[Date Prev][Date Next]
Re: openldap, proxy, round robin?
- To: Nathan Lager <email@example.com>
- Subject: Re: openldap, proxy, round robin?
- From: "Brett @Google" <firstname.lastname@example.org>
- Date: Thu, 14 May 2009 12:13:08 +1000
- Cc: email@example.com
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:cc:content-type; bh=gg1TKNR+MFoCzEiJPaR8nXu5ioZoWiKVAAOWBFHpPDo=; b=Nt3DSo/YOwGNCLwkwAPgUQBiOnVLmsD/gRd9y81F8NRgFEns8AopDlKstWf8Ruhw0m ys+b8ckbUOAX8Dvkh6p2+EMY09fKKNjMFjRIZF3wEpcjsgR75RF+DTmhleOsWC3CZcAV YmJ74pI6STwZRG0UqQuO1CfzVd+8cXeR4J6OY=
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=nyhnN55yRAt2vndtb/tV8VYAaN57tiidWk7fb/jRcBGUQYkqoeGyUzQcPsvUPjxhw2 IGsDbMhEoUtV0ej5rPFL5JaY8kHAYQ5p3NPN1zPtKAdgyNxdNVJkkeH5gpNrZQUmvCX3 D/B8iRaFUSZRet3G1ef4FFFUTwfeMqWj70JjM=
- In-reply-to: <4A0B2E6B.firstname.lastname@example.org>
- References: <4A0B2E6B.email@example.com>
You could force a short ldap timeout on the server, so the server will drop the connection after a certain amount of inactivity.
AFAIK from the client's perspective LDAP connection stays open once established, until the TCP/IP connection is lost. This can mean the server dropping the connection due to inactivity, which is a poor man's round robin.
Even if you had a hardware content switch, you can only round robin "new" connections, you wouldn't want to forcefully / randomly terminate (non-timed out) established connections for data safety, as thie client might be in the middle of doing some critical ldap transaction which takes several operations to complete etc.,
Importantly though, the ldap client application(s) should be written with clustering in mind:
a. app should make a connection, do some stuff, then disconnect. There cannot be long duration connection caching if you want to make sure the load is spread evenly over your ldap cluster.
b. app should retry idempotent operations at least once, to cover the case it tries to use a "stale" connection which has just been terminated due to inactivity.
On Thu, May 14, 2009 at 6:32 AM, Nathan Lager <firstname.lastname@example.org>
-----BEGIN PGP SIGNED MESSAGE-----
I am attempting to setup an openldap proxy, which i'd like to connect to
a number of openldap directories in a round-robin fashion.
There are currently 2 ldap servers, with a round-robin DNS hostname
pointing to them.
I setup openldap to proxy to this hostname, but it seems that when i
actually connect to the proxy, it picks one of the addresses, and holds
on to it. If it gets the second server on its first connection, it then
continues to use that server.
Is there a way to make openldap connect to each server? Whether it uses
the round robin hostname or not is irrelevant. Two methods I can think
of would be to somehow keep slapd from caching the dns name. Or if I can
specify each server separately in the slapd.conf on the proxy.