局域网Ubuntu服务器部署GitLab HTTPS访问失败及证书问题求助
解决局域网GitLab HTTPS访问及Let's Encrypt验证失败问题
问题核心原因
Let's Encrypt的ACME验证服务器是公网服务,无法访问你局域网内的gitlab.mydomain.com域名,导致HTTP-01验证流程直接失败,这是你执行gitlab-ctl reconfigure报错的根本原因——公网验证服务器无法穿透到你的内网环境完成验证。
具体解决步骤
1. 禁用GitLab自带的Let's Encrypt自动配置
编辑GitLab主配置文件/etc/gitlab/gitlab.rb,找到并修改以下配置项:
# 禁用Let's Encrypt自动证书申请 letsencrypt['enable'] = false # 注释或删除所有与Let's Encrypt相关的其他配置(如contact_emails、auto_renew等)
2. 生成自签名证书(适用于局域网场景)
如果没有内网CA,直接生成自签名证书即可满足内网HTTPS需求:
# 生成私钥 openssl genrsa -out /etc/gitlab/ssl/gitlab.mydomain.com.key 2048 # 生成自签名证书,有效期365天,CN需与你的内网域名一致 openssl req -new -x509 -key /etc/gitlab/ssl/gitlab.mydomain.com.key -out /etc/gitlab/ssl/gitlab.mydomain.com.crt -days 365 -subj "/CN=gitlab.mydomain.com"
设置证书文件权限(GitLab需要正确的权限才能读取):
chmod 600 /etc/gitlab/ssl/gitlab.mydomain.com.key chmod 644 /etc/gitlab/ssl/gitlab.mydomain.com.crt chown root:root /etc/gitlab/ssl/gitlab.mydomain.com.*
3. 配置GitLab使用自定义证书
回到/etc/gitlab/gitlab.rb,设置HTTPS相关配置:
external_url 'https://gitlab.mydomain.com' # 开启HTTP转HTTPS nginx['redirect_http_to_https'] = true # 指定自定义证书路径 nginx['ssl_certificate'] = "/etc/gitlab/ssl/gitlab.mydomain.com.crt" nginx['ssl_certificate_key'] = "/etc/gitlab/ssl/gitlab.mydomain.com.key"
4. 应用配置并重启服务
执行命令让GitLab加载新配置:
gitlab-ctl reconfigure gitlab-ctl restart
5. 客户端信任自签名证书(可选)
将/etc/gitlab/ssl/gitlab.mydomain.com.crt复制到局域网内的客户端机器,添加到系统或浏览器的信任根证书列表中,即可消除访问时的安全提示。
内容的提问来源于stack exchange,提问作者Z.J
相关产品推荐
相关产品推荐

