温馨提示×

centos gitlab怎样集成ldap

小樊
32
2026-10-05 19:55:43
栏目: 智能运维

在 CentOS 上部署的 GitLab 集成 LDAP 通常通过修改 GitLab 配置文件 来实现(GitLab 内置了对 LDAP 的支持,无需额外插件)。下面以 Omnibus 安装的 GitLab 为例说明。


一、前提条件

  • GitLab 已通过官方 Omnibus 包安装在 CentOS
  • 已有可用的 LDAP 服务(如 OpenLDAP、Windows AD)
  • 有 LDAP 管理员账号或只读账号
  • GitLab 版本较新(建议 12+)

二、修改 GitLab LDAP 配置

1. 编辑配置文件

sudo vi /etc/gitlab/gitlab.rb

2. 添加 LDAP 配置示例(OpenLDAP)

gitlab_rails['ldap_enabled'] = true
gitlab_rails['ldap_servers'] = YAML.load <<-EOS
  main:
    label: 'LDAP'
    host: 'ldap.example.com'
    port: 389
    uid: 'uid'
    bind_dn: 'cn=admin,dc=example,dc=com'
    password: 'ldap_password'
    encryption: 'plain' # 可选:start_tls / simple_tls
    verify_certificates: false
    active_directory: false
    allow_username_or_email_login: true
    base: 'dc=example,dc=com'
    user_filter: ''
EOS

3. Windows AD 示例

gitlab_rails['ldap_servers'] = YAML.load <<-EOS
  main:
    label: 'AD'
    host: 'ad.example.com'
    port: 389
    uid: 'sAMAccountName'
    bind_dn: 'cn=gitlab,ou=users,dc=example,dc=com'
    password: 'password'
    encryption: 'plain'
    active_directory: true
    allow_username_or_email_login: true
    base: 'dc=example,dc=com'
EOS

三、应用配置

sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart

四、验证 LDAP 是否可用

sudo gitlab-rake gitlab:ldap:check

看到用户列表说明配置成功。


五、登录方式

  • GitLab 登录页会出现 “LDAP” 登录按钮
  • 使用 LDAP 用户名 / 邮箱登录
  • 首次登录会自动创建 GitLab 用户

六、常见问题

1. 登录失败但 LDAP check 正常

  • 检查 uid 是否正确
  • 检查 user_filter
  • 查看日志:
sudo gitlab-ctl tail gitlab-rails

2. 启用 TLS

port: 636
encryption: 'simple_tls'

3. 只同步部分用户

user_filter: '(memberOf=cn=gitlab-users,ou=groups,dc=example,dc=com)'

七、可选:禁止本地登录

gitlab_rails['omniauth_allow_single_sign_on'] = ['ldap']

如果你能提供:

  • GitLab 安装方式(Omnibus / Docker / 源码)
  • LDAP 类型(OpenLDAP / AD)
  • CentOS 版本

我可以给你一份完全对应你环境的配置。

0 踩