温馨提示×

linux gitlab如何限速

小樊
49
2026-09-16 15:57:12
栏目: 智能运维

在 Linux 上部署的 GitLab 限速,常见有几种层面,取决于你想“限什么”:


一、GitLab 自带限速(推荐先做)

GitLab 本身支持对 Web / API / 用户认证 做限速。

1. 修改 GitLab 配置

编辑配置文件:

sudo vim /etc/gitlab/gitlab.rb

2. 常见限速参数

# 限制单个 IP 对 GitLab Web/API 的请求速率
gitlab_rails['rate_limit_requests_per_period'] = 100
gitlab_rails['rate_limit_period'] = 60   # 60 秒内最多 100 次

# 登录失败限速
gitlab_rails['rate_limit_user_allowed_failed_login_attempts'] = 5
gitlab_rails['rate_limit_user_failed_login_period'] = 60

# API 限速
gitlab_rails['api_rate_limit'] = 300   # 每分钟 300 次

3. 重新加载配置

sudo gitlab-ctl reconfigure

✅ 适合:防止暴力破解、API 被刷


二、Git(SSH / HTTP)限速(git clone / push)

GitLab 自身 不好直接限制 Git 传输速度,一般靠 Nginx / 系统层。


三、通过 GitLab 的 Nginx 限速(最常用)

GitLab 内置 Nginx,可以直接限速。

1. 编辑 gitlab.rb

sudo vim /etc/gitlab/gitlab.rb

2. 配置 Nginx 限速

nginx['enable'] = true

# 定义限速区域
nginx['custom_gitlab_server_config'] = <<-EOS
    limit_req_zone $binary_remote_addr zone=gitlab_limit:10m rate=10r/s;
EOS

# 应用限速
nginx['custom_nginx_config'] = <<-EOS
    server {
        listen 80;
        server_name gitlab.example.com;

        location / {
            limit_req zone=gitlab_limit burst=20 nodelay;
            proxy_pass http://gitlab;
        }
    }
EOS

3. 重新加载

sudo gitlab-ctl reconfigure

✅ 适合:HTTP(S) 访问限速
❌ 对 SSH 无效


四、限制 Git 传输速度(带宽限速)

方法 1:Linux tc(系统级,推荐)

限制某个 IP 或网卡速度:

# 限制 eth0 出口 1Mbps
sudo tc qdisc add dev eth0 root tbf rate 1mbit burst 32kbit latency 400ms

恢复:

sudo tc qdisc del dev eth0 root

方法 2:SSH 限速(Git over SSH)

修改 /etc/ssh/sshd_config:

Match User git
    ForceCommand /usr/bin/pv -L 1m /usr/bin/git-shell -c "$SSH_ORIGINAL_COMMAND"

(需安装 pv)


五、Docker 部署的 GitLab 限速

如果是 Docker:

docker run -d \
  --name gitlab \
  -p 80:80 \
  --network mynet \
  gitlab/gitlab-ce

限速:

  • Docker 网络限速
  • 或前面加 Nginx / Traefik

六、总结建议

需求 推荐方式
防爆破 / API 刷 GitLab 配置
Web 访问限速 Nginx limit_req
Git 下载限速 tc / SSH
整体带宽 系统 tc

如果你能说明:

  • GitLab 部署方式(Omnibus / Docker)
  • 想限制 Web、API 还是 Git 传输
  • 限速目标(防刷 / 省带宽)

我可以给你一份精确配置。

0 踩