Regional availability matrix

Содержание:

Пример: комбинирование концепций

Можно распределять нагрузку серверов кэширования, в дополнение к серверам приложений, и использовать репликацию базы данных в едином окружении. Целью объединения этих методов является получение преимуществ каждого подхода без лишней сложности.

Вот примерная диаграмма того, как может выглядеть серверное окружение:

Давайте предположим, что балансировщик нагрузки настроен на распознавание статических запросов (таких как изображения, CSS, JavaScript и т.д.) и отправляет эти запросы к серверам кэширования, а все другие запросы — к серверам приложений.

Вот что будет происходить, когда пользователь отправит запрос на динамический контент:

  1. Пользователь запрашивает динамический контент с http://example.com/ (балансировщик нагрузки).
  2. Балансировщик нагрузки посылает запрос на сервер приложения (app-backend).
  3. Сервер приложения (app-backend) читает из базы и возвращает запрашиваемый контент обратно балансировщику нагрузки.
  4. Балансировщик нагрузки возвращает запрашиваемый контент пользователю.

Если пользователь запрашивает статический контент:

  1. Балансировщик нагрузки проверяет кэш (cache-backend) на предмет того, закэширован ли запрашиваемый контент.
  2. Если закэширован, то запрашиваемый контент возвращается балансирощику нагрузки, переходим в шагу 7. Если не закэширован, то сервер кэширование перенаправит запрос на сервер приложения через балансировщик нагрузки.
  3. Балансировщик нагрузки перенаправит запрос на сервер приложения.
  4. Сервер приложения (app-backend) читает из базы и возвращает запрашиваемый контент обратно балансировщику нагрузки.
  5. Балансировщик нагрузки перенаправляет ответ к серверу кэширования (cache-backend).
  6. Сервер кэширования кэширует полученный контент и возвращает его балансировщику нагрузки.
  7. Балансировщик нагрузки возвращает запрашиваемый контент пользователю.

Данное окружение имеет две возможные точки отказа (балансировщик нагрузки и ведущий сервер базы данных), но обеспечивает другие преимущества в области надежности и производительности, описанные ранее в каждом из пунктов.

Заключение

Теперь, когда вы знакомы с некоторыми основными вариантами настройками сервера, вы должны иметь хорошее представление о том, что именно вы будете использовать для вашего собственного приложения или приложений. Если вы работаете над улучшением своего окружения, помните, что лучше идти итерационным путем во избежание излишнего усложнения.

Installing the Metrics Agent Manually

You can also install the metrics agent manually on . There is an installation script available that automatically detects the client operating system and configures repositories to install the agent. If you are uncomfortable running an installation script, you can set up your repositories manually.

With an Installation Script

An installation script is available to install the metrics agent manually. The script will add a repository to your system and use the native package manager to install the metrics agent. This simplifies package management tasks like upgrading or removing the metrics agent.

Log in to your Droplet as or as a user with access:

Once connected, to install and enable the metrics agent immediately, you can download and execute the installation script by typing:

You may be prompted for your password if running as a user.

Note

If you would like to audit the script before installing, you can write it to disk first, then view the contents and run it manually.

The agent should now be installed and .

Configuring Repositories Manually

You can also add the repositories and install the package manually if you prefer.

Ubuntu and Debian

To add the metrics agent repository, create and open a file in the directory with privileges:

Inside, add the following line:

Save and close the file.

Next, add the DigitalOcean key to by typing:

Now you can update the repository package index and install the Agent by typing:

The agent should now be installed and .

CentOS and Fedora

On CentOS or Fedora, create and open a repository definition file with privileges:

Inside, paste the following configuration:

Import the DigitalOcean key by typing:

Now, you can install the metrics agent by typing:

The agent should now be installed and .

Verify the Agent is Running

No matter how you install the agent or which operating system you use, you can verify it is running from the command line with:

When you receive output with a line something like the one below, then the agent is running:

Once the agent is running, enhanced graphs should be available in the control panel.

