温馨提示×

gitlab在debian如何续期

小樊
36
2026-09-17 16:02:57
栏目: 智能运维

在 Debian 上给 GitLab 续期,通常分两种场景:

  1. GitLab 证书(HTTPS,Let’s Encrypt / 自定义证书)续期
  2. GitLab License(企业版订阅)续期

下面分别说明。


一、GitLab HTTPS 证书续期(最常见)

1. 使用 Let’s Encrypt(GitLab 内置)

GitLab 默认会用内置的 Let’s Encrypt 自动续期。

手动触发续期

sudo gitlab-ctl renew-le-certs

查看证书状态

sudo gitlab-ctl status nginx

检查自动续期是否开启

sudo grep letsencrypt /etc/gitlab/gitlab.rb

应有类似:

letsencrypt['enable'] = true

强制重新配置(必要时)

sudo gitlab-ctl reconfigure

2. 使用自定义证书(非 Let’s Encrypt)

如果你用的是自己 CA 或购买的证书:

替换证书文件

/etc/gitlab/ssl/gitlab.example.com.crt
/etc/gitlab/ssl/gitlab.example.com.key

重新配置 GitLab

sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart nginx

二、GitLab Enterprise License 续期(企业版)

1. 获取新 License

从 GitLab 销售或账户中心下载 .gitlab-license 文件

2. 在 Web 页面续期

  • 登录 GitLab
  • Admin → Settings → General → License
  • 上传新 License 文件

3. 命令行方式(可选)

sudo cp new.gitlab-license /etc/gitlab/
sudo gitlab-ctl reconfigure

三、常见问题排查

证书续期失败

sudo gitlab-ctl tail letsencrypt

端口被防火墙挡住(80/443)

sudo ufw allow 80
sudo ufw allow 443

四、建议

  • Let’s Encrypt:设 cron 自动续期(GitLab 已内置)
  • 企业 License:提前 30 天续
  • 续期后务必 reconfigure + restart

如果你能告诉我:

  • GitLab 版本
  • CE 还是 EE
  • 用的是 Let’s Encrypt 还是自有证书

我可以给你更精确的命令。

0 踩