在 Linux 上配置 GitLab 的 SSL(HTTPS),通常有两种常见方式:
下面以 最常见、最省事的方式:GitLab 内置 Nginx + 证书 来说明。
你需要:
gitlab.example.com)gitlab.example.com.crtgitlab.example.com.keysudo mkdir -p /etc/gitlab/ssl
sudo chmod 700 /etc/gitlab/ssl
sudo cp gitlab.example.com.crt /etc/gitlab/ssl/
sudo cp gitlab.example.com.key /etc/gitlab/ssl/
sudo chmod 600 /etc/gitlab/ssl/*
编辑配置文件:
sudo vim /etc/gitlab/gitlab.rb
external_url 'https://gitlab.example.com'
# 启用 SSL
nginx['redirect_http_to_https'] = true
# 证书路径(注意文件名)
nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.example.com.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.example.com.key"
✅ external_url 必须是 https
sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart
sudo ufw allow 443
sudo ufw allow 80
(CentOS / Rocky)
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --reload
GitLab 支持自动申请:
letsencrypt['enable'] = true
letsencrypt['contact_emails'] = ['admin@example.com']
然后:
sudo gitlab-ctl reconfigure
⚠️ 需要:
浏览器访问:
https://gitlab.example.com
无证书警告即成功。
合并证书:
cat gitlab.crt ca_bundle.crt > fullchain.crt
需客户端信任 CA。
可关闭 GitLab Nginx:
nginx['enable'] = false
如果你告诉我:
我可以给你更精确的配置方案。