在 Debian 上部署的 GitLab 限速,通常分为几种场景。下面按最常见、最实用的方式给你总结。
GitLab(Omnibus 安装)自带限流功能,通过修改配置文件即可。
sudo vim /etc/gitlab/gitlab.rb
gitlab_rails['rate_limit_requests_per_period'] = 10
gitlab_rails['rate_limit_period'] = 60
含义:每个 IP 每 60 秒最多 10 次请求。
gitlab_rails['git_rate_limit'] = 100
(单位:请求/分钟)
gitlab_rails['rack_attack_git_basic_auth'] = {
'enabled' => true,
'maxretry' => 10,
'findtime' => 60,
'bantime' => 3600
}
sudo gitlab-ctl reconfigure
✅ 适合:防止刷接口、暴力破解、API 滥用
GitLab 默认使用 Nginx。
sudo vim /etc/gitlab/gitlab.rb
nginx['enable'] = true
nginx['client_max_body_size'] = '100m'
# 限速(字节/秒)
nginx['limit_req_zone'] = '$binary_remote_addr zone=one:10m rate=5r/s'
nginx['custom_gitlab_server_config'] = <<-EOS
location / {
limit_req zone=one burst=10 nodelay;
}
EOS
nginx['custom_gitlab_server_config'] = <<-EOS
location / {
limit_rate 1m;
}
EOS
sudo gitlab-ctl reconfigure
✅ 适合:限制 clone / push 速度、防止占满带宽
如果你想限制整个 GitLab 服务器的出入带宽:
sudo apt install wondershaper
sudo wondershaper eth0 1024 1024
(下载/上传 1Mbps)
⚠️ 不推荐生产环境长期使用
如果是 Docker:
docker run -d \
--name gitlab \
-p 80:80 \
--restart always \
gitlab/gitlab-ce
限速用:
--blkio-weighttc| 场景 | 推荐方式 |
|---|---|
| 防止接口刷爆 | GitLab 自带 rate_limit |
| 控制 clone 速度 | Nginx limit_rate |
| 防止暴力破解 | Rack Attack |
| 整体带宽控制 | Nginx / tc |
如果你能告诉我:
我可以直接给你一份可直接用的配置。