{"id":10993,"date":"2022-10-12T14:02:32","date_gmt":"2022-10-12T21:02:32","guid":{"rendered":"https:\/\/www.xh86.me\/?p=10993"},"modified":"2022-10-12T14:02:32","modified_gmt":"2022-10-12T21:02:32","slug":"%e5%9c%a8-dn42-%e4%b8%ad%e4%bd%bf%e7%94%a8-docker-%e5%bb%ba%e7%ab%8b-anycast-dns-%e6%9c%8d%e5%8a%a1","status":"publish","type":"post","link":"https:\/\/www.xh86.me\/?p=10993","title":{"rendered":"\u5728 DN42 \u4e2d\u4f7f\u7528 Docker \u5efa\u7acb Anycast DNS \u670d\u52a1"},"content":{"rendered":"<h2 id=\"\u4ec0\u4e48\u662f-anycast\">\u4ec0\u4e48\u662f Anycast<\/h2>\n<p>\u4e92\u8054\u7f51\u4e0a\u5e38\u7528\u7684\u8def\u7531\u534f\u8bae BGP \u662f\u8fd9\u6837\u5de5\u4f5c\u7684\uff1a<\/p>\n<ul>\n<li>\u6211\u5728 DN42 \u62e5\u6709 IP \u6bb5 172.22.76.104\/29\u3002<\/li>\n<li>\u6211\u901a\u8fc7 BIRD \u7b49 BGP \u8f6f\u4ef6\uff0c\u300c\u5ba3\u544a\u300d\u8fd9\u53f0\u670d\u52a1\u5668\u4e0a\u53ef\u4ee5\u8bbf\u95ee\u5230 172.22.76.104\/29 \u8fd9\u4e2a IP \u6bb5\u3002<\/li>\n<li>\u4e0e\u6211\u6709 Peering \u7684\u5176\u5b83\u670d\u52a1\u5668\u8bb0\u5f55\u4e0b\u8fd9\u4e00\u6761\u6d88\u606f\uff1a\u300c\u901a\u8fc7\u67d0\u6761\u8def\u5f84\uff0c\u8d70 1 \u683c\u53ef\u4ee5\u8bbf\u95ee\u5230 172.22.76.104\/29\u3002\u300d<\/li>\n<li>\u5176\u5b83\u670d\u52a1\u5668\u5411\u4e0e\u5b83\u4eec\u6709 Peering \u7684\u670d\u52a1\u5668\u7ee7\u7eed\u5ba3\u544a\uff1a\u300c\u8fd9\u53f0\u670d\u52a1\u5668\u8ddd\u79bb 172.22.76.104\/29 \u53ea\u6709 1 \u683c\u8ddd\u79bb\u3002\u300d<\/li>\n<li>\u4ee5\u6b64\u7c7b\u63a8\uff0c\u5176\u4f59\u670d\u52a1\u5668\u4e5f\u901a\u8fc7\u7c7b\u4f3c\u7684\u6d41\u7a0b\uff0c\u5ba3\u5e03\u81ea\u5df1\u4e0e 172.22.76.104\/29 \u6709 2 \u683c\uff0c3 \u683c\uff0c4 \u683c\u8ddd\u79bb\u2026\u2026<\/li>\n<li>\u6240\u6709\u670d\u52a1\u5668\u4e5f\u90fd\u901a\u8fc7\u8ddd\u79bb\u6700\u77ed\u7684\u8def\u5f84\uff0c\u5c06\u6570\u636e\u53d1\u9001\u5230\u6211\u7684\u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n<p>\u5728\u8fd9\u79cd\u60c5\u51b5\u4e2d\uff0c\u53ea\u6709\u4e00\u53f0\u670d\u52a1\u5668\u5ba3\u5e03\u81ea\u5df1\u662f 172.22.76.104\/29 \u7684\u300c\u6e90\u5934\u300d\u3002\u8fd9\u5c31\u662f\u5355\u64ad\uff08Unicast\uff09\u3002\u800c\u4efb\u64ad\uff0c\u5373 Anycast\uff0c\u5c31\u662f\u6211\u5728\u591a\u53f0\u670d\u52a1\u5668\uff08\u5b9e\u9645\u4e2d\u5f80\u5f80\u5728\u4e0d\u540c\u5730\u7406\u4f4d\u7f6e\uff0c\u6bd4\u5982\u4e2d\u56fd\u9999\u6e2f\u3001\u7f8e\u56fd\u6d1b\u6749\u77f6\u3001\u6cd5\u56fd\u5df4\u9ece\u7b49\uff09\u4e0a\u90fd\u5ba3\u544a\u81ea\u5df1\u6709 