在 Linux 上更新 GitLab 的 HTTPS 证书,通常分几种情况。下面给你最常见、最安全的做法。
如果你是用官方 Omnibus 包安装的 GitLab:
通常需要两个文件:
gitlab.example.com.crtgitlab.example.com.key放到目录(示例):
/etc/gitlab/ssl/
编辑配置文件:
vi /etc/gitlab/gitlab.rb
确保有以下内容(域名改成你的):
external_url "https://gitlab.example.com"
nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.example.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.example.com.key"
gitlab-ctl reconfigure
gitlab-ctl restart nginx
如果是 Let’s Encrypt:
letsencrypt['enable'] = true
letsencrypt['auto_renew'] = true
gitlab-ctl renew-le-certs
gitlab-ctl restart nginx
一般 cron 会自动续期,不用手动
如果你用 外部 Nginx / Apache:
systemctl restart nginx
或
systemctl restart httpd
例如:
-v /srv/gitlab/ssl:/etc/gitlab/ssl
docker restart gitlab
openssl s_client -connect gitlab.example.com:443
或浏览器访问查看证书日期。
如果你能告诉我:
我可以给你精确命令。