在 Linux 上部署的 GitLab 限速,常见有几种层面,取决于你想“限什么”:
GitLab 本身支持对 Web / API / 用户认证 做限速。
编辑配置文件:
sudo vim /etc/gitlab/gitlab.rb
# 限制单个 IP 对 GitLab Web/API 的请求速率
gitlab_rails['rate_limit_requests_per_period'] = 100
gitlab_rails['rate_limit_period'] = 60 # 60 秒内最多 100 次
# 登录失败限速
gitlab_rails['rate_limit_user_allowed_failed_login_attempts'] = 5
gitlab_rails['rate_limit_user_failed_login_period'] = 60
# API 限速
gitlab_rails['api_rate_limit'] = 300 # 每分钟 300 次
sudo gitlab-ctl reconfigure
✅ 适合:防止暴力破解、API 被刷
GitLab 自身 不好直接限制 Git 传输速度,一般靠 Nginx / 系统层。
GitLab 内置 Nginx,可以直接限速。
sudo vim /etc/gitlab/gitlab.rb
nginx['enable'] = true
# 定义限速区域
nginx['custom_gitlab_server_config'] = <<-EOS
limit_req_zone $binary_remote_addr zone=gitlab_limit:10m rate=10r/s;
EOS
# 应用限速
nginx['custom_nginx_config'] = <<-EOS
server {
listen 80;
server_name gitlab.example.com;
location / {
limit_req zone=gitlab_limit burst=20 nodelay;
proxy_pass http://gitlab;
}
}
EOS
sudo gitlab-ctl reconfigure
✅ 适合:HTTP(S) 访问限速
❌ 对 SSH 无效
限制某个 IP 或网卡速度:
# 限制 eth0 出口 1Mbps
sudo tc qdisc add dev eth0 root tbf rate 1mbit burst 32kbit latency 400ms
恢复:
sudo tc qdisc del dev eth0 root
修改 /etc/ssh/sshd_config:
Match User git
ForceCommand /usr/bin/pv -L 1m /usr/bin/git-shell -c "$SSH_ORIGINAL_COMMAND"
(需安装 pv)
如果是 Docker:
docker run -d \
--name gitlab \
-p 80:80 \
--network mynet \
gitlab/gitlab-ce
限速:
| 需求 | 推荐方式 |
|---|---|
| 防爆破 / API 刷 | GitLab 配置 |
| Web 访问限速 | Nginx limit_req |
| Git 下载限速 | tc / SSH |
| 整体带宽 | 系统 tc |
如果你能说明:
我可以给你一份精确配置。