温馨提示×

linux gitlab怎样更新证书

小樊
38
2026-09-19 19:16:52
栏目: 智能运维

在 Linux 上更新 GitLab 的 HTTPS 证书,通常分几种情况。下面给你最常见、最安全的做法。


一、使用 GitLab 自带证书(Omnibus 安装,推荐)

如果你是用官方 Omnibus 包安装的 GitLab:

1. 准备新证书

通常需要两个文件:

  • 证书:gitlab.example.com.crt
  • 私钥:gitlab.example.com.key

放到目录(示例):

/etc/gitlab/ssl/

2. 修改 GitLab 配置

编辑配置文件:

vi /etc/gitlab/gitlab.rb

确保有以下内容(域名改成你的):

external_url "https://gitlab.example.com"

nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.example.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.example.com.key"

3. 重新配置 GitLab

gitlab-ctl reconfigure
gitlab-ctl restart nginx

二、使用 Let’s Encrypt 自动证书

如果是 Let’s Encrypt:

1. 配置自动续期

letsencrypt['enable'] = true
letsencrypt['auto_renew'] = true

2. 手动更新证书

gitlab-ctl renew-le-certs
gitlab-ctl restart nginx

一般 cron 会自动续期,不用手动


三、使用系统证书(非 GitLab 管理 Nginx)

如果你用 外部 Nginx / Apache:

  1. 替换系统证书文件
  2. 重启 Web 服务:
systemctl restart nginx

或

systemctl restart httpd

四、Docker 方式运行的 GitLab

1. 替换挂载目录中的证书

例如:

-v /srv/gitlab/ssl:/etc/gitlab/ssl

2. 重启容器

docker restart gitlab

五、验证证书是否生效

openssl s_client -connect gitlab.example.com:443

或浏览器访问查看证书日期。


如果你能告诉我:

  • GitLab 安装方式(Omnibus / Docker / 源码)
  • 证书来源(自签 / 厂商 / Let’s Encrypt)

我可以给你精确命令。

0 踩