温馨提示×

debian gitlab怎样开启https

小樊
49
2026-09-17 16:03:56
栏目: 智能运维

在 Debian 上部署的 GitLab 开启 HTTPS,通常有两种常见场景:


一、使用 GitLab 自带 Nginx(推荐,最简单)

1. 准备 SSL 证书

你可以使用:

  • 免费证书(Let’s Encrypt)
  • 自签名证书
  • 商业证书

示例目录(自建证书):

/etc/gitlab/ssl/gitlab.example.com.crt
/etc/gitlab/ssl/gitlab.example.com.key

2. 修改 GitLab 配置

编辑配置文件:

sudo vim /etc/gitlab/gitlab.rb

修改为:

external_url 'https://gitlab.example.com'

nginx['redirect_http_to_https'] = true
nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.example.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.example.com.key"

3. 重新配置 GitLab

sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart

4. 开放防火墙

sudo ufw allow 443
sudo ufw allow 80

二、使用 Let’s Encrypt 自动证书(官方支持)

在 /etc/gitlab/gitlab.rb 中:

external_url 'https://gitlab.example.com'

letsencrypt['enable'] = true
letsencrypt['auto_renew'] = true

然后:

sudo gitlab-ctl reconfigure

GitLab 会自动申请并配置 HTTPS。


三、使用外部 Nginx / Apache 反向代理(进阶)

如果你 不用 GitLab 自带的 Nginx:

nginx['enable'] = false

然后在你的 Nginx 中配置 HTTPS 并反代到 GitLab(通常是 proxy_pass http://gitlab内部IP)。


四、常见问题

1. 访问提示证书不安全

  • 自签名证书会提示
  • 浏览器需手动信任

2. Git 操作仍走 HTTP?

确保:

external_url 'https://...'

并重启 GitLab

3. 端口不是 443?

nginx['listen_port'] = 443
nginx['listen_https'] = true

如果你愿意,可以告诉我:

  • GitLab 安装方式(omnibus / docker)
  • 是否有域名
  • 是否已有证书

我可以给你更精确的步骤。

0 踩