consul入门
consul
consul用于微服务下的服务治理,主要特点有:服务发现、服务配置、健康检查、键值存储、安全服务通信、多数据中心等。
什么叫服务治理发现?起初我们的服务比较单一,各服务之间通过接口就能访问。后面服务越来越复杂出现了分布式,为了不引起单点问题,必然是多服务部署,如果还用原来的方式直接连接,那么在某个服务挂掉或者修改了信息,就会导致连接失败。如果连接端能够不去关心具体的服务配置,他只要连接到那个服务,后续的工作由其它服务保证,包括负载均衡、健康检查等,保证总有可用的连接那就行了,consul就是做这个的,当然,它的功能远不止这些,这里只是以服务发现为例。
与它同类的东西,还有eureka、zookeeper、etcd等也能做这些事,说不上谁好谁坏,看场景挑合适的吧,不过eureka现在已经闭源了,这个还是建议不要去用这个了。
consul下载
consule的安装超级简单,去官方下载地址download ,找到自已对应系统的压缩包,解压后里面就一个文件consul, 将这个文件放到你的path中,就能直接用了。
验证下安装成功没有, 看到下面的提示就行了。
$ consul version consul v1.7.2 protocol 2 spoken by default, understands 2 to 3 (agent will automatically use protocol >2 when speaking to compatible agents)
consul的cli操作
consul提供了cli的命令操作,如启动代理、键值存储、注册/注销服务、加入集群等,这个consul提供的http的api操作也是一样的,只是这里都是shell的操作。
$ consul usage: consul [--version] [--help] <command> [<args>] available commands are: acl interact with consul's acls agent runs a consul agent catalog interact with the catalog config interact with consul's centralized configurations connect interact with consul connect debug records a debugging archive for operators event fire a new event exec executes a command on consul nodes force-leave forces a member of the cluster to enter the "left" state info provides debugging information for operators. intention interact with connect service intentions join tell consul agent to join cluster keygen generates a new encryption key keyring manages gossip layer encryption keys kv interact with the key-value store leave gracefully leaves the consul cluster and shuts down lock execute a command holding a lock login login to consul using an auth method logout destroy a consul token created with login maint controls node or service maintenance mode members lists the members of a consul cluster monitor stream logs from a consul agent operator provides cluster-level tools for consul operators reload triggers the agent to reload configuration files rtt estimates network round trip time between nodes services interact with services snapshot saves, restores and inspects snapshots of consul server state tls builtin helpers for creating cas and certificates validate validate config files/directories version prints the consul version watch watch for changes in consul
agent启动
consul是通过agent来运行的,agent又分为server agent和client agent两种类型,这两类型基本上是没区别的,server agent会将服务的消息存储起来,至少要启动一个server agent,为了防止单点,集群环境中推荐3-5个。
client agent主要用于注销服务、健康检查及转发server agent的查询等,它相当于一个代理,所以他必须在集群的每台主机上都要运行。
先看下agent的常用配置
$ consul agent --help
-
--server 定义运行server agent
-
--data-dir 配置consul数据存储路径
-
--bootstrap-expect :期望的server节点数目,consul一直等到指定sever数目的时候才会引导整个集群
-
--bind:该地址用来在集群内部的通讯,集群内的所有节点到地址都必须是可达的,默认是0.0.0.0
-
--node:节点在集群中的名称,在一个集群中必须是唯一的,默认是该节点的主机名
-
--ui: web的管理ui,查看服务和节点
-
--config-dir:配置文件目录,所有以.json结尾的文件都会被加载,可以是服务或consul自身的配置
-
--client:提供http、dns、rpc等服务,默认是127.0.0.1,不对外提供服务,如果需要则改成0.0.0.0
我本地没有虚拟机,也没用docker操作,所以,如果要同时启动server和client的话,我就用的改端口的方式,当然生产环境肯定就没有这个了,它都是一台机器启动一个agent, 这里只是测试用的。
启动一个server agent
$ consul agent --server=true --ui=true --data-dir=/tmp/consul --node=server1 --dev
上面的 --server
表示以server方式,--ui
会开启一个web ui管理界面, --dev
表示开发者模式,不需要acl验证。不然那个web ui的打不开会报没有权限。
==> starting consul agent... version: 'v1.7.2' node id: 'f6272369-098a-1412-ed86-6e2076c1e5e4' node name: 'server1' datacenter: 'dc1' (segment: '<all>') server: true (bootstrap: false) client addr: [127.0.0.1] (http: 8500, https: -1, grpc: 8502, dns: 8600) cluster addr: 127.0.0.1 (lan: 8301, wan: 8302) encrypt: gossip: false, tls-outgoing: false, tls-incoming: false, auto-encrypt-tls: false ==> log data will now stream in as it occurs: 2020-04-01t14:28:52.579+0800 [debug] agent.tlsutil: update: version=1 2020-04-01t14:28:52.580+0800 [debug] agent.tlsutil: outgoingrpcwrapper: version=1 2020-04-01t14:28:52.580+0800 [info] agent.server.raft: initial configuration: index=1 servers="[{suffrage:voter id:f6272369-098a-1412-ed86-6e2076c1e5e4 address:127.0.0.1:8300}]" 2020-04-01t14:28:52.580+0800 [info] agent.server.raft: entering follower state: follower="node at 127.0.0.1:8300 [follower]" leader= 2020-04-01t14:28:52.581+0800 [info] agent.server.serf.wan: serf: eventmemberjoin: server1.dc1 127.0.0.1 2020-04-01t14:28:52.581+0800 [info] agent.server.serf.lan: serf: eventmemberjoin: server1 127.0.0.1 2020-04-01t14:28:52.581+0800 [info] agent.server: adding lan server: server="server1 (addr: tcp/127.0.0.1:8300) (dc: dc1)" 2020-04-01t14:28:52.581+0800 [info] agent.server: handled event for server in area: event=member-join server=server1.dc1 area=wan 2020-04-01t14:28:52.581+0800 [info] agent: started dns server: address=127.0.0.1:8600 network=tcp 2020-04-01t14:28:52.582+0800 [info] agent: started dns server: address=127.0.0.1:8600 network=udp 2020-04-01t14:28:52.582+0800 [info] agent: started http server: address=127.0.0.1:8500 network=tcp 2020-04-01t14:28:52.582+0800 [info] agent: started grpc server: address=127.0.0.1:8502 network=tcp 2020-04-01t14:28:52.582+0800 [info] agent: started state syncer ==> consul agent running!