Registrar: A Small Orange

This section of the guide was last updated on October 27, 2014

1. Sign in to your A Small Orange account and select My Domains.

2. Find the domain name that you want to use with your Droplet, then select Manage Domain to the right of that domain name.

3. By default, A Small Orange locks your domain to prevent it from being transferred away without your authorization. This means that before we can change the nameservers, we’ll need to disable this lock. Select the Registrar Lock tab, then select Disable Registrar Lock.

4. Select the Nameservers tab.

5. Enter the following nameservers:

  • ns1.digitalocean.com
  • ns2.digitalocean.com
  • ns3.digitalocean.com

6. Select Change Nameservers to apply your changes. Now you are ready to move on to connecting the domain with your Droplet in the DigitalOcean control panel. Check out the Conclusion section at the end of this article to read on what to do next.

Product Availability by Datacenter Region

Each product’s availability is listed on its overview page. This table summarizes the availability for our major products using the following key:

  • ◆ Full availability. All users can create this resource in this datacenter.


  • Hover for more information. Limited availability. There may be limited capacity in this datacenter, or the product may be in an earlier phase of the product lifecycle.


  • Hover for more information. Future availablity. We intend to offer the product in this datacenter in the future. For example, we can expand availability when a product enters . We’ll provide more information as we have it in the tooltips and in our release notes.

You can learn more about product availability from our product release lifecycle stages.

Droplet Plan Availability

Droplet Plan NYC1 NYC2 NYC3 AMS2 AMS3 SFO1 SFO2 SFO3 SGP1 LON1 FRA1 TOR1 BLR1
Basic
Limited capacity. Restricted to users with existing resources only.

Limited capacity. Restricted to users with existing resources only.

Limited capacity. Restricted to users with existing resources only.
General Purpose Performance
CPU-Optimized Performance
The largest plan isn’t available in this region.
Memory Optimized Performance

Managed Databases Availability

Database Engine NYC1 NYC2 NYC3 AMS2 AMS3 SFO1 SFO2 SFO3 SGP1 LON1 FRA1 TOR1 BLR1
PostgreSQL
MySQL
Redis

Other Product Availability

Product NYC1 NYC2 NYC3 AMS2 AMS3 SFO1 SFO2 SFO3 SGP1 LON1 FRA1 TOR1 BLR1
Kubernetes
Volumes
Some legacy hardware. Attach volumes during Droplet creation to ensure compatibility.
Spaces
Creation disabled until capacity expansion in late 2020.
Load Balancers

Connect to DigitalOcean

To connect to DigitalOcean from Cyberduck, click the Open Connection icon, then select Amazon S3.

When you select Amazon S3, a new window opens:

For the Server field, use a combination of the region, e.g. , and , so that the complete address looks like . Then enter your access key and secret key for the Access Key ID and Password fields respectively. Once the values are filled in, select Connect.

You can check the Save password box to avoid being prompted for the Secret Key each time you connect. This can be appropriate on a personal computer, but on a shared machine, it would allow anyone to connect with administrative powers.

Registrar: eNom

This section of the guide was last updated on February 16, 2018

1. Sign in to your eNom account.

2. Under Domains, select Registered Domains. If you have multiple domains registered with eNom, select the domain name that you want to use with your Droplet.

3. Select DNS Server Settings.

4. Under User our Name Servers?, select Custom.

5. Enter the following nameservers:

  • ns1.digitalocean.com
  • ns2.digitalocean.com
  • ns3.digitalocean.com

6. Select save, then confirm your changes in the popup by selecting OK. Now you are ready to move on to connecting the domain with your Droplet in the DigitalOcean control panel. Check out the Conclusion section at the end of this article to read about what to do next.

