温馨提示×

gitlab在debian如何限速

小樊
43
2026-09-29 15:07:49
栏目: 智能运维

在 Debian 上部署的 GitLab 限速,通常分为几种场景。下面按最常见、最实用的方式给你总结。


一、GitLab 自带的限流(推荐,最省事)

GitLab(Omnibus 安装)自带限流功能,通过修改配置文件即可。

1. 编辑配置文件

sudo vim /etc/gitlab/gitlab.rb

2. 限制 Git HTTP / API 请求速率(按 IP)

gitlab_rails['rate_limit_requests_per_period'] = 10
gitlab_rails['rate_limit_period'] = 60

含义:每个 IP 每 60 秒最多 10 次请求。

3. 限制 Git LFS / 克隆 / 拉取

gitlab_rails['git_rate_limit'] = 100

(单位:请求/分钟)

4. 限制登录失败

gitlab_rails['rack_attack_git_basic_auth'] = {
  'enabled' => true,
  'maxretry' => 10,
  'findtime' => 60,
  'bantime' => 3600
}

5. 重新加载配置

sudo gitlab-ctl reconfigure

✅ 适合:防止刷接口、暴力破解、API 滥用


二、Nginx 层限速(最常用,控制带宽)

GitLab 默认使用 Nginx。

1. 修改 GitLab Nginx 配置

sudo vim /etc/gitlab/gitlab.rb
nginx['enable'] = true
nginx['client_max_body_size'] = '100m'

# 限速(字节/秒)
nginx['limit_req_zone'] = '$binary_remote_addr zone=one:10m rate=5r/s'

2. 针对 Git 路径限速

nginx['custom_gitlab_server_config'] = <<-EOS
  location / {
    limit_req zone=one burst=10 nodelay;
  }
EOS

3. 带宽限制(如 1MB/s)

nginx['custom_gitlab_server_config'] = <<-EOS
  location / {
    limit_rate 1m;
  }
EOS

4. 重新配置

sudo gitlab-ctl reconfigure

✅ 适合:限制 clone / push 速度、防止占满带宽


三、系统层限速(tc / wondershaper)

如果你想限制整个 GitLab 服务器的出入带宽:

使用 wondershaper(最简单)

sudo apt install wondershaper
sudo wondershaper eth0 1024 1024

(下载/上传 1Mbps)

⚠️ 不推荐生产环境长期使用


四、Docker 部署的 GitLab 限速

如果是 Docker:

docker run -d \
  --name gitlab \
  -p 80:80 \
  --restart always \
  gitlab/gitlab-ce

限速用:

  • Docker --blkio-weight
  • 宿主机 tc
  • 或 Nginx 反向代理限速

五、推荐组合方案 ✅

场景 推荐方式
防止接口刷爆 GitLab 自带 rate_limit
控制 clone 速度 Nginx limit_rate
防止暴力破解 Rack Attack
整体带宽控制 Nginx / tc

如果你能告诉我:

  • GitLab 安装方式(Omnibus / Docker)
  • 想限 请求频率 还是 带宽
  • 内网还是公网

我可以直接给你一份可直接用的配置。

0 踩