温馨提示×

linux gitlab如何配ssl

小樊
43
2026-10-07 09:24:06
栏目: 云计算

下面以 Linux(Ubuntu/CentOS 等常见发行版)上自建 GitLab 为例,说明如何配置 SSL(HTTPS)。


一、准备 SSL 证书

方式 1:使用 Let’s Encrypt(推荐,免费)

sudo apt install certbot -y        # Ubuntu/Debian
# 或
sudo yum install certbot -y        # CentOS

申请证书(假设域名是 gitlab.example.com):

sudo certbot certonly --webroot \
  -w /var/www/letsencrypt \
  -d gitlab.example.com

证书位置:

/etc/letsencrypt/live/gitlab.example.com/fullchain.pem
/etc/letsencrypt/live/gitlab.example.com/privkey.pem

方式 2:使用自签名证书(测试用)

sudo mkdir -p /etc/gitlab/ssl
sudo openssl req -x509 -nodes -days 365 \
  -newkey rsa:2048 \
  -keyout /etc/gitlab/ssl/gitlab.example.com.key \
  -out /etc/gitlab/ssl/gitlab.example.com.crt

二、修改 GitLab 配置

编辑配置文件:

sudo vim /etc/gitlab/gitlab.rb

1️⃣ 设置 HTTPS

external_url 'https://gitlab.example.com'

2️⃣ 指定 SSL 证书(Let’s Encrypt 示例)

nginx['ssl_certificate'] = "/etc/letsencrypt/live/gitlab.example.com/fullchain.pem"
nginx['ssl_certificate_key'] = "/etc/letsencrypt/live/gitlab.example.com/privkey.pem"

如果是自签名:

nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.example.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.example.com.key"

3️⃣ (可选)强制跳转 HTTPS

nginx['redirect_http_to_https'] = true

三、重新配置 GitLab

sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart

四、防火墙 & 端口

确保开放:

sudo ufw allow 443
sudo ufw allow 80

或 CentOS:

firewall-cmd --permanent --add-service=https
firewall-cmd --reload

五、Let’s Encrypt 自动续期(重要)

sudo crontab -e

添加:

0 3 * * * /usr/bin/certbot renew --quiet && /usr/bin/gitlab-ctl restart nginx

六、验证

浏览器访问:

https://gitlab.example.com

无证书警告即成功 ✅


常见问题

  • 端口冲突:GitLab 默认使用 80/443,确保未被 Nginx/Apache 占用
  • Docker GitLab:需映射 443 并在 GITLAB_OMNIBUS_CONFIG 中配置
  • 内网 IP:Let’s Encrypt 不支持,只能用自签名

如果你能提供:

  • GitLab 安装方式(Omnibus / Docker / K8s)
  • Linux 发行版
  • 是否已有证书

我可以给你更精确的配置示例。

0 踩