /var/lib/etcd sudo chown -R etcd:etcd /etc/etcd

2.3。 CentOS/RHEL

# Download (same as Ubuntu)
ETCD_VER=v3.5.11
wget https://github.com/etcd-io/etcd/releases/download/${ETCD_VER}/etcd-${ETCD_VER}-linux-amd64.tar.gz

tar xzvf etcd-${ETCD_VER}-linux-amd64.tar.gz

sudo mv etcd-${ETCD_VER}-linux-amd64/etcd* /usr/local/bin/

Create user and directories

sudo useradd -r -s /sbin/nologin etcd sudo mkdir -p /var/lib/etcd /etc/etcd sudo chown -R etcd:etcd /var/lib/etcd /etc/etcd

3 にインストールします。 etcd クラスター 3 ノードを構成

3.1。ネットワーク トポロジ_

node1 (etcd1): 10.0.1.11:2379,2380
node2 (etcd2): 10.0.1.12:2379,2380
node3 (etcd3): 10.0.1.13:2379,2380

Port 2379: Client communication (Patroni connects here) Port 2380: Peer communication (etcd cluster internal)

3.2。構成ファイルの作成_

ノード 1 (10.0.1.11) - /etc/etcd/etcd.conf

# Member name
ETCD_NAME="etcd1"

Data directory

ETCD_DATA_DIR="/var/lib/etcd/etcd1.etcd"

Listen URLs

ETCD_LISTEN_PEER_URLS="http://10.0.1.11:2380" ETCD_LISTEN_CLIENT_URLS="http://10.0.1.11:2379,http://127.0.0.1:2379"

Advertise URLs (what other nodes use to connect)

ETCD_INITIAL_ADVERTISE_PEER_URLS="http://10.0.1.11:2380" ETCD_ADVERTISE_CLIENT_URLS="http://10.0.1.11:2379"

Cluster configuration

ETCD_INITIAL_CLUSTER="etcd1=http://10.0.1.11:2380,etcd2=http://10.0.1.12:2380,etcd3=http://10.0.1.13:2380" ETCD_INITIAL_CLUSTER_STATE="new" ETCD_INITIAL_CLUSTER_TOKEN="etcd-cluster-patroni"

Logging

ETCD_LOG_LEVEL="info"

ノード 2 (10.0.1.12) - /etc/etcd/etcd.conf

ETCD_NAME="etcd2"
ETCD_DATA_DIR="/var/lib/etcd/etcd2.etcd"

ETCD_LISTEN_PEER_URLS="http://10.0.1.12:2380" ETCD_LISTEN_CLIENT_URLS="http://10.0.1.12:2379,http://127.0.0.1:2379"

ETCD_INITIAL_ADVERTISE_PEER_URLS="http://10.0.1.12:2380" ETCD_ADVERTISE_CLIENT_URLS="http://10.0.1.12:2379"

ETCD_INITIAL_CLUSTER="etcd1=http://10.0.1.11:2380,etcd2=http://10.0.1.12:2380,etcd3=http://10.0.1.13:2380" ETCD_INITIAL_CLUSTER_STATE="new" ETCD_INITIAL_CLUSTER_TOKEN="etcd-cluster-patroni"

ETCD_LOG_LEVEL="info"

ノード 3 (10.0.1.13) - /etc/etcd/etcd.conf

ETCD_NAME="etcd3"
ETCD_DATA_DIR="/var/lib/etcd/etcd3.etcd"

ETCD_LISTEN_PEER_URLS="http://10.0.1.13:2380" ETCD_LISTEN_CLIENT_URLS="http://10.0.1.13:2379,http://127.0.0.1:2379"

ETCD_INITIAL_ADVERTISE_PEER_URLS="http://10.0.1.13:2380" ETCD_ADVERTISE_CLIENT_URLS="http://10.0.1.13:2379"

ETCD_INITIAL_CLUSTER="etcd1=http://10.0.1.11:2380,etcd2=http://10.0.1.12:2380,etcd3=http://10.0.1.13:2380" ETCD_INITIAL_CLUSTER_STATE="new" ETCD_INITIAL_CLUSTER_TOKEN="etcd-cluster-patroni"

ETCD_LOG_LEVEL="info"

