You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EC2上GitLab Pages出现502错误:x509证书未知权威签名

GitLab Pages 502错误:证书验证失败解决方案

问题背景

在Amazon Linux 2的EC2实例上部署GitLab 16.4.0,已为GitLab主站和Pages配置Let's Encrypt证书:

## GitLab URL
external_url "https://gitlab-test.tools.myhostname.io"

# NGINX configuration
nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab-test.tools.myhostname.io.crt"
nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab-test.tools.myhostname.io.key"

# Letsencrypt configuration
letsencrypt['enable'] = true
letsencrypt['auto_renew_hour'] = "12"
letsencrypt['auto_renew_minute'] = "30" # Renew every 1th day of the month at 12:30
letsencrypt['auto_renew_day_of_month'] = "*/1"

## GitLab Pages
pages_external_url "https://gitlab-test-pages.myhostname.io"
pages_nginx['redirect_http_to_https'] = true
pages_nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab-test-pages.myhostname.io.crt"
pages_nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab-test-pages.myhostname.io.key"

GitLab主站正常访问,但Pages站点出现502错误「Whoops, something went wrong on our end」,浏览器显示证书有效,但Pages NGINX日志报错:

{"correlation_id":"01HDECSGCCFK5SKZZA206X6MAJ",
"error":"Get \"https://gitlab-test.tools.myhostname.io/api/v4/internal/pages?host=poc.gitlab-test-pages.myhostname.io\": tls: failed to verify certificate: x509: certificate signed by unknown authority",
"host":"poc.gitlab-test-pages.myhostname.io",
"level":"error",
"msg":"could not fetch domain information from a source","path":"/favicon.ico",
"time":"2023-10-23T13:50:04Z"}

重新生成证书后问题仍未解决。

问题分析

核心原因是GitLab Pages服务向主站API发起内部请求时,服务器本地的证书信任链不完整:Let's Encrypt的证书依赖中间/根证书完成信任验证,而Amazon Linux 2默认的CA证书存储可能未包含Let's Encrypt的根证书,或GitLab Pages配置未指定正确的CA证书路径。

解决方案

方案1:更新系统CA证书存储

Amazon Linux 2默认可能缺少Let's Encrypt的根证书(如ISRG Root X1),执行以下命令更新:

# 安装/更新ca-certificates包
sudo yum install -y ca-certificates
# 刷新系统证书信任链
sudo update-ca-trust extract
# 重启GitLab Pages服务
sudo gitlab-ctl restart pages

方案2:为GitLab Pages指定CA证书路径

修改/etc/gitlab/gitlab.rb,添加Pages服务的CA证书配置,指向系统默认CA bundle或Let's Encrypt的fullchain证书:

# 配置Pages服务使用系统默认CA证书链
pages['internal_api_ca_file'] = "/etc/pki/tls/certs/ca-bundle.crt"

# 或者指向主站的fullchain证书(包含完整信任链)
# pages['internal_api_ca_file'] = "/etc/gitlab/ssl/gitlab-test.tools.myhostname.io.crt"

保存配置后重新应用并重启服务:

sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart pages

方案3:确保证书文件包含完整信任链

确认GitLab配置中使用的是fullchain证书(包含域名证书、中间证书和根证书),而非单独的域名证书:

  1. 复制Certbot生成的fullchain文件到GitLab证书目录:
# 主站证书
sudo cp /etc/letsencrypt/live/gitlab-test.tools.myhostname.io/fullchain.pem /etc/gitlab/ssl/gitlab-test.tools.myhostname.io.crt
# Pages证书
sudo cp /etc/letsencrypt/live/gitlab-test-pages.myhostname.io/fullchain.pem /etc/gitlab/ssl/gitlab-test-pages.myhostname.io.crt
  1. 重新配置GitLab并重启服务:
sudo gitlab-ctl reconfigure
sudo gitlab-ctl restart

验证

访问Pages站点,查看/var/log/gitlab/pages_nginx/current日志,确认不再出现证书验证错误,站点可正常访问。

内容的提问来源于stack exchange,提问作者Sierra6

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 18:13:13