172.22.76.104\/29\uff0c\u5176\u4f59\u670d\u52a1\u5668\u4ecd\u7136\u6570\u683c\u5b50\u5c06\u6570\u636e\u53d1\u9001\u5230\u6700\u8fd1\u7684\u670d\u52a1\u5668\u3002\u8fd9\u6837\uff0c\u4e2d\u56fd\u5927\u9646\u7684\u7528\u6237\u66f4\u53ef\u80fd\u5c06\u6570\u636e\u53d1\u9001\u5230\u4e2d\u56fd\u9999\u6e2f\u7684\u670d\u52a1\u5668\uff0c\u56e0\u4e3a\u4e00\u822c\u800c\u8a00\u4ece\u4e2d\u56fd\u5927\u9646\u5230\u9999\u6e2f\u7684\u300c\u683c\u5b50\u300d\u8981\u6bd4\u5230\u5176\u5b83\u5730\u533a\u5c11\u5f88\u591a\uff1b\u540c\u7406\uff0c\u5fb7\u56fd\u7684\u7528\u6237\u4f1a\u8bf7\u6c42\u6cd5\u56fd\u5df4\u9ece\u670d\u52a1\u5668\uff0c\u7f8e\u56fd\u829d\u52a0\u54e5\u7684\u7528\u6237\u4f1a\u8bf7\u6c42\u6d1b\u6749\u77f6\u7684\u670d\u52a1\u5668\u3002<\/p>\n<p>\uff08\u6ce8\uff1a\u4ee5\u4e0a\u8bf4\u660e\u76f8\u5bf9\u771f\u5b9e\u60c5\u51b5\u505a\u4e86\u7b80\u5316\uff1b\u771f\u5b9e\u60c5\u51b5\u4e0b BGP \u7684\u9009\u62e9\u8def\u5f84\u6d41\u7a0b\u66f4\u52a0\u590d\u6742\u3002\uff09<\/p>\n<p>\u5728\u4ee5\u4e0a\u914d\u7f6e\u4e2d\uff0c\u6240\u6709\u670d\u52a1\u5668\u90fd\u5171\u4eab\u4e86\u540c\u4e00\u4e2a\u7f51\u6bb5\uff0c\u6700\u7ec8\u4e92\u8054\u7f51\u7528\u6237\u53ea\u8981\u8bbf\u95ee\u8fd9\u4e2a\u7f51\u6bb5\u4e2d\u7684 IP \u5730\u5740\uff0c\u5c31\u4f1a\u88ab\u81ea\u52a8\u5bfc\u5230\u8f83\u8fd1\u7684\u670d\u52a1\u5668\u4e0a\uff0c\u65e0\u9700\u5ba2\u6237\u7aef\u8f6f\u4ef6\u7684\u652f\u6301\u3002<\/p>\n<p>\u4e0d\u8fc7\uff0cAnycast \u4e5f\u6709\u5b83\u7684\u5c40\u9650\u6027\uff1a\u6bcf\u53f0\u670d\u52a1\u5668\u4ecd\u7136\u662f\u72ec\u7acb\u7684\u670d\u52a1\u5668\uff0c\u5b83\u4eec\u4e4b\u95f4\u7684\u7f51\u7edc\u8fde\u63a5\u72b6\u6001\u5f80\u5f80\u662f\u4e0d\u5171\u4eab\u7684\u3002\u800c\u4e92\u8054\u7f51\u4e0a\u7684\u8def\u7531\u5343\u53d8\u4e07\u5316\uff0c\u6bcf\u4e2a\u7528\u6237\u90fd\u6709\u53ef\u80fd\u5728\u4e0b\u4e00\u523b\u88ab\u5206\u914d\u5230\u53e6\u4e00\u53f0\u670d\u52a1\u5668\uff0c\u800c\u8fd9\u4e00\u5207\u90fd\u5728\u7f51\u7edc\u5c42\uff08L3\uff09\u5b8c\u6210\uff0c\u5e94\u7528\u5c42\uff08L7\uff09\u7684\u8f6f\u4ef6\u5e76\u4e0d\u77e5\u60c5\u3002\u8fd9\u5c31\u610f\u5473\u7740\u57fa\u4e8e\u6709\u72b6\u6001\u534f\u8bae\u7684\u670d\u52a1\uff08\u4f8b\u5982 TCP\uff09\u8f83\u96be\u7a33\u5b9a\u5de5\u4f5c\u3002\u56e0\u6b64\uff0c\u73b0\u5728 Anycast \u6700\u5e38\u7528\u5728 DNS \u7b49\u65e0\u72b6\u6001\u534f\u8bae\u670d\u52a1\u4e0a\u3002<\/p>\n<h2 id=\"\u6211\u8981\u5b9e\u73b0\u4ec0\u4e48\u529f\u80fd\">\u6211\u8981\u5b9e\u73b0\u4ec0\u4e48\u529f\u80fd<\/h2>\n<ol>\n<li>\u7edf\u4e00\u67d0\u4e2a\u670d\u52a1\u7684 IP \u5730\u5740\uff0c\u65b9\u4fbf\u5176\u5b83\u7a0b\u5e8f\u914d\u7f6e\uff1a\u4f8b\u5982\u6211\u5c06 DNS IP \u56fa\u5b9a\u4e3a 172.18.53.53\uff0c\u5e76\u5728\u5404\u4e2a VPS \u4e0a\u914d\u7f6e Anycast\uff0c\u8ba9\u5230\u8fd9\u4e2a IP \u7684\u8bf7\u6c42\u53d1\u5230\u6700\u8fd1\u7684 VPS\u3002\u4e4b\u540e\u6211\u914d\u7f6e\u9700\u8981 DNS \u7684\u670d\u52a1\u65f6\uff0c\u5c31\u53ef\u4ee5\u76f4\u63a5\u5c06 IP \u56fa\u5b9a\u4e3a 172.18.53.53\uff0c\u5e76\u5c06\u914d\u7f6e\u6587\u4ef6\u76f4\u63a5\u590d\u5236\u7c98\u8d34\u5230\u5176\u5b83 VPS \u4e0a\u6279\u91cf\u90e8\u7f72\u3002<\/li>\n<li>\u6545\u969c\u8f6c\u79fb\uff1a\u6709\u7684\u65f6\u5019\u6211\u7684 VPS \u4e0a\u7684\u670d\u52a1\uff0c\u8fd8\u662f\u4f8b\u5982 DNS\uff0c\u4f1a\u56e0\u4e3a\u6211\u914d\u7f6e\u6539\u9519\u4e86 \/ VPS \u6bcd\u9e21\u7206\u70b8\u7b49\u539f\u56e0\u505c\u6b62\u8fd0\u884c\u3002\u6b64\u65f6\u8fd9\u53f0 VPS \u4e0a\u7684 DNS \u505c\u6b62\u8fd0\u884c\uff0cVPS \u505c\u6b62\u5ba3\u5e03\u81ea\u5df1\u53ef\u4ee5\u76f4\u63a5\u8bbf\u95ee\u5230 DNS \u8fd9\u4e2a IP\uff0c\u5230 DNS \u7684\u8bf7\u6c42\u4f1a\u81ea\u52a8\u53d1\u5230\u5176\u5b83\u7684 VPS\u3002\u8fd8\u6d3b\u7740\u7684\u670d\u52a1\u5c31\u4e0d\u4f1a\u8ddf\u7740 DNS \u4e00\u8d77\u6302\u6389\u3002<\/li>\n<li>\u964d\u4f4e\u5ef6\u8fdf\uff1a\u5728 DN42 \u4e2d\uff0c\u6b27\u6d32\u7528\u6237\u53ef\u4ee5\u8bbf\u95ee\u6211\u7684\u6cd5\u56fd VPS\uff0c\u7f8e\u56fd\u7528\u6237\u53ef\u4ee5\u8bbf\u95ee\u6d1b\u6749\u77f6 VPS\uff0c\u4e9a\u6d32\u7528\u6237\u8bbf\u95ee\u9999\u6e2f VPS\uff0c\u5c06\u5ef6\u8fdf\u6700\u5c0f\u5316\uff0c\u63d0\u9ad8\u670d\u52a1\u7684\u7a33\u5b9a\u6027\u3002<\/li>\n<\/ol>\n<p>\u4e00\u4e9b\u989d\u5916\u7684\u8981\u6c42\uff1a\u670d\u52a1\u90e8\u7f72\u5fc5\u987b\u4f7f\u7528 Docker\u3002<\/p>\n<h2 id=\"\u73b0\u6709\u65b9\u6848\u7684\u95ee\u9898\u53ca\u6211\u7684\u65b9\u6cd5\">\u73b0\u6709\u65b9\u6848\u7684\u95ee\u9898\uff0c\u53ca\u6211\u7684\u65b9\u6cd5<\/h2>\n<p>\u7f51\u7edc\u4e0a\u5e38\u89c1\u51e0\u79cd\u65b9\u6848\uff0c\u90fd\u5b58\u5728\u4e00\u4e9b\u95ee\u9898\uff1a<\/p>\n<ol>\n<li>\u5728\u7cfb\u7edf\u5185\u76f4\u63a5\u6dfb\u52a0 IP\uff0c\u76f4\u63a5\u8fdb\u884c BGP \u5ba3\u544a\u3002\u6b64\u65f6\u5982\u679c DNS \u670d\u52a1\u7206\u70b8\uff0cBGP \u5ba3\u544a\u4e0d\u4f1a\u505c\u6b62\uff0c\u5916\u90e8\u6d41\u91cf\u8fd8\u662f\u4f1a\u8f6c\u53d1\u5230\u8fd9\u53f0 VPS\u3002\u56e0\u4e3a DNS \u5df2\u7ecf GG\uff0c\u8fd9\u4e2a\u5730\u533a\u7684 DNS \u670d\u52a1\u5c06\u4e0d\u53ef\u7528\u3002<\/li>\n<li>\u5728\u7cfb\u7edf\u5185\u76f4\u63a5\u6dfb\u52a0 IP\uff0c\u4f7f\u7528 ExaBGP \u914d\u5408\u76d1\u63a7\u811a\u672c\uff0c\u5728 DNS \u7206\u70b8\u65f6\u81ea\u52a8\u53d6\u6d88\u5ba3\u544a\u8def\u7531\u3002\u6b64\u65f6\u867d\u7136\u8def\u7531\u5df2\u7ecf\u53d6\u6d88\uff0c\u4f46\u7cfb\u7edf\u5185\u8fd8\u662f\u6709\u8fd9\u4e2a