Step 3 — Generate Certificates and Keys for Clients

So far we’ve installed and configured the OpenVPN server, created a Certificate Authority, and created the server’s own certificate and key. In this step, we use the server’s CA to generate certificates and keys for each client device which will be connecting to the VPN. These files will later be installed onto the client devices such as a laptop or smartphone.

Key and Certificate Building

It’s ideal for each client connecting to the VPN to have its own unique certificate and key. This is preferable to generating one general certificate and key to use among all client devices.

To create separate authentication credentials for each device you intend to connect to the VPN, you should complete this step for each device, but change the name client1 below to something different such as client2 or iphone2. With separate credentials per device, they can later be deactivated at the server individually, if need be. The remaining examples in this tutorial will use client1 as our example client device’s name.

As we did with the server’s key, now we build one for our client1 example. You should still be working out of .

Once again, you’ll be asked to change or confirm the Distinguished Name variables and these two prompts which should be left blank. Press to accept the defaults.

As before, these two confirmations at the end of the build process require a () response:

If the key build was successful, the output will again be:

The example client configuration file should be copied to the Easy-RSA key directory too. We’ll use it as a template which will be downloaded to client devices for editing. In the copy process, we are changing the name of the example file from to because the file extension is what the clients will expect to use.

You can repeat this section again for each client, replacing client1 with the appropriate client name throughout.

Transferring Certificates and Keys to Client Devices

Recall from the steps above that we created the client certificates and keys, and that they are stored on the OpenVPN server in the directory.

For each client we need to transfer the client certificate, key, and profile template files to a folder on our local computer or another client device.

In this example, our client1 device requires its certificate and key, located on the server in:

The and files are the same for all clients. Download these two files as well; note that the file is in a different directory than the others.

While the exact applications used to accomplish this transfer will depend on your choice and device’s operating system, you want the application to use SFTP (SSH file transfer protocol) or SCP (Secure Copy) on the backend. This will transport your client’s VPN authentication files over an encrypted connection.

Here is an example SCP command using our client1 example. It places the file into the Downloads directory on the local computer.

Here are several tools and tutorials for securely transfering files from the server to a local computer:

  • WinSCP
  • How To Use SFTP to Securely Transfer Files with a Remote Server
  • How To Use Filezilla to Transfer and Manage Files Securely on your VPS

At the end of this section, make sure you have these four files on your client device:

Working with Firewalls

The command lets you create and manage Firewalls, including creating and maintaining rules. For more about information about administering Firewalls using , check out the How To Secure Web Server Infrastructure With DigitalOcean Cloud Firewalls Using Doctl tutorial.

command Notes
List all Firewalls.
List all Firewalls by Droplet’s numeric ID.
Create a Firewall. The name and at least an inbound or outbound rule are mandatory.
Update a Firewall. The numeric ID, name and at least an inbound or outbound rule are mandatory.
Get a Firewall by its numeric ID.
Delete a Firewall by numeric ID.
Add Droplets by their numeric ID to the Firewall.
Remove Droplets from the Firewall by their numeric IDs.
Add Tags to the Firewall.
Remove Tags from the Firewall.
Add inbound or outbound rules to the Firewall.
Remove inbound or outbound rules to the Firewall.

When used as an argument to , inbound or outbound rules should be expressed like: .

Regional Availability

Spaces are available in NYC3, SFO2, AMS3, SGP1, and FRA1. Spaces work with Droplets in all regions. The Spaces CDN is available in all regions where Spaces are available.

Note

We have temporarily disabled the creation of new Spaces in FRA1 until we expand the capacity in that region. Learn more about Spaces availability in FRA1.