3.3。パラメータの説明

パラメータイタリア語意味_
ETCD_NAME_メンバーの一意の名前クラスター_
_ETCD_DATA_DIRディレクトリを保存データ_
ETCD_LISTEN_PEER_URLSURL はピア通信をリッスンします (ポート2380)
ETCD_LISTEN_CLIENT_URLSURL クライアント接続をリッスンします (ポート2379)_
ETCD_INITIAL_ADVERTISE_PEER_URLS他のピアが接続するための URL to
_ETCD_ADVERTISE_CLIENT_URLSクライアントが接続するための URL to_
_ETCD_INITIAL_CLUSTER_全メンバーのリストブートストラップ
ETCD_INITIAL_CLUSTER_STATE___HTML TAG_275___新規 (初回)または ___HTMLTAG_283__HTMLTAG_284___既存 (追加member)
_ETCD_INITIAL_CLUSTER_TOKEN_一意のクラスターのトークン (混乱を避ける)混合)_

4. systemd サービスを作成

ファイルを作成/etc/systemd/system/etcd.service on ALL 3ノード:

[Unit]
Description=etcd distributed reliable key-value store
Documentation=https://etcd.io/docs/
After=network.target
Wants=network-online.target

[Service] Type=notify User=etcd Group=etcd

Load environment variables from config file

EnvironmentFile=/etc/etcd/etcd.conf

Start etcd with config

ExecStart=/usr/local/bin/etcd

Restart on failure

Restart=on-failure RestartSec=5

Limits

LimitNOFILE=65536 LimitNPROC=65536

Security

NoNewPrivileges=true ProtectHome=true ProtectSystem=strict ReadWritePaths=/var/lib/etcd

[Install] WantedBy=multi-user.target

systemd をリロードし、サービスを有効にします:

sudo systemctl daemon-reload
sudo systemctl enable etcd

5。 etcd クラスター

5.1 を開始します。ノードで etcd を開始_

重要: クラスターを形成できるように、同時にまたは 30 秒以内に開始してください。

ターミナル 1 (ノード 1):

sudo systemctl start etcd
sudo systemctl status etcd

ターミナル2 (ノード 2):

sudo systemctl start etcd
sudo systemctl status etcd

ターミナル 3 (ノード 3):HTMLTAG_332__CODEBLOCK_14

5.2。ログ_

sudo journalctl -u etcd -f

成功した起動ログ:_

... etcd1 became leader at term 2
... established a TCP streaming connection with peer etcd2
... established a TCP streaming connection with peer etcd3
... ready to serve client requests

6を確認してください。 etcd クラスター

6.1 の健全性を確認します。クラスター メンバー

# Từ bất kỳ node nào
etcdctl member list

Output:

8e9e05c52164694d, started, etcd1, http://10.0.1.11:2380, http://10.0.1.11:2379, false

91bc3c398fb3c146, started, etcd2, http://10.0.1.12:2380, http://10.0.1.12:2379, false

fd422379fda50e48, started, etcd3, http://10.0.1.13:2380, http://10.0.1.13:2379, false

6.2 を確認します。クラスターの健全性を確認します_

etcdctl endpoint health --cluster

Output:

http://10.0.1.11:2379 is healthy: successfully committed proposal: took = 2.345678ms

http://10.0.1.12:2379 is healthy: successfully committed proposal: took = 1.234567ms

http://10.0.1.13:2379 is healthy: successfully committed proposal: took = 2.123456ms

6.3。エンドポイントのステータスを確認

etcdctl endpoint status --cluster --write-out=table

Output:

+------------------+------------------+---------+---------+-----------+------------+-----------+------------+--------------------+--------+

| ENDPOINT | ID | VERSION | DB SIZE | IS LEADER | IS LEARNER | RAFT TERM | RAFT INDEX | RAFT APPLIED INDEX | ERRORS |

+------------------+------------------+---------+---------+-----------+------------+-----------+------------+--------------------+--------+

| 10.0.1.11:2379 | 8e9e05c52164694d | 3.5.11 | 20 kB | true | false | 2 | 8 | 8 | |

| 10.0.1.12:2379 | 91bc3c398fb3c146 | 3.5.11 | 20 kB | false | false | 2 | 8 | 8 | |

| 10.0.1.13:2379 | fd422379fda50e48 | 3.5.11 | 20 kB | false | false | 2 | 8 | 8 | |