IP \u5730\u5740\uff0c\u5982\u679c\u5230 DNS \u7684\u6d41\u91cf\u7ecf\u8fc7\u8fd9\u53f0 VPS\uff08\u5373\u4f7f\u5b83\u4eec\u662f\u5954\u7740\u5176\u5b83 VPS \u53bb\u7684\uff09\uff0c\u5c31\u4f1a\u88ab\u8fd9\u53f0 VPS \u5904\u7406\uff0c\u8be5\u5730\u533a DNS \u670d\u52a1\u4ecd\u7136\u4e0d\u53ef\u7528\u3002<\/li>\n<\/ol>\n<p>\u8fd9\u4e24\u4e2a\u65b9\u6848\u8fd8\u6709\u4e00\u4e2a\u5171\u540c\u7684\u7f3a\u70b9\uff1a\u4e0d\u652f\u6301 Docker\u3002<\/p>\n<p>\u6211\u6700\u7ec8\u91c7\u53d6\u7684\u65b9\u6848\u662f\uff0c\u5728 Docker \u5bb9\u5668\u5185\u6dfb\u52a0 IP\uff0c\u5e76\u5b89\u88c5 Bird \u901a\u8fc7 OSPF \u534f\u8bae\u4e0e\u4e3b\u7cfb\u7edf\u7684 Bird \u901a\u4fe1\uff0c\u8fdb\u884c\u5ba3\u544a\u3002\u5982\u679c\u5bb9\u5668\u6302\u6389\u4e86\uff0c\u5ba3\u544a\u4f1a\u81ea\u52a8\u505c\u6b62\u3002\u6b64\u65f6\u4e3b\u7cfb\u7edf\u4e0a\u6ca1\u6709\u8fd9\u4e2a IP\uff0c\u5c31\u4f1a\u6b63\u5e38\u8f6c\u53d1\u6570\u636e\uff0c\u800c\u4e0d\u4f1a\u534a\u8def\u62e6\u622a\u3002<\/p>\n<h2 id=\"\u7ed9\u5bb9\u5668\u6dfb\u52a0-ip\">\u7ed9\u5bb9\u5668\u6dfb\u52a0 IP<\/h2>\n<p>Docker \u9ed8\u8ba4\u7684\u7f51\u7edc\u9a71\u52a8 bridge \u4f1a\u5728\u4e3b\u7cfb\u7edf\u521b\u5efa\u4e00\u5f20\u865a\u62df\u7f51\u5361\uff0c\u5e76\u4e14\u6dfb\u52a0\u4e00\u4e2a\u7f51\u6bb5\uff0c\u8ba9\u8fd9\u4e2a\u7f51\u6bb5\u90fd\u4ece\u8fd9\u5f20\u7f51\u5361\u8d70\u3002\u4f46\u5982\u679c\u8fd9\u6837\u914d\u7f6e\uff0c\u4e3b\u7cfb\u7edf\u4f1a\u4e00\u76f4\u6709\u4e00\u6761\u5c06\u8fd9\u4e2a IP \u6bb5\u6307\u5411\u865a\u62df\u7f51\u5361\u7684\u8def\u7531\uff0c\u5bfc\u81f4\u7ecf\u8fc7\u8fd9\u91cc\u7684\u8bf7\u6c42\u5931\u8d25\u3002\u56e0\u6b64\uff0c\u6211\u4eec\u9700\u8981\u4e00\u4e2a\u548c\u4e3b\u7cfb\u7edf\u9694\u7edd\u7684\u7f51\u7edc\u3002<\/p>\n<p>\u5728 Docker \u4e2d\uff0c\u5728\u521b\u5efa\u7f51\u7edc\u65f6\u4f7f\u7528 macvlan \u9a71\u52a8\uff0c\u5e76\u4e14\u5f00\u542f internal \u9009\u9879\uff0c\u5c31\u53ef\u4ee5\u521b\u5efa\u4e00\u4e2a\u9694\u79bb\u7684\u7f51\u7edc\u3002<\/p>\n<pre><code class=\"hljs language-docker\">networks:\r\n  anycast_ip:\r\n    driver: macvlan\r\n    internal: true\r\n    enable_ipv6: true\r\n    ipam:\r\n      config:\r\n        - subnet: <span class=\"hljs-number\">172.22<\/span>.<span class=\"hljs-number\">76.104<\/span>\/<span class=\"hljs-number\">29<\/span>\r\n        - subnet: fdbc:f9dc:<span class=\"hljs-number\">67<\/span>ad:<span class=\"hljs-number\">2547<\/span>::\/<span class=\"hljs-number\">64<\/span>\r\n<\/code><\/pre>\n<p>\u8fd9\u4e2a\u7f51\u7edc\u53ea\u8d1f\u8d23\u7ed9\u5bb9\u5668\u6dfb\u52a0 IP \u7528\uff0c\u4e92\u8054\u7f51\u8bbf\u95ee\u4ecd\u7136\u662f\u8d70 Docker \u9ed8\u8ba4\u7684 bridge \u7f51\u7edc\u3002\u56e0\u6b64\uff0c\u5728\u5bb9\u5668\u4e2d\u8981\u8fd9\u6837\u914d\u7f6e\uff1a<\/p>\n<pre><code class=\"hljs language-docker\">services:\r\n  dnsmasq:\r\n    image: xddxdd\/dnsmasq-bird\r\n    [...]