Enable the real_ip module in the NGINX ingress controller in the Helm chart
Summary
When installing Gitlab Enterprise Edition using the Helm chart it is not possible to set the real_ip parameters to the NGINX ingress controller.
The documentation from Gitlab is here: https://docs.gitlab.com/omnibus/settings/nginx.html#configuring-gitlab-trusted_proxies-and-the-nginx-real_ip-module
This does not cover the Kubernetes deployment using the Helm chart. When passing the parameters described in the page above, the nginx container goes into a CrashLoopBackoff due to the unknown parameters.
Steps to reproduce
Deploy the chart and add the real_ip parameters to the extraArgs section.
Configuration used
nginx-ingress:
enabled: true
tcpExternalConfig: "true"
controller:
config:
hsts-include-subdomains: "false"
server-name-hash-bucket-size: "256"
enable-vts-status: "true"
use-http2: "true"
ssl-ciphers: "EECDH+AESGCM:EDH+AESGCM:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"
ssl-protocols: "TLSv1.3 TLSv1.2"
server-tokens: "false"
# Security
#enable-modsecurity: "true"
#modsecurity-transaction-id: "$request_id"
# Proxy buffering
proxy-buffering: "off"
proxy-request-buffering: "off"
extraArgs:
force-namespace-isolation: ""
# Add the realip configuration
#real-ip-header: "X-Forwarded-For"
#real-ip-recursive: "on"
service:
externalTrafficPolicy: "Local"
annotations: {}
resources:
requests:
cpu: 100m
memory: 100Mi
publishService:
enabled: true
replicaCount: 3
minAvailable: 2
scope:
enabled: true
stats:
enabled: true
metrics:
enabled: true
service:
annotations:
gitlab.com/prometheus_scrape: "true"
gitlab.com/prometheus_port: "10254"
prometheus.io/scrape: "true"
prometheus.io/port: "10254"
defaultBackend:
minAvailable: 1
replicaCount: 2
resources:
requests:
cpu: 5m
memory: 5Mi
rbac:
create: true
serviceAccount:
create: true
Current behavior
Real ip is disabled
Expected behavior
Real ip is disabled
Versions
Gitlab Helm chart 4.3.7
- Chart: (tagged version | branch | hash
git rev-parse HEAD) - Platform:
- Cloud: (GKE | AKS | EKS | ?)
- Self-hosted: (OpenShift | Minikube | Rancher RKE | ?)
- Kubernetes: (
kubectl version)- Client:
- Server:
- Helm: (
helm version)- Client:
- Server:
Relevant logs
(Please provide any relevate log snippets you have collected, using code blocks (```) to format)
Edited by DJ Mountney