GitLab使用现有Nginx配置HTTPS访问

前言

GitLab默认内置了Nginx,但有些情况下服务器本身已经安装过Nginx,想直接利用现有的Nginx配置HTTPS访问

1、申请证书

在阿里云申请免费的证书,并下载到服务器

2、配置域名解析

创建一条 git.example.com 地址解析

3、设置外部访问地址

/etc/gitlab/gitlab.rb 设置

external_url 'https://git.example.com'

4、禁用内置的Nginx

/etc/gitlab/gitlab.rb 设置

nginx['enable'] = false

5、设置现有Nginx的用户名

根据服务器安装Nginx时创建的用户名,在 /etc/gitlab/gitlab.rb 设置

web_server['external_users'] = ['nginx-user']

6、设置现有Nginx的受信代理

/etc/gitlab/gitlab.rb 设置

gitlab_rails['trusted_proxies'] = ['127.0.0.1']

7、在现有Nginx中增加虚拟主机

/data/nginx/nginx.conf 设置

upstream gitlab-workhorse {
  server unix:/var/opt/gitlab/gitlab-workhorse/socket fail_timeout=0;
}

server {
  listen 80;
  server_name git.example.com;
  server_tokens off;
  return 301 https://$http_host$request_uri;
  access_log  /var/log/nginx/gitlab_access.log;
  error_log   /var/log/nginx/gitlab_error.log;
}

server {
  listen 443 ssl;
  server_name git.example.com;
  server_tokens off;
  root /opt/gitlab/embedded/service/gitlab-rails/public;
  
  ssl on;
  ssl_certificate cert/git.example.com/git.example.com.pem;
  ssl_certificate_key cert/git.example.com/git.example.com.key;
  
  ssl_ciphers "ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4";
  ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  ssl_prefer_server_ciphers on;
  ssl_session_cache shared:SSL:10m;
  ssl_session_timeout 5m;
  
  access_log  /var/log/nginx/gitlab_access.log;
  error_log   /var/log/nginx/gitlab_error.log;

  location / {
    client_max_body_size 0;
    gzip off;
    
    proxy_read_timeout      300;
    proxy_connect_timeout   300;
    proxy_redirect          off;

    proxy_http_version 1.1;

    proxy_set_header    Host                $http_host;
    proxy_set_header    X-Real-IP           $remote_addr;
    proxy_set_header    X-Forwarded-Ssl     on;
    proxy_set_header    X-Forwarded-For     $proxy_add_x_forwarded_for;
    proxy_set_header    X-Forwarded-Proto   $scheme;
    proxy_pass http://gitlab-workhorse;
  }
}

8、重新配置

nginx -t
nginx -s reload
gitlab-ctl reconfigure

9、参考资料

  • GitLab recipes repository
  • Using a non-bundled web-server

你可能感兴趣的:(GitLab)