\r\n    networks:\r\n      default:\r\n        ipv4_address: <span class=\"hljs-number\">172.18<\/span>.<span class=\"hljs-number\">1.53<\/span>\r\n        ipv6_address: fcf9:a876:ed8b:c606:ba01::<span class=\"hljs-number\">53<\/span>\r\n      anycast_ip:\r\n        ipv4_address: <span class=\"hljs-number\">172.22<\/span>.<span class=\"hljs-number\">76.110<\/span>\r\n        ipv6_address: fdbc:f9dc:<span class=\"hljs-number\">67<\/span>ad:<span class=\"hljs-number\">2547<\/span>::<span class=\"hljs-number\">53<\/span>\r\n<\/code><\/pre>\n<p>\u4e0a\u4f8b\u4e2d 172.18.1.53 \u662f\u5bb9\u5668\u5728 bridge \u7f51\u7edc\u7684 IP\uff0c172.22.76.110 \u662f\u5bb9\u5668\u5206\u914d\u5230\u7684 Anycast IP \u5730\u5740\u3002<\/p>\n<p>\u542f\u52a8\u5bb9\u5668\u540e\uff0c\u53ef\u4ee5\u770b\u5230\u5bb9\u5668\u5206\u914d\u5230\u4e86\u4e24\u4e2a IP \u5730\u5740\uff1a<\/p>\n<pre><code class=\"hljs language-bash\"><span class=\"hljs-comment\"># docker exec -it dnsmasq ip addr<\/span>\r\n[...]\r\n391: eth1@if302: &lt;BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN&gt; mtu 1500 qdisc noqueue state UP\r\n    <span class=\"hljs-built_in\">link<\/span>\/ether 02:42:ac:16:4c:6e brd ff:ff:ff:ff:ff:ff\r\n    inet 172.22.76.110\/29 brd 172.22.76.111 scope global eth1\r\n       valid_lft forever preferred_lft forever\r\n    inet6 fdbc:f9dc:67ad:2547::53\/64 scope global flags 02\r\n       valid_lft forever preferred_lft forever\r\n392: eth0@if393: &lt;BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN&gt; mtu 1500 qdisc noqueue state UP\r\n    <span class=\"hljs-built_in\">link<\/span>\/ether 02:42:ac:12:01:35 brd ff:ff:ff:ff:ff:ff\r\n    inet 172.18.1.53\/24 brd 172.18.1.255 scope global eth0\r\n       valid_lft forever preferred_lft forever\r\n    inet6 fcf9:a876:ed8b:c606:ba01::53\/80 scope global flags 02\r\n       valid_lft forever preferred_lft forever\r\n<\/code><\/pre>\n<p>\u5e76\u4e14\u5bb9\u5668\u9ed8\u8ba4\u4ecd\u7136\u8d70 bridge \u7f51\u7edc\uff0c\u5916\u7f51\u8bbf\u95ee\u6ca1\u6709\u53d7\u5230\u5f71\u54cd\uff1a<\/p>\n<pre><code class=\"hljs language-bash\"><span class=\"hljs-comment\"># docker exec -it dnsmasq ip route<\/span>\r\ndefault via 172.18.1.1 dev eth0\r\n172.18.1.0\/24 dev eth0 scope <span class=\"hljs-built_in\">link<\/span>  src 172.18.1.53\r\n172.22.76.104\/29 dev eth1 scope <span