The Spaces CDN points of presence are in the following locations:

Region PoP Locations
North America Ashburn, Atlanta, Chicago, Dallas, Denver, Los Angeles, Miami, New York, San Jose, Seattle, Toronto
Europe Amsterdam, Frankfurt, London, Madrid, Milan, Paris, Stockholm, Warsaw
South America São Paulo (beta)
Asia Hong Kong (beta), Manila (beta), Seoul (beta), Singapore (beta), Tokyo (beta)
Oceania Melbourne (beta), Sydney (beta)

Generic doctl Usage

Invoking Commands

In , individual features are invoked by giving the utility a command, one or more sub-commands, and sometimes one or more options specifying particular values. Commands are grouped under three main categories:

  • for account-related information
  • for authenticating with DigitalOcean
  • for managing infrastructure

To see an overview of all commands, you can invoke by itself. To see all available commands under one of the three main categories, you can use , like . For a usage guide on a specific command, enter the command with the flag, as in .

Retrieving Data in JSON Format

In scripting environments, or when working on the command line with data-processing tools, it’s often helpful to get machine-readable output from a command.

By default, formats its output in columns of human-readable text, but can produce detailed JSON output using the option.

In addition to being a format readable with standard libraries in most programming languages, the JSON output may allow more fine-grained inspection of Droplets and other resources.

Formatting

It’s often useful to obtain only a set of fields from output. To do this, you can use the flag followed by a list of your desired fields. For example, if you want to obtain only the ID, name, and IP address of your Droplets, you can use the following command:

Templates

The command supports output templating, which lets you customize the format of the output. To use this feature, specify the Go-formatted template via the flag.

For example, if you want to get a Droplet’s name in the format , you would use the following command:

Getting Help

DigitalOcean maintains several ways to get help, each with its own focus.

Website Content
Product Docs (You are here) Information on DigitalOcean product features, pricing, availability, and limits; how to use products from the control panel; how to manage your account, teams, and billing; and platform details like release notes and product policies.
API Docs Use DigitalOcean programmatically to manage resources.
Product Ideas Suggest new product ideas and vote on existing suggestions.
Community Tutorials How to build on top of DigitalOcean resources, administer servers, write and deploy code, and install and configure open source tools.
Community Q&A Ask and answer questions about software development, system administration, and other technical topics.
Status Page Check the current status of DigitalOcean services.
Contact Support Get help with your account or services.
Contact Sales Contact sales for help with large deployments.
Report Abuse Report abuse or suspicious activity.

Finalize and create

In the Finalize and create section, you specify the quantity, name, tags, and project for the Droplet you’re creating.

There are four subsections for these options:

  • How many Droplets?, where you choose the quantity of Droplets you’re creating with the specified configuration. Adjust the number by clicking the plus, +, or minus, -, buttons.

  • Choose a hostname, where you give each Droplet a name which is used in the control panel and as the server’s hostname. Default names are provided based on the options you selected, but you can modify them to suit your needs.

    Note

    Using an FQDN (fully qualified domain name) (e.g. ) as the Droplet’s name automatically generates for your Droplet based on that name. This also applies if you rename a Droplet after creation.

  • Add tags, where you can add tags to organize and relate Droplets.

  • Select Project, where you can assign the Droplet to a project.

Once you have selected your options, click Create. A progress bar displays how close your Droplet is to being ready.

Once the Droplet is fully set up, the control panel displays its IP address.

Once you see the IP address, you can log in to your Droplet.

To go to a Droplet’s detail page where you can make changes, click its name or go straight to the task you want using the More menu. You can also get a quick view of the Droplet’s details by clicking the icon by the Droplet’s name.

Шаг 6 — Добавление необходимого модуля ядра

Создайте новый файл и добавьте туда следующие строчки, заменяя имя и пароль Вашими значениями:

Здесь — публичный IP-адрес нашего PPTP-сервера, и — это пара логин/пароль, которые мы задали в файле на нашем PPTP-сервере.

