์ƒˆ์†Œ์‹

DevOps/Git

[GitLab] ๊นƒ๋žฉ SSL์ ์šฉ ๋ฐ ์ž๋™๊ฐฑ์‹ 

  • -

 

 

 

๊นƒ๋žฉ(GitLab)์„ ์‹ค์ œ ์šด์˜ํ•˜๊ธฐ ์œ„ํ•ด์„œ ๋„๋ฉ”์ธ๊ณผ SSL๋“ฑ๋ก์„ ์ง„ํ–‰ํ•˜์˜€๊ณ , ๊ทธ ๊ณผ์ •์„ ๊ธฐ๋กํ•˜๋Š” ๋ชฉ์ ์œผ๋กœ ์ž‘์„ฑํ–ˆ์Šต๋‹ˆ๋‹ค. ๋” ์ข‹์€ ๋ฐฉ๋ฒ•์œผ๋กœ ํ•˜์…”๋„ ๋ฌด๋ฐฉํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ธ€์€ ์ฐธ๊ณ ์šฉ์œผ๋กœ๋งŒ ๋ด์ฃผ์‹œ๊ธธ ๋ฐ”๋ž๋‹ˆ๋‹ค.

 

์ฐธ๊ณ  ์‚ฌ์ดํŠธ

https://docs.gitlab.com/omnibus/settings/ssl.html#available-ssl-configuration-tasks

 

SSL Configuration | GitLab

Documentation for GitLab Community Edition, GitLab Enterprise Edition, Omnibus GitLab, and GitLab Runner.

docs.gitlab.com


 

SSL์ ์šฉ ๋ฐ ์ž๋™๊ฐฑ์‹ 

 

๊นƒ๋žฉ(GitLab) ์„ค์ •ํŒŒ์ผ ํŽธ์ง‘๊ธฐ๋กœ ์—ด๊ธฐ

sudo vi /etc/gitlab/gitlab.rb

 

์•„๋ž˜์˜ ๋‚ด์šฉ์„ ์„ค์ •ํŒŒ์ผ ์•ˆ์— ์ถ”๊ฐ€

letsencrypt['enable'] = true                      # GitLab 10.5 and 10.6 require this option
external_url "https://gitlab.example.com"         # Must use https protocol
letsencrypt['contact_emails'] = ['foo@email.com'] # Optional

 

๊นƒ๋žฉ(GitLab)์—์„œ ์ž์ฒด์ ์œผ๋กœ ์ง€์›ํ•˜๋Š” ์ž๋™๊ฐฑ์‹  ์ ์šฉ

# This example renews every 7th day at 12:30
letsencrypt['auto_renew_hour'] = "12"
letsencrypt['auto_renew_minute'] = "30"
letsencrypt['auto_renew_day_of_month'] = "*/7"

(์ฃผ์˜) ์ธ์ฆ์„œ๋Š” 30์ผ ์ด๋‚ด์— ๋งŒ๋ฃŒ๋˜๋Š” ๊ฒฝ์šฐ์—๋งŒ ๊ฐฑ์‹ ๋ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ๋งค์›” 1์ผ 00:00์— ๊ฐฑ์‹ ํ•˜๋„๋ก ์„ค์ •ํ•˜๊ณ  ์ธ์ฆ์„œ๊ฐ€ 31์ผ์— ๋งŒ๋ฃŒ๋˜๋Š” ๊ฒฝ์šฐ ์ธ์ฆ์„œ๋Š” ๊ฐฑ์‹ ๋˜๊ธฐ ์ „์— ๋งŒ๋ฃŒ๋ฉ๋‹ˆ๋‹ค.

 

 

์ˆ˜๋™์œผ๋กœ Let's Encrypt ์ธ์ฆ์„œ๋ฅผ ๊ฐฑ์‹ 

sudo gitlab-ctl reconfigure

 

์ ์šฉ์ด ์™„๋ฃŒ๋˜์—ˆ๋‹ค๋ฉด, ์•„๋ž˜์™€ ๊ฐ™์ด ssl ๊ด€๋ จ ๋””๋ ‰ํ„ฐ๋ฆฌ๊ฐ€ ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค.

 

 

[Ubuntu] ์šฐ๋ถ„ํˆฌ ์„œ๋ฒ„ ์„ธํŒ…

 

[Ubuntu] ์šฐ๋ถ„ํˆฌ ์„œ๋ฒ„ ์„ธํŒ…

์šฐ๋ถ„ํˆฌ(Ubuntu)์„œ๋ฒ„์— ๋ฆฌ๋ˆ…์Šค(Linux)์„ค์น˜๋ฅผ ๊ธฐ๋ก ๋ชฉ์ ์œผ๋กœ ์ •๋ฆฌ ๋ฐ ์ž‘์„ฑ ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ๊ฐ„๋‹จํ•˜๊ฒŒ ์ •๋ฆฌํ•˜์ž๋Š” ๋ชฉ์ ์ด๋ผ ์ƒ์„ธํ•˜๊ฒŒ ์ •๋ฆฌ๋˜์–ด ์žˆ์ง€๋Š” ์•Š์„ ๊ฒ๋‹ˆ๋‹ค. ํ•„์š”ํ•œ ๋ถ€๋ถ„์€ ๋ฆฌ์„œ์นญ์„ ํ†ตํ•ด ์ฑ„์›Œ์ฃผ์‹œ

sm-code.tistory.com

[GitLab] ๊นƒ๋žฉ ์šฐ๋ถ„ํˆฌ(Ubuntu)์„œ๋ฒ„์— ์„ธํŒ…

 

[GitLab] ๊นƒ๋žฉ ์šฐ๋ถ„ํˆฌ(Ubuntu)์„œ๋ฒ„์— ์„ธํŒ…

์šฐ๋ถ„ํˆฌ(Ubuntu) OS์—์„œ ๊นƒ๋žฉ(GitLab) ์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•˜๊ฒŒ ๋˜์–ด ๊ธฐ๋ก ๋ชฉ์ ์œผ๋กœ ์ž‘์„ฑ๋œ ๊ธ€์ž…๋‹ˆ๋‹ค. GitLab ์„ค์น˜ ๋ฐฉ๋ฒ•์€ ์ฐพ์•„๋ณธ ๊ฒฐ๊ณผ, ์„ค์น˜๋ฐฉ์‹์ด ๋ณ€๊ฒฝ๋˜๋Š” ์ด์Šˆ๊ฐ€ ์ข…์ข… ๋ฐœ์ƒํ•˜๋‹ˆ ์ฐธ๊ณ ์šฉ์œผ๋กœ๋งŒ ํ™•์ธํ•˜์…”์•ผ ํ•ฉ

sm-code.tistory.com

[GitLab] ๊นƒ๋žฉ ๋กœ๊ทธ์ธ ํ™”๋ฉด ์ปค์Šคํ„ฐ๋งˆ์ด์ง•

 

[GitLab] ๊นƒ๋žฉ ๋กœ๊ทธ์ธ ํ™”๋ฉด ์ปค์Šคํ„ฐ๋งˆ์ด์ง•

๊นƒ๋žฉ(GitLab)์—์„œ ๋กœ๊ทธ์ธ ํ™”๋ฉด ์ปค์Šคํ„ฐ๋งˆ์ด์ง•์„ ํ†ตํ•ด ์ž…๋ง›์— ๋งž๊ฒŒ ๋ณ€๊ฒฝํ•˜๊ณ  ์‹ถ์€๋ฐ ์ƒ๊ฐ์™ธ๋กœ ์ž๋ฃŒ๊ฐ€ ๋งŽ์ง€ ์•Š์•„์„œ ๊ธฐ๋ก ๋ชฉ์ ์œผ๋กœ ์ž‘์„ฑ๋˜์—ˆ์œผ๋ฏ€๋กœ ์ฐธ๊ณ ์šฉ์œผ๋กœ๋งŒ ๋ด์ฃผ์‹œ๋ฉด ๊ฐ์‚ฌํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ์„ค์ • ๋ฐฉ

sm-code.tistory.com

 

[GitLab] ๊นƒ๋žฉ ๋งˆ์ดํฌ๋กœ์†Œํ”„ํŠธ(MS) ๊ณ„์ • SSO ์„ค์ •

 

[GitLab] ๊นƒ๋žฉ ๋งˆ์ดํฌ๋กœ์†Œํ”„ํŠธ(MS) ๊ณ„์ • SSO ์„ค์ •

๊นƒ๋žฉ์€ OmniAuth๋ผ๋Š” ๋ชจ๋“ˆ์„ ๋‚ด์žฅํ•˜์—ฌ SSO(Single Sign On)์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ด๋กœ ์ธํ•ด ๋งค์šฐ ๋‹ค์–‘ํ•œ ์ธ์ฆ ํ”„๋กœ๋ฐ”์ด๋”๋ฅผ ์ง€์›ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. https://docs.gitlab.com/ee/integration/omniauth.html#supported-providers ์ด ๋ฌธ์„œ

sm-code.tistory.com

 

Contents

ํฌ์ŠคํŒ… ์ฃผ์†Œ๋ฅผ ๋ณต์‚ฌํ–ˆ์Šต๋‹ˆ๋‹ค. ๐Ÿ˜Š

์ด ๊ธ€์ด ๋„์›€์ด ๋˜์—ˆ๋‹ค๋ฉด ๊ณต๊ฐ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค. ๐Ÿ‘