class=\"hljs-built_in\">link<\/span>  src 172.22.76.110\r\n<\/code><\/pre>\n<h2 id=\"\u5bb9\u5668\u5ba3\u544a-ip\">\u5bb9\u5668\u5ba3\u544a IP<\/h2>\n<p>\u4e0b\u4e00\u6b65\u662f\u5728\u5bb9\u5668\u4e2d\u5b89\u88c5 Bird\uff0c\u5bf9\u81ea\u5df1\u7684 IP \u8fdb\u884c\u5ba3\u544a\u3002Dockerfile \u7684\u4f8b\u5b50\u53ef\u4ee5\u5728<a href=\"https:\/\/github.com\/xddxdd\/dockerfiles\/tree\/0b36ccecc7f8da33e994a479686bb78e918a969f\/dnsmasq-bird\" target=\"_blank\" rel=\"noopener\">\u8fd9\u4e2a commit<\/a>\u00a0\u4e2d\u770b\u5230\u3002\u5927\u81f4\u5c31\u662f\u5728\u5bb9\u5668\u4e2d\u5b89\u88c5 Bird \u548c Supervisord\uff0c\u7531 Supervisord \u542f\u52a8 Bird \u548c Dnsmasq\u3002\u5e76\u4e14\uff0c\u5c06\u4e00\u4efd\u7b80\u5355\u7684 Bird \u914d\u7f6e\u6587\u4ef6\u653e\u5165\u955c\u50cf\u4e2d\uff0c\u8ba9\u5bb9\u5668\u4f7f\u7528 OSPF \u534f\u8bae\u8fdb\u884c IP \u5ba3\u544a\u3002<\/p>\n<p>\u8fd9\u91cc\u4e0d\u4f7f\u7528 BGP \u662f\u56e0\u4e3a BGP \u9700\u8981\u624b\u5de5\u5206\u914d\u4e00\u4e2a AS \u53f7\uff0c\u4e0d\u4ec5\u9ebb\u70e6\uff0c\u5982\u679c\u5206\u914d\u4e0d\u5f53\u66f4\u4f1a\u5bfc\u81f4\u8be1\u5f02\u7684\u8def\u7531\u7ed3\u679c\u3002\u800c OSPF \u7684\u5404\u4e2a\u8bbe\u5907\u6ca1\u6709\u552f\u4e00\u7684\u7f16\u53f7\uff0c\u65b9\u4fbf\u90e8\u7f72\u3002<\/p>\n<p>\u914d\u7f6e\u6587\u4ef6\u5982\u4e0b\uff1a\uff08Alpine \u7684 Bird \u662f 2.0 \u7248\u672c\uff09<\/p>\n<pre><code class=\"hljs language-bash\"><span class=\"hljs-built_in\">log<\/span> syslog all;\r\nprotocol device {}\r\nprotocol ospf {\r\n    ipv4 {\r\n        import none;\r\n        <span class=\"hljs-built_in\">export<\/span> all;\r\n    };\r\n    area 0.0.0.0 {\r\n        interface <span class=\"hljs-string\">\"eth*\"<\/span> {\r\n            <span class=\"hljs-built_in\">type<\/span> broadcast;\r\n            cost 1;\r\n            hello 2;\r\n            retransmit 2;\r\n            dead count 2;\r\n        };\r\n    };\r\n}\r\nprotocol ospf v3 {\r\n    ipv6 {\r\n        import none;\r\n        <span class=\"hljs-built_in\">export<\/span> all;\r\n    };\r\n    area 0.0.0.0 {\r\n        interface <span class=\"hljs-string\">\"eth*\"<\/span> {\r\n            <span class=\"hljs-built_in\">type<\/span> broadcast;\r\n            cost 1;\r\n            hello 2;\r\n            retransmit 2;\r\n            dead count 2;\r\n        };\r\n    };\r\n}\r\n\r\ninclude <span class=\"hljs-string\">\"\/etc\/bird-static.conf\"<\/span>;\r\n<\/code><\/pre>\n<p>\u4e0d\u8fc7\u5982\u679c\u53ea\u4f7f\u7528\u8fd9\u4efd\u914d\u7f6e\u6587\u4ef6\uff0cBird \u53ea\u4f1a\u5e7f\u64ad\u5bb9\u5668\u83b7\u5f97\u7684\u8def\u7531\uff0c\u4e5f\u5c31\u662f\u53ea\u6709 