Теперь мы можем “вызывать” этот PPTP-сервер. В следующей команде необходимо использовать имя, которое Вы дали файлу с пирами (peers) в директории . Поскольку в нашем примере мы назвали этот файл , наша команда выглядит следующим образом:

Вы должны увидеть успешное подключение в логах PPTP-сервера:

На Вашем PPTP-клиенте настройте маршрутизацию на Вашу приватную сеть через интерфейс ppp0:

Ваш интерфейс ppp0 должен быть настроен, что можно проверить путем запуска

Теперь Вы можете сделать пинг к Вашему PPTP-серверу и любым другим клиентам, подключенным к этой сети:

Мы можем добавить второй PPTP-клиент к этой сети:

Добавьте необходимые строки в файл (заменяя логины и пароли своими):

Теперь на втором клиенте выполните следующие команды:

Вы можете сделать пинг к первому клиенту, при этом пакеты будут идти через PPTP-сервер и перенаправляться по правилам ip-таблиц, которые мы задали ранее:

Такая настройка позволит Вам создать Вашу собственную виртуальную частную сеть:

Если Вы хотите, чтобы все ваши устройства общались безопасно в рамках одной сети, это наиболее быстрый способ сделать это.

Вы можете использовать такой подход совместно с Nginx, Squid, MySQL и любыми другими приложениями.

Поскольку трафик внутри сети шифруется 128-битным шифрованием, PPTP меньше нагружает процессор, чем OpenVPN, но все же обеспечивает дополнительный уровень безопасности Вашего трафика.

Features

A Virtual Private Cloud (VPC) is a private network interface for collections of DigitalOcean resources. VPC networks are private networks that contain collections of resources that are isolated from the public internet and other VPC networks within your account, project or between teams in the same datacenter region. This means your resources, such as Droplets and databases, can reside in a network that is only accessible to other resources in the same network.

You can use VPC networks to organize and isolate resources into a more secure infrastructure for your applications, execution environments, and tenancies. VPC networks also give you more control over your infrastructure’s networking environment: you can select your network’s IP range, set up cloud firewalls, and configure internet gateways.

You can create a variety of new resources in a VPC network, but you can’t migrate all kinds of resources between networks. The following table lists Digitalocean resources compatible with VPC networks and which ones support migration:

Resource Type Create within VPCs Migrate between VPCs
Droplets Creation supported. .
Managed databases Creation supported. .
Kubernetes clusters Creation supported. Not supported.
Load balancers Creation supported. Not supported.
Spaces Not applicable. Not applicable.
Volumes Not applicable. Not applicable.

Репликация базы данных по схеме ведущий-ведомый (Master-Slave)

Одним из способов улучшения производительности системы базы данных, к которой запросов на чтение происходит гораздо больше, чем на запись, как, например, в системах управления контентом (CMS), является использование репликации базы данных по схеме ведущий-ведомый. Такая схема предполагает наличие одного ведущего и одного и более ведомых узлов. В таком случае, все записи направляются на ведущий узел, а запросы на чтение могут быть распределены между всеми узлами.

Пример использования: Дает хорошее увеличение производительности приложения в части чтения из базы данных.

Вот пример репликации базы данных по схеме ведущий-ведомый с одним ведомым узлом:

Плюсы:

  • Улучшает производительность чтения из базы данных путем распределения запросов на чтение между ведомыми узлами.
  • Может улучшить производительность записи путем использования ведущего узла исключительно для записи (таким образом он не тратит время на обслуживание запросов на чтение)

Минусы:

  • Приложение, работающее с базой данных, должно иметь механизм определения узлов, на которые необходимо отправлять запросы на чтение и запись.
  • Обновления ведомых узлов асинхронны, поэтому есть вероятность получить не самые свежие данные при запросе.
  • Если ведущий узел перестает работать, нельзя делать какие-либо обновления базы, пока проблема не будет устранена.
  • Не имеет встроенных резервных средств на случай выхода из строя главного узла.

Дополнительные руководства:

  • Как оптимизировать производительность WordPress путем репликации MySQL на Ubuntu 14.04
  • Как настроить репликацию MySQL по схеме ведущий-ведомый
Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *