温馨提示×

linux gitlab怎么配ssl

小樊
38
2026-09-22 18:26:51
栏目: 云计算

下面以 Linux + 自建 GitLab(Omnibus 安装方式) 为例,说明如何配置 SSL(HTTPS)。如果你用的是 Docker 或源码安装,可以告诉我,我再补充对应方式。


一、准备 SSL 证书

你需要:

  • 域名(如 gitlab.example.com)
  • 证书文件:
    • gitlab.example.com.crt(或 .pem)
    • gitlab.example.com.key

方式 1:使用 Let’s Encrypt(免费,推荐)

sudo gitlab-ctl stop nginx
sudo certbot certonly --webroot -w /var/opt/gitlab/nginx/www -d gitlab.example.com

证书路径一般为:

/etc/letsencrypt/live/gitlab.example.com/fullchain.pem
/etc/letsencrypt/live/gitlab.example.com/privkey.pem

方式 2:使用自有证书

把证书放到:

/etc/gitlab/ssl/gitlab.example.com.crt
/etc/gitlab/ssl/gitlab.example.com.key

二、修改 GitLab 配置

编辑配置文件:

sudo vim /etc/gitlab/gitlab.rb

1. 设置外部访问地址(HTTPS)

external_url 'https://gitlab.example.com'

2. 配置 SSL 证书路径(Omnibus 默认)

nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.example.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.example.com.key"

如果是 Let’s Encrypt:

nginx['ssl_certificate'] = "/etc/letsencrypt/live/gitlab.example.com/fullchain.pem"
nginx['ssl_certificate_key'] = "/etc/letsencrypt/live/gitlab.example.com/privkey.pem"

3.(可选)强制 HTTPS 跳转

nginx['redirect_http_to_https'] = true

三、重新配置并重启 GitLab

sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart

四、防火墙 & 端口

确保开放:

sudo ufw allow 443
sudo ufw allow 80

五、验证

浏览器访问:

https://gitlab.example.com

无证书警告即配置成功。


六、Let’s Encrypt 自动续期(可选)

sudo crontab -e

添加:

0 3 * * * /usr/bin/certbot renew --quiet && /opt/gitlab/bin/gitlab-ctl restart nginx

如果你用的是:

  • ✅ Docker GitLab
  • ✅ 源码安装
  • ✅ 使用反向代理(Nginx / Caddy)
  • ✅ 内网自签证书

可以告诉我,我可以给你更精确的配置示例。

0 踩