172.22.76.104\/29 \u4e00\u6761\u3002\u800c\u6211\u4eec\u5e0c\u671b\u5bb9\u5668\u7684 IP 172.22.76.110\/32 \u4e5f\u80fd\u6709\u4e00\u6761\u72ec\u7acb\u8def\u7531\uff0c\u5c31\u8981\u5728 bird-static.conf \u4e2d\u8bbe\u7f6e\u9759\u6001\u8def\u7531\u3002\u72ec\u7acb\u51fa\u4e00\u4e2a\u6587\u4ef6\u662f\u4e3a\u4e86\u65b9\u4fbf\u4e4b\u540e\u4ee5 Volume \u7684\u65b9\u5f0f\u8986\u76d6\u8fd9\u4e2a\u6587\u4ef6\u3002<\/p>\n<pre><code class=\"hljs language-bash\">protocol static {\r\n    ipv4;\r\n    route 172.22.76.110\/32 unreachable;\r\n}\r\n\r\nprotocol static {\r\n    ipv6;\r\n    route fdbc:f9dc:67ad:2547::53\/128 unreachable;\r\n}\r\n<\/code><\/pre>\n<p>\u8fd9\u4efd\u914d\u7f6e\u6587\u4ef6\u4f7f Bird \u4ee5 OSPF \u534f\u8bae\u5728\u6240\u6709\u7f51\u5361\u4e0a\u5ba3\u544a\u8fd9\u4e2a\u4e24\u4e2a IP\u3002<\/p>\n<p>\u7136\u540e\uff0c\u5728\u4e3b\u7cfb\u7edf\u4e0a\u7684 Bird \u4e2d\u6dfb\u52a0 OSPF\uff1a\uff08\u4e3b\u7cfb\u7edf\u7684 Bird \u662f 1.6 \u7248\u672c\uff09<\/p>\n<pre><code class=\"hljs language-bash\">protocol ospf lt_docker_ospf {\r\n    tick 2;\r\n    rfc1583compat <span class=\"hljs-built_in\">yes<\/span>;\r\n    area 0.0.0.0 {\r\n        interface <span class=\"hljs-string\">\"docker*\"<\/span> {\r\n        <span class=\"hljs-built_in\">type<\/span> broadcast;\r\n        cost 1;\r\n        hello 2;\r\n        retransmit 2;\r\n        dead count 2;\r\n        };\r\n        interface <span class=\"hljs-string\">\"ltnet\"<\/span> {\r\n        <span class=\"hljs-built_in\">type<\/span> broadcast;\r\n        cost 1;\r\n        hello 2;\r\n        retransmit 2;\r\n        dead count 2;\r\n        };\r\n    };\r\n}\r\n<\/code><\/pre>\n<p>\u5bb9\u5668\u542f\u52a8\u65f6\u4e0d\u8981\u5fd8\u4e86\u6dfb\u52a0 NET_ADMIN \u6743\u9650\uff0c\u5426\u5219 Bird \u65e0\u6cd5\u6b63\u5e38\u5efa\u7acb OSPF \u8fde\u63a5\uff1a<\/p>\n<pre><code class=\"hljs language-yaml\">  <span class=\"hljs-attr\">dnsmasq:<\/span>\r\n    <span class=\"hljs-attr\">image:<\/span> <span class=\"hljs-string\">xddxdd\/dnsmasq-bird<\/span>\r\n    [<span class=\"hljs-string\">...<\/span>]\r\n    <span class=\"hljs-attr\">cap_add:<\/span>\r\n      <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">NET_ADMIN<\/span>\r\n<\/code><\/pre>\n<p>\u968f\u540e\u4e3b\u7cfb\u7edf\u5c31\u53ef\u4ee5\u770b\u5230\u5bb9\u5668\u7684\u5ba3\u544a\u4e86\uff1a<\/p>\n<pre><code class=\"hljs language-bash\"><span class=\"hljs-comment\"># birdc show route protocol lt_docker_ospf<\/span>\r\nBIRD 1.6.3 ready.