You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu16.04下Apache环境GitLab-CE子域名Let's Encrypt配置问题

嘿,我之前在多站点Apache环境下配置GitLab+Let's Encrypt时也踩过坑,给你梳理几个关键的排查和修复步骤,应该能解决你的问题:

排查与修复GitLab SSL配置问题

1. 先搞定GitLab本身的基础配置

因为你用的是Apache而非GitLab默认的Nginx,首先得让GitLab“放权”给Apache管理Web服务:

  • 编辑GitLab主配置文件 /etc/gitlab/gitlab.rb,修改以下几项:
    # 把外部URL改成HTTPS的地址
    external_url 'https://git.example.com'
    # 禁用GitLab自带的Nginx
    nginx['enable'] = false
    # 让Apache的www-data用户能访问GitLab的服务
    web_server['external_users'] = ['www-data']
    # 配置GitLab Workhorse监听本地TCP端口,方便Apache反向代理
    gitlab_workhorse['listen_network'] = "tcp"
    gitlab_workhorse['listen_addr'] = "127.0.0.1:8181"
    
    改完后执行sudo gitlab-ctl reconfigure让配置生效,这一步很关键,别忘跑!

2. 检查Apache的GitLab虚拟主机SSL配置

Let's Encrypt的certbot工具通常会自动生成SSL配置,但可能没加GitLab需要的反向代理规则。你需要手动调整/etc/apache2/sites-available/git.example.com-le-ssl.conf:

<VirtualHost *:443>
  ServerName git.example.com

  # Let's Encrypt证书路径,certbot生成的一般是这个位置
  SSLEngine on
  SSLCertificateFile /etc/letsencrypt/live/git.example.com/fullchain.pem
  SSLCertificateKeyFile /etc/letsencrypt/live/git.example.com/privkey.pem

  # 反向代理到GitLab Workhorse的端口
  ProxyPass / http://127.0.0.1:8181/
  ProxyPassReverse / http://127.0.0.1:8181/

  # 必须设置这些头部,不然GitLab会一直跳转到HTTP
  RequestHeader set X-Forwarded-Proto "https"
  RequestHeader set X-Forwarded-Ssl on

  # 支持WebSocket,GitLab的Web终端、实时通知功能需要这个
  RewriteEngine on
  RewriteCond %{HTTP:Upgrade} =websocket [NC]
  RewriteRule /(.*) ws://127.0.0.1:8181/$1 [P,L]
</VirtualHost>

然后启用Apache必备的模块并重启服务:

sudo a2enmod proxy proxy_http proxy_wstunnel rewrite headers ssl
sudo systemctl restart apache2

3. 验证Let's Encrypt证书有效性

先确认git.example.com的证书是否正常颁发:

sudo certbot certificates

如果显示证书过期或者路径不对,重新申请一次:

sudo certbot --apache -d git.example.com

申请时要确保80端口没被占用(你已经关了GitLab的Nginx,所以应该是Apache在管80,没问题)。

4. 查日志找具体问题

如果以上步骤都做完还是不行,直接看日志定位:

  • GitLab的综合日志:sudo gitlab-ctl tail,能看到GitLab服务是否正常启动、有没有权限问题
  • Apache错误日志:sudo tail -f /var/log/apache2/error.log,看看反向代理有没有报错、证书加载是否失败

常见的坑比如:反向代理端口写错了、www-data用户没权限访问GitLab的端口、SSL证书链不完整导致浏览器不信任。

5. 最后确认防火墙规则

虽然其他站点正常,但还是顺手检查一下443端口是否开放:

sudo ufw status

确保443/tcp规则是允许的。


内容的提问来源于stack exchange,提问作者OLF

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:08:50