温馨提示×

linux gitlab ssl如何配置

小樊
42
2026-09-28 15:24:04
栏目: 云计算

在 Linux 上配置 GitLab 的 SSL(HTTPS),通常有两种常见方式:

  1. 使用 GitLab 自带的 Nginx(推荐)
  2. 使用外部反向代理(如独立 Nginx / Apache)

下面以 最常见、最省事的方式:GitLab 内置 Nginx + 证书 来说明。


一、准备 SSL 证书

你需要:

  • 域名(如 gitlab.example.com)
  • 证书文件:
    • gitlab.example.com.crt
    • gitlab.example.com.key

证书来源

  • Let’s Encrypt(免费)
  • 公司内部 CA
  • 云厂商证书

二、放置证书文件

sudo mkdir -p /etc/gitlab/ssl
sudo chmod 700 /etc/gitlab/ssl

sudo cp gitlab.example.com.crt /etc/gitlab/ssl/
sudo cp gitlab.example.com.key /etc/gitlab/ssl/

sudo chmod 600 /etc/gitlab/ssl/*

三、修改 GitLab 配置

编辑配置文件:

sudo vim /etc/gitlab/gitlab.rb

核心配置

external_url 'https://gitlab.example.com'

# 启用 SSL
nginx['redirect_http_to_https'] = true

# 证书路径(注意文件名)
nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.example.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.example.com.key"

✅ external_url 必须是 https


四、重新配置 GitLab

sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart

五、防火墙 & 端口

sudo ufw allow 443
sudo ufw allow 80

(CentOS / Rocky)

sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --reload

六、Let’s Encrypt 自动证书(可选)

GitLab 支持自动申请:

letsencrypt['enable'] = true
letsencrypt['contact_emails'] = ['admin@example.com']

然后:

sudo gitlab-ctl reconfigure

⚠️ 需要:

  • 公网可访问
  • 80 端口开放
  • 正确 DNS 解析

七、验证

浏览器访问:

https://gitlab.example.com

无证书警告即成功。


常见问题

1. 证书链不完整

合并证书:

cat gitlab.crt ca_bundle.crt > fullchain.crt

2. 私有 CA

需客户端信任 CA。

3. 想用外部 Nginx

可关闭 GitLab Nginx:

nginx['enable'] = false

如果你告诉我:

  • GitLab 版本
  • 是否是内网
  • 是否用 Docker

我可以给你更精确的配置方案。

0 踩