Nginx-Ingress未覆盖X-Forwarded-Proto致GitLab重定向过多求助
永久修复GitLab在GCP L7负载均衡器+IAP+nginx-ingress环境下的ERR_TOO_MANY_REDIRECTS问题
问题背景
使用GCP L7负载均衡器、IAP搭配0.49.3版本nginx-ingress controller部署自建GitLab时,出现ERR_TOO_MANY_REDIRECTS错误。排查发现请求到达GitLab时,X-Forwarded-Proto和X-Forwarded-Scheme头部被设置为http,导致GitLab持续触发HTTPS重定向,形成循环。手动修改nginx-ingress容器内的nginx.conf将这两个头部设为https并添加ssl-redirect: false注解后,问题临时解决,但每次部署流水线执行后配置会被重置。尝试通过Ingress注解和ConfigMap配置覆盖无效,需永久修复方案。
永久修复方案
方案1:配置nginx-ingress信任GCP LB代理,强制转发HTTPS头部
nginx-ingress需要识别GCP L7 LB的IP为可信代理,同时强制设置转发头部为HTTPS,避免配置被重置。
1.1 更新nginx-ingress的ConfigMap
在ConfigMap中添加代理信任配置和强制HTTPS头部的snippet:
apiVersion: v1 kind: ConfigMap metadata: name: nginx namespace: ingress-stable-protected data: # 保留原有配置,新增以下内容 proxy-real-ip-cidr: "35.191.0.0/16,35.201.0.0/16,130.211.0.0/22" # GCP LB官方IP段,可根据实际调整 use-forwarded-headers: "true" forwarded-for-header: "X-Forwarded-For" http-snippet: | map $http_x_forwarded_proto $proxy_x_forwarded_proto { default https; } map $http_x_forwarded_scheme $proxy_x_forwarded_scheme { default https; }
1.2 更新GitLab Ingress注解
在Ingress资源中添加配置片段,强制设置转发头部:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: gitlab-chart-webservice-default namespace: gitlab annotations: # 保留原有注解,新增以下内容 nginx.ingress.kubernetes.io/configuration-snippet: | proxy_set_header X-Forwarded-Proto https; proxy_set_header X-Forwarded-Scheme https; nginx.ingress.kubernetes.io/force-ssl-redirect: "false" nginx.ingress.kubernetes.io/proxy-redirect-from: http://gitlab.ci.example.com nginx.ingress.kubernetes.io/proxy-redirect-to: https://gitlab.ci.example.com # 其余配置保留
方案2:直接配置GitLab信任转发头部
通过GitLab自身配置强制识别HTTPS请求,无需依赖nginx-ingress的转发头部设置。
2.1 修改GitLab Helm Values(Helm部署场景)
在values.yaml中添加环境变量配置:
gitlab: webservice: extraEnv: - name: GITLAB_OMNIBUS_CONFIG value: | nginx['proxy_set_headers'] = { "X-Forwarded-Proto" => "https", "X-Forwarded-Scheme" => "https" } gitlab_rails['trusted_proxies'] = ["35.191.0.0/16", "35.201.0.0/16"] # GCP LB IP段 gitlab_rails['force_ssl'] = false gitlab_rails['redirect_http_to_https'] = false
2.2 重新部署GitLab
执行Helm升级命令生效配置:
helm upgrade gitlab-chart gitlab/gitlab -n gitlab -f values.yaml
方案3:调整GCP L7负载均衡器后端配置
直接在GCP LB层面强制设置HTTPS转发头部:
- 进入GCP控制台的负载均衡器页面,找到目标LB的后端服务
- 进入"高级配置"->"请求头设置"
- 添加自定义请求头:
- 键:
X-Forwarded-Proto,值:https - 键:
X-Forwarded-Scheme,值:https
- 键:
- 保存配置,等待LB更新生效
验证修复
部署完成后,执行以下操作验证:
- 查看nginx-ingress控制器的
nginx.conf,确认proxy_set_header X-Forwarded-Proto https;和proxy_set_header X-Forwarded-Scheme https;已存在 - 发送测试请求,检查请求头部中两个字段的值为
https - 访问GitLab页面,确认无重定向循环错误
内容的提问来源于stack exchange,提问作者Stefan Neacsu
相关产品推荐
相关产品推荐

