You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请校验WSO2 APim主主(Active-Active)部署YAML脚本(MicroK8s环境)

WSO2 APIM 主主(Active-Active)架构部署校验与优化建议

一、原脚本的问题分析

你提供的Deployment.yaml仅实现了2个独立的WSO2 APIM实例部署,完全无法满足主主(Active-Active)架构的核心要求,具体问题如下:

  1. 无共享状态管理:WSO2 APIM默认使用本地嵌入式H2数据库,两个实例各自维护独立的API定义、订阅数据、用户会话,无法实现数据同步,本质还是两个孤立的单节点。
  2. 无分布式会话支持:用户会话默认存储在本地内存,跨实例访问会导致会话丢失,无法实现无缝的请求切换。
  3. 无统一流量入口:未配置Kubernetes Service或Ingress,外部无法通过负载均衡方式访问两个实例,无法实现请求分发。
  4. 无统一配置管理:所有实例使用镜像默认配置,无法同步API策略、租户设置等核心配置,无法保证实例行为一致。

二、优化后的部署方案建议

1. 配置共享数据库

主主架构必须依赖共享关系型数据库(如MySQL、PostgreSQL)替换默认H2,确保所有实例使用同一数据源:

  • 先部署数据库实例(可使用StatefulSet或外部托管数据库)
  • 在Deployment中通过环境变量或挂载配置文件指定数据库连接:
    env:
      - name: DB_USERNAME
        value: "wso2carbon"
      - name: DB_PASSWORD
        valueFrom:
          secretKeyRef:
            name: db-secrets
            key: password
      - name: DB_URL
        value: "jdbc:mysql://mysql-service:3306/wso2_apim_db?useSSL=false"
    

2. 实现分布式会话与共享注册表

使用Redis或JDBC存储实现分布式会话,配置共享注册表保证配置同步:

env:
  - name: SESSION_STORAGE_TYPE
    value: "redis"
  - name: REDIS_HOST
    value: "redis-service"
  - name: REDIS_PORT
    value: "6379"
  - name: REGISTRY_TYPE
    value: "jdbc"

3. 挂载自定义配置文件

通过ConfigMap挂载统一的deployment.toml配置文件,确保所有实例配置一致:

volumes:
  - name: apim-config
    configMap:
      name: wso2-apim-config
containers:
  - name: wso2-apim
    image: wso2/wso2am:3.2.0
    volumeMounts:
      - name: apim-config
        mountPath: /home/wso2carbon/wso2am-3.2.0/repository/conf/deployment.toml
        subPath: deployment.toml

4. 配置Service与Ingress实现负载均衡

先创建ClusterIP Service暴露实例:

apiVersion: v1
kind: Service
metadata:
  name: wso2-apim-service
spec:
  selector:
    app: wso2-apim
  ports:
    - name: https
      port: 9443
      targetPort: 9443
  type: ClusterIP

再配置Ingress实现外部访问(MicroK8s需先执行microk8s enable ingress启用插件):

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: wso2-apim-ingress
  annotations:
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
  tls:
    - hosts:
        - apim.your-domain.com
      secretName: apim-tls-secret
  rules:
    - host: apim.your-domain.com
      http:
        paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: wso2-apim-service
                port:
                  number: 9443

5. 优化Deployment基础配置

  • 添加资源限制,避免节点资源耗尽:
    resources:
      requests:
        memory: "2Gi"
        cpu: "1"
      limits:
        memory: "4Gi"
        cpu: "2"
    
  • 添加健康探针,确保实例可用性:
    livenessProbe:
      httpGet:
        path: /healthcheck
        port: 9443
        scheme: HTTPS
      initialDelaySeconds: 180
      periodSeconds: 30
    readinessProbe:
      httpGet:
        path: /healthcheck
        port: 9443
        scheme: HTTPS
      initialDelaySeconds: 60
      periodSeconds: 10
    
  • 使用Secret存储数据库密码、SSL证书等敏感信息,禁止明文配置。

6. 优先使用官方Helm Chart

WSO2提供了针对Kubernetes优化的官方Helm Chart,内置主主架构所需的数据库、会话同步、负载均衡等配置,可直接部署:

helm repo add wso2 https://wso2.github.io/helm-charts/
helm install wso2-apim wso2/wso2am --version 3.2.0

内容的提问来源于stack exchange,提问作者Sonny Real Jr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 21:57:42