\r\n172.22.76.110\/32   via 172.18.1.53 on ltnet [lt_docker_ospf 00:00:37] * E2 (150\/1\/10000) [172.18.1.53]\r\n172.22.76.109\/32   via 172.18.1.54 on ltnet [lt_docker_ospf 17:41:06] * E2 (150\/1\/10000) [172.18.1.54]\r\n172.22.76.104\/29   via 172.18.1.54 on ltnet [lt_docker_ospf 01:00:08] * I (150\/2) [172.18.1.54]\r\n[...]\r\n<\/code><\/pre>\n<p>\u6ce8\u610f\u8fd9\u91cc\u53ef\u4ee5\u770b\u5230\u5bb9\u5668\u4ecd\u7136\u5e7f\u64ad\u4e86 Anycast \u7684 IP \u6bb5\uff08\u4f3c\u4e4e\u96be\u4ee5\u8fc7\u6ee4\uff09\uff0c\u4f46\u56e0\u4e3a\u5355\u4e2a\u7684 Anycast IP \u6709 \/32 \u7684\u8def\u7531\u8986\u76d6 \/29 \u7684\u8def\u7531\uff0c\u6240\u4ee5\u5b9e\u9645\u4e0a\u6ca1\u4ec0\u4e48\u5f71\u54cd\u3002<\/p>\n<p>\u5728\u6bcf\u53f0 VPS \u4e0a\u505a\u76f8\u540c\u7684\u8bbe\u7f6e\uff0c\u5e76\u5c06 VPS \u4e24\u4e24\u505a\u597d Peering\uff0c\u4e00\u4e2a\u5bb9\u5668\u7684\u5ba3\u544a\u5c31\u53ef\u4ee5\u88ab\u4e3b\u7cfb\u7edf\u4e0a\u7684 Bird \u518d\u6b21\u5ba3\u544a\u7ed9\u5176\u5b83 VPS\uff0c\u8ba9\u6240\u6709 VPS \u90fd\u53ef\u4ee5\u8bbf\u95ee\u5230\u5bb9\u5668\u4e0a\u7684\u670d\u52a1\u3002<\/p>\n<p>\u5f53\u67d0\u4e2a\u5bb9\u5668\u88ab\u505c\u6b62\uff0c\u6240\u6709\u6d41\u91cf\u4f1a\u88ab\u8f6c\u53d1\u5230\u5176\u5b83\u7684 VPS\uff0c\u4fdd\u8bc1\u670d\u52a1\u4e0d\u4e2d\u65ad\u3002<\/p>\n<h2 id=\"dn42-\u4e2d\u7684\u6f14\u793a\">DN42 \u4e2d\u7684\u6f14\u793a<\/h2>\n<p>\u6211\u76ee\u524d\u5728 DN42 \u4e2d\u5efa\u7acb\u4e86\u8fd9\u6837\u4e24\u4e2a Anycast \u670d\u52a1\uff1a<\/p>\n<p>172.22.76.110 &#8211; \u57fa\u4e8e Dnsmasq \u7684\u9012\u5f52 DNS 172.22.76.109 &#8211; \u57fa\u4e8e PowerDNS \u7684\u6743\u5a01 DNS\uff0c\u4e3a\u6211\u7684 IP \u6bb5\u548c lantian.dn42 \u57df\u540d\u63d0\u4f9b\u89e3\u6790\u670d\u52a1<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4ec0\u4e48\u662f Anycast \u4e92\u8054\u7f51\u4e0a\u5e38\u7528\u7684\u8def\u7531\u534f\u8bae BGP \u662f\u8fd9\u6837\u5de5\u4f5c\u7684\uff1a \u6211\u5728 DN42 \u62e5\u6709 IP \u6bb5 172 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,2],"tags":[],"class_list":["post-10993","post","type-post","status-publish","format-standard","hentry","category-cisco","category-network"],"_links":{"self":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/10993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10993"}],"version-history":[{"count":1,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/10993\/revisions"}],"predecessor-version":[{"id":10994,"href":"https:\/\/www.xh86.me\/index.php?rest_route=\/wp\/v2\/posts\/10993\/revisions\/10994"}],"wp:attachment":[{"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xh86.me\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}