Docker 集群环境准备

确保主机已安装 Docker 和 Docker Compose。验证版本兼容性,推荐 Docker 20.10+ 和 Compose v2.4+。各节点需开放以下端口:6667(客户端通信)、9003(集群内部RPC)、40010(数据同步)。

创建共享网络以便容器间通信:

docker network create iotdb-net

集群配置文件生成

通过 IoTDB 官方工具生成集群配置模板:

wget https://downloads.apache.org/iotdb/1.0.0/apache-iotdb-1.0.0-cluster-all-bin.zip
unzip apache-iotdb-1.0.0-cluster-all-bin.zip
cd apache-iotdb-1.0.0-cluster-all-bin/tools
./cluster-conf-generator.sh -n 3 -c

修改生成的iotdb-cluster.properties:

cluster_name=iotdb-cluster
internal_ip=容器名称或IP
target_config_node=主配置节点地址
seed_config_nodes=cfg1:10710,cfg2:10710,cfg3:10710

容器化部署实现

编写docker-compose.yml示例:

version: '3.8'
services:
  cfg1:
    image: apache/iotdb:1.0.0-cluster
    volumes:
      - ./conf1:/iotdb/conf
    ports:
      - "9003:9003"
    networks:
      - iotdb-net

  data1:
    image: apache/iotdb:1.0.0-cluster
    environment:
      - IOTDB_ROLE=DataNode
    depends_on:
      - cfg1
    networks:
      - iotdb-net

节点通信验证

进入任意容器执行集群状态检查:

docker exec -it cfg1 bash
/iotdb/sbin/start-cli.sh -h cfg1
show cluster

关键指标验证:

  • 使用telnet测试端口连通性
  • 检查日志/iotdb/logs无Connection refused错误
  • 通过jps命令确认ConfigNode和DataNode进程存在

负载均衡配置

在 Nginx 中添加反向代理规则:

stream {
    upstream iotdb_nodes {
        server data1:6667 weight=5;
        server data2:6667 weight=3;
    }
    server {
        listen 6667;
        proxy_pass iotdb_nodes;
    }
}

安全策略加固

修改iotdb-common.properties启用TLS:

enable_ssl=true
key_store_path=/iotdb/conf/ssl/server.keystore
trust_store_path=/iotdb/conf/ssl/server.truststore

生成SSL证书并挂载到容器:

keytool -genkeypair -alias iotdb -keyalg RSA -validity 365 -keystore server.keystore

更多推荐