+------------------+------------------+---------+---------+-----------+------------+-----------+------------+--------------------+--------+

説明出力:

  • IS LEADER_: etcd1 は現在リーダー
  • RAFT TERM: 選挙期間 (選挙ごとに増加)
  • RAFT INDEX: ログの数エントリ_

7。 etcdctl 基本コマンド

7.1。環境を設定します (オプション)

export ETCDCTL_API=3
export ETCDCTL_ENDPOINTS=http://10.0.1.11:2379,http://10.0.1.12:2379,http://10.0.1.13:2379

Thêm vào ~/.bashrc để persistent

echo 'export ETCDCTL_API=3' >> ~/.bashrc echo 'export ETCDCTL_ENDPOINTS=http://10.0.1.11:2379,http://10.0.1.12:2379,http://10.0.1.13:2379' >> ~/.bashrc

7.2。基本操作_

_キーの入力/取得/削除

# Write a key
etcdctl put /test/key1 "Hello etcd"

Read a key

etcdctl get /test/key1

Output:

/test/key1

Hello etcd

Get with details

etcdctl get /test/key1 --write-out=json

Delete a key

etcdctl del /test/key1

プレフィックス付きのキーのリスト_

# Put some test keys
etcdctl put /service/postgres/test1 "value1"
etcdctl put /service/postgres/test2 "value2"

List all keys under /service/postgres/

etcdctl get /service/postgres/ --prefix

Output:

/service/postgres/test1

value1

/service/postgres/test2

value2

変更を監視

# Terminal 1: Watch for changes
etcdctl watch /service/postgres/ --prefix

Terminal 2: Make changes

etcdctl put /service/postgres/leader "node1"

Terminal 1 sẽ hiển thị:

PUT

/service/postgres/leader

node1

TTL キー (リーダーに使用)ロック)

# Create a lease with 30 seconds TTL
etcdctl lease grant 30

Output: lease 7587869125995748410 granted with TTL(30s)

Put key with lease

etcdctl put /test/ttl-key "value" --lease=7587869125995748410

Key sẽ tự động xóa sau 30 giây

Keep lease alive

etcdctl lease keep-alive 7587869125995748410

7.3。高度な操作_

トランザクション (アトミック操作)_

# Atomic compare-and-swap
etcdctl txn <<< '
compare:
value("/test/key1") = "old_value"

success requests: put /test/key1 "new_value"

failure requests: get /test/key1 '

スナップショットバックアップ_

# Create snapshot
etcdctl snapshot save /tmp/etcd-backup.db

Verify snapshot

etcdctl snapshot status /tmp/etcd-backup.db --write-out=table

8。ラボ: etcd クラスターを完全にセットアップ

8.1。ラボの目的

  • ✅ 3 つのノードに etcd をインストール
  • ✅ クラスター構成
  • ✅ クラスターの正常性を確認
  • ✅ 基本的なテスト操作
  • ✅ ノード障害をシミュレート

8.2。ステップバイステップのラボ ガイド

1。 etcd をすべてのノードにインストールします

セクション 2 で完了しました。

2。構成ファイルを作成します

セクション 3 で完了しました。

3。 systemd サービスを作成します

セクション 4.

4 で実装します。クラスター

# Trên cả 3 nodes (đồng thời)
sudo systemctl start etcd

Check status

sudo systemctl status etcd

5を開始します。クラスター_

# Member list
etcdctl member list

Health check

etcdctl endpoint health --cluster

Status

etcdctl endpoint status --cluster --write-out=table

6 を確認します。書き込み/読み取り_

# On node1: Write
etcdctl put /test/mykey "Hello from etcd cluster"

On node2: Read

etcdctl get /test/mykey

Should see: Hello from etcd cluster

On node3: Verify

etcdctl get /test/mykey

Should see: Hello from etcd cluster

7 をテストします。テスト リーダーの選出

# Identify current leader
etcdctl endpoint status --cluster --write-out=table

Note which node IS LEADER = true

Stop leader node

sudo systemctl stop etcd # On leader node

Wait 5-10 seconds

Check from another node

etcdctl endpoint status --cluster --write-out=table

New leader should be elected

Restart stopped node

sudo systemctl start etcd # On stopped node

Verify rejoined

etcdctl member list

8。データの永続性_

# Write some data
etcdctl put /persistent/key "This should survive restart"

Restart ALL nodes (one by one)

sudo systemctl restart etcd

Verify data

etcdctl get /persistent/key

Should still see: This should survive restart

8.3。一般的な問題のトラブルシューティング

問題 1: クラスターが形成されない

# Symptom
journalctl -u etcd -n 50

Error: "request cluster ID mismatch"

Solution: Clear data and restart

sudo systemctl stop etcd sudo rm -rf /var/lib/etcd/* sudo systemctl start etcd

問題 2: etcd に接続できない

# Check if etcd is listening
sudo netstat -tlnp | grep etcd

Should see ports 2379 and 2380

Check firewall

sudo firewall-cmd --list-all # CentOS/RHEL sudo ufw status # Ubuntu

Add firewall rules if needed

sudo ufw allow 2379/tcp sudo ufw allow 2380/tcp

問題 3: ノードがクラスターに参加しない

# Check ETCD_INITIAL_CLUSTER in config
cat /etc/etcd/etcd.conf | grep INITIAL_CLUSTER

Verify network connectivity

ping 10.0.1.11 telnet 10.0.1.11 2380

問題 4: スプリット ブレインまたは複数のリーダー

# Check cluster status
etcdctl endpoint status --cluster --write-out=table

If multiple leaders (shouldn't happen with proper setup):

1. Stop all etcd instances

sudo systemctl stop etcd # On all nodes

2. Clear data on all nodes

sudo rm -rf /var/lib/etcd/*

3. Restart cluster (bootstrap again)

Start all nodes within 30 seconds

9。パフォーマンスのチューニング_

9.1。 etcd 調整パラメータ_

# Add to /etc/etcd/etcd.conf

Heartbeat interval (default: 100ms)

ETCD_HEARTBEAT_INTERVAL="100"

Election timeout (default: 1000ms)

ETCD_ELECTION_TIMEOUT="1000"

Snapshot count (default: 10000)

Compact and snapshot after this many transactions

ETCD_SNAPSHOT_COUNT="10000"

Quota backend bytes (default: 2GB)

Max database size

ETCD_QUOTA_BACKEND_BYTES="2147483648"

9.2。 etcd のモニタリング

監視する主要なメトリクス:

  • 遅延 (99 パーセンタイル < 50 ミリ秒)
  • ディスクの fsync 持続時間 (< 50 ミリ秒) 10ms)
  • リーダーの変更 (まれであるはず)
  • データベースのサイズ
  • 失敗した提案

チェックメトリクス:_

curl http://10.0.1.11:2379/metrics

Key metrics:

etcd_server_has_leader

etcd_server_leader_changes_seen_total

etcd_disk_backend_commit_duration_seconds

etcd_network_peer_round_trip_time_seconds

10。概要

重要なポイント

✅ etcd クラスター: 実稼働用の 3 ノード クラスターHA

✅ ポート: 2379 (クライアント)、2380 (ピア)

✅ Raftコンセンサス: 自動リーダー選出とデータ複製

✅ クォーラム: クラスターが動作するには 2/3 ノードが必要動的_

✅ TTL キー: Patroni リーダー ロックに使用

✅ etcdctl: 管理およびトラブルシューティング

チェックリストは後でラボ

  •  etcd クラスター 3 ノードが実行
  •  etcdctl メンバーリスト 全表示 3メンバー
  •  etcdctl エンドポイントの正常性 --cluster すべて正常
  •  リーダーが 1 人、フォロワーが 2 人です
  •  etcd サービスが有効になっています再起動すると自動起動
  •  ファイアウォールはポート 2379 と 2380 を許可します_

_現在のアーキテクチャ

✅ 3 VMs prepared (Bài 4)
✅ PostgreSQL 15 installed (Bài 5)
✅ etcd cluster running (Bài 6)

Next: Cài đặt Patroni và bootstrap HA cluster

レッスンの準備7

次のレッスンでは、Patroni をインストールし、セットアップ etcd クラスターと統合します。