Gitlab Runner本地网络注册遇401错误的排查与解决
GitLab Runner内网IP注册401未授权问题解决
问题场景
GitLab EE部署在内网IP 176.0.1.7,GitLab Runner部署在同网段内网IP 176.0.1.3,尝试直接用内网IP注册Runner时遭遇401未授权错误。
错误详情
执行以下注册命令:
sudo gitlab-runner register --url http://176.0.1.7 --registration-token GR12345678_1234abcde --executor "shell" --description "rails-runner" --maintenance-note "rails-runner is currently in maintenance" --tag-list "rails, debian-11" --run-untagged="true"
返回错误:
ERROR: Registering runner... failed runner=GR123456789 status=GET https://<domain>:443/api/v4/runners: 401 Unauthorized PANIC: Failed to register the runner.
排查发现
通过httpry抓包确认,请求被301重定向至公网域名,但后续认证流程异常。使用公网域名注册可成功,但Runner会通过公网与GitLab通信,存在安全风险。
解决方案
- 在GitLab Runner节点的
/etc/hosts文件中添加内网IP与GitLab域名的映射:
176.0.1.7 git.git-local.com # 替换为你的GitLab域名
- 使用域名执行注册命令:
sudo gitlab-runner register --url https://git.git-local.com/ --registration-token GR12345678_1234abcde --executor "shell" --description "rails-runner" --maintenance-note "rails-runner is currently in maintenance" --tag-list "rails, debian-11" --run-untagged="true"
执行成功后,GitLab后台会显示Runner的内网IP,实现两者的内网通信。
内容的提问来源于stack exchange,提问作者S.Klatt
相关产品推荐
相关产品推荐

