在 Debian 上部署的 GitLab 开启 HTTPS,通常有两种常见场景:
你可以使用:
示例目录(自建证书):
/etc/gitlab/ssl/gitlab.example.com.crt
/etc/gitlab/ssl/gitlab.example.com.key
编辑配置文件:
sudo vim /etc/gitlab/gitlab.rb
修改为:
external_url 'https://gitlab.example.com'
nginx['redirect_http_to_https'] = true
nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.example.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.example.com.key"
sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart
sudo ufw allow 443
sudo ufw allow 80
在 /etc/gitlab/gitlab.rb 中:
external_url 'https://gitlab.example.com'
letsencrypt['enable'] = true
letsencrypt['auto_renew'] = true
然后:
sudo gitlab-ctl reconfigure
GitLab 会自动申请并配置 HTTPS。
如果你 不用 GitLab 自带的 Nginx:
nginx['enable'] = false
然后在你的 Nginx 中配置 HTTPS 并反代到 GitLab(通常是 proxy_pass http://gitlab内部IP)。
确保:
external_url 'https://...'
并重启 GitLab
nginx['listen_port'] = 443
nginx['listen_https'] = true
如果你愿意,可以告诉我:
我可以给你更精确的步骤。