You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx-Ingress未覆盖X-Forwarded-Proto致GitLab重定向过多求助

永久修复GitLab在GCP L7负载均衡器+IAP+nginx-ingress环境下的ERR_TOO_MANY_REDIRECTS问题

问题背景

使用GCP L7负载均衡器、IAP搭配0.49.3版本nginx-ingress controller部署自建GitLab时,出现ERR_TOO_MANY_REDIRECTS错误。排查发现请求到达GitLab时,X-Forwarded-Proto和X-Forwarded-Scheme头部被设置为http,导致GitLab持续触发HTTPS重定向,形成循环。手动修改nginx-ingress容器内的nginx.conf将这两个头部设为https并添加ssl-redirect: false注解后,问题临时解决,但每次部署流水线执行后配置会被重置。尝试通过Ingress注解和ConfigMap配置覆盖无效,需永久修复方案。

永久修复方案

方案1:配置nginx-ingress信任GCP LB代理,强制转发HTTPS头部

nginx-ingress需要识别GCP L7 LB的IP为可信代理,同时强制设置转发头部为HTTPS,避免配置被重置。

1.1 更新nginx-ingress的ConfigMap

在ConfigMap中添加代理信任配置和强制HTTPS头部的snippet:

apiVersion: v1
kind: ConfigMap
metadata:
  name: nginx
  namespace: ingress-stable-protected
data:
  # 保留原有配置,新增以下内容
  proxy-real-ip-cidr: "35.191.0.0/16,35.201.0.0/16,130.211.0.0/22" # GCP LB官方IP段,可根据实际调整
  use-forwarded-headers: "true"
  forwarded-for-header: "X-Forwarded-For"
  http-snippet: |
    map $http_x_forwarded_proto $proxy_x_forwarded_proto {
      default https;
    }
    map $http_x_forwarded_scheme $proxy_x_forwarded_scheme {
      default https;
    }

1.2 更新GitLab Ingress注解

在Ingress资源中添加配置片段,强制设置转发头部:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: gitlab-chart-webservice-default
  namespace: gitlab
  annotations:
    # 保留原有注解,新增以下内容
    nginx.ingress.kubernetes.io/configuration-snippet: |
      proxy_set_header X-Forwarded-Proto https;
      proxy_set_header X-Forwarded-Scheme https;
    nginx.ingress.kubernetes.io/force-ssl-redirect: "false"
    nginx.ingress.kubernetes.io/proxy-redirect-from: http://gitlab.ci.example.com
    nginx.ingress.kubernetes.io/proxy-redirect-to: https://gitlab.ci.example.com
# 其余配置保留

方案2:直接配置GitLab信任转发头部

通过GitLab自身配置强制识别HTTPS请求,无需依赖nginx-ingress的转发头部设置。

2.1 修改GitLab Helm Values(Helm部署场景)

在values.yaml中添加环境变量配置:

gitlab:
  webservice:
    extraEnv:
      - name: GITLAB_OMNIBUS_CONFIG
        value: |
          nginx['proxy_set_headers'] = {
            "X-Forwarded-Proto" => "https",
            "X-Forwarded-Scheme" => "https"
          }
          gitlab_rails['trusted_proxies'] = ["35.191.0.0/16", "35.201.0.0/16"] # GCP LB IP段
          gitlab_rails['force_ssl'] = false
          gitlab_rails['redirect_http_to_https'] = false

2.2 重新部署GitLab

执行Helm升级命令生效配置:

helm upgrade gitlab-chart gitlab/gitlab -n gitlab -f values.yaml

方案3:调整GCP L7负载均衡器后端配置

直接在GCP LB层面强制设置HTTPS转发头部:

  1. 进入GCP控制台的负载均衡器页面,找到目标LB的后端服务
  2. 进入"高级配置"->"请求头设置"
  3. 添加自定义请求头:
    • 键:X-Forwarded-Proto,值:https
    • 键:X-Forwarded-Scheme,值:https
  4. 保存配置,等待LB更新生效

验证修复

部署完成后,执行以下操作验证:

  1. 查看nginx-ingress控制器的nginx.conf,确认proxy_set_header X-Forwarded-Proto https;和proxy_set_header X-Forwarded-Scheme https;已存在
  2. 发送测试请求,检查请求头部中两个字段的值为https
  3. 访问GitLab页面,确认无重定向循环错误

内容的提问来源于stack exchange,提问作者Stefan Neacsu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 17:10:34