启动client agent
$ consul agent --data-dir=/tmp/consul_client --join=127.0.0.1:8301 --serf-lan-port=8303 --serf-wan-port=8305 --dns-port=8601 --server-port=8304 --http-port=8503 --server=false --config-dir=./consul.d --enable-script-checks --node=client1
上面有一个--join
表示加入到集群中,写server agent的地址就行。
config-dir的配置目录下面一个服务的配置
{ "service":{ "name":"web", "tags":[ "local" ], "port":80, "check":{ "name":"ping", "args":["/usr/bin/curl","-s", "http://localhost/"], "interval":"10s" } } }
上面的命令运行后,会启动一个名字为“web"的服务,并提供健康检查。
==> starting consul agent... version: 'v1.7.2' node id: 'e1c8f283-f5c4-27e7-c29c-64666df1c52b' node name: 'client1' datacenter: 'dc1' (segment: '') server: false (bootstrap: false) client addr: [127.0.0.1] (http: 8503, https: -1, grpc: -1, dns: 8601) cluster addr: 192.168.0.103 (lan: 8303, wan: 8305) encrypt: gossip: false, tls-outgoing: false, tls-incoming: false, auto-encrypt-tls: false ==> log data will now stream in as it occurs: 2020-04-01t00:00:49.227+0800 [info] agent.client.serf.lan: serf: eventmemberjoin: client1 192.168.0.103 2020-04-01t00:00:49.231+0800 [info] agent: started dns server: address=127.0.0.1:8601 network=udp 2020-04-01t00:00:49.232+0800 [info] agent: started dns server: address=127.0.0.1:8601 network=tcp 2020-04-01t00:00:49.232+0800 [info] agent: started http server: address=127.0.0.1:8503 network=tcp ==> joining cluster... 2020-04-01t00:00:49.232+0800 [info] agent: (lan) joining: lan_addresses=[127.0.0.1:8301] 2020-04-01t00:00:49.233+0800 [warn] agent.client.memberlist.lan: memberlist: refuting a dead message (from: client1) 2020-04-01t00:00:49.233+0800 [info] agent.client.serf.lan: serf: eventmemberjoin: server1 127.0.0.1 2020-04-01t00:00:49.233+0800 [info] agent.client: adding server: server="server1 (addr: tcp/127.0.0.1:8300) (dc: dc1)" 2020-04-01t00:00:49.233+0800 [info] agent: (lan) joined: number_of_nodes=1 2020-04-01t00:00:49.233+0800 [info] agent: join completed. initial agents synced with: agent_count=1 2020-04-01t00:00:49.233+0800 [info] agent: started state syncer ==> consul agent running! 2020-04-01t00:00:49.235+0800 [info] agent: synced node info 2020-04-01t00:00:49.235+0800 [info] agent: synced service: service=web 2020-04-01t00:00:53.316+0800 [info] agent: synced check: check=service:web
查看下,启动的agent
$ ./consul members node address status type build protocol dc segment server1 127.0.0.1:8301 alive server 1.7.2 2 dc1 <all> client1 127.0.0.1:8303 alive client 1.7.2 2 dc1 <default>
web管理界面
可以查看服务的定义和节点,访问[web管理界面](
http api
consul除了提供dns外,还提供http的操作,如注册服务、查看节点、查看服务信息等,一般都是通过api来操作的。
如我上面定义的 "web"服务,通过下面的api查询,就能得到具体的ip地址和端口,这样就能直接连到那台服务了。
其它更详情api操作,可以自已去参照官方的文档 api
$ curl http://127.0.0.1:8500/v1/catalog/service/web [ { "id": "e1c8f283-f5c4-27e7-c29c-64666df1c52b", "node": "client1", "address": "127.0.0.1", "datacenter": "dc1", "taggedaddresses": { "lan": "127.0.0.1", "lan_ipv4": "127.0.0.1", "wan": "127.0.0.1", "wan_ipv4": "127.0.0.1" }, "nodemeta": { "consul-network-segment": "" }, "servicekind": "", "serviceid": "web", "servicename": "web", "servicetags": [ "local" ], "serviceaddress": "", "serviceweights": { "passing": 1, "warning": 1 }, "servicemeta": {}, "serviceport": 80, "serviceenabletagoverride": false, "serviceproxy": { "meshgateway": {}, "expose": {} }, "serviceconnect": {}, "createindex": 15, "modifyindex": 15 } ]
下一篇: Go语言库系列之flag