Enable the real_ip module in the NGINX ingress controller in the Helm chart

Summary

When installing Gitlab Enterprise Edition using the Helm chart it is not possible to set the real_ip parameters to the NGINX ingress controller.

The documentation from Gitlab is here: https://docs.gitlab.com/omnibus/settings/nginx.html#configuring-gitlab-trusted_proxies-and-the-nginx-real_ip-module

This does not cover the Kubernetes deployment using the Helm chart. When passing the parameters described in the page above, the nginx container goes into a CrashLoopBackoff due to the unknown parameters.

Steps to reproduce

Deploy the chart and add the real_ip parameters to the extraArgs section.

Configuration used



nginx-ingress:
  enabled: true
  tcpExternalConfig: "true"
  controller:
    config:
      hsts-include-subdomains: "false"
      server-name-hash-bucket-size: "256"
      enable-vts-status: "true"
      use-http2: "true"
      ssl-ciphers: "EECDH+AESGCM:EDH+AESGCM:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"
      ssl-protocols: "TLSv1.3 TLSv1.2"
      server-tokens: "false"
      # Security
      #enable-modsecurity: "true"
      #modsecurity-transaction-id: "$request_id"
      # Proxy buffering
      proxy-buffering: "off"
      proxy-request-buffering: "off"
      
    extraArgs:
      force-namespace-isolation: ""
      # Add the realip configuration
      #real-ip-header: "X-Forwarded-For"
      #real-ip-recursive: "on"

    service:
      externalTrafficPolicy: "Local"
      annotations: {}
    resources:
      requests:
        cpu: 100m
        memory: 100Mi
    publishService:
      enabled: true
    replicaCount: 3
    minAvailable: 2
    scope:
      enabled: true
    stats:
      enabled: true
    metrics:
      enabled: true
      service:
        annotations:
          gitlab.com/prometheus_scrape: "true"
          gitlab.com/prometheus_port: "10254"
          prometheus.io/scrape: "true"
          prometheus.io/port: "10254"
  defaultBackend:
    minAvailable: 1
    replicaCount: 2
    resources:
      requests:
        cpu: 5m
        memory: 5Mi
  rbac:
    create: true
  serviceAccount:
    create: true

Current behavior

Real ip is disabled

Expected behavior

Real ip is disabled

Versions

Gitlab Helm chart 4.3.7

  • Chart: (tagged version | branch | hash git rev-parse HEAD)
  • Platform:
    • Cloud: (GKE | AKS | EKS | ?)
    • Self-hosted: (OpenShift | Minikube | Rancher RKE | ?)
  • Kubernetes: (kubectl version)
    • Client:
    • Server:
  • Helm: (helm version)
    • Client:
    • Server:

Relevant logs

(Please provide any relevate log snippets you have collected, using code blocks (```) to format)

Edited by DJ Mountney