Unable to configure Gitlab to work behind nginx over https

I'm attempting to run gitlab-omnibus behind nginx reverse-proxy over https externally (http internally).

  • Gitlab's config structure and properties change so often that most manuals online are obsolete/don't work.
  • There is no step-by-step manual on how to do this officially.

I'm at my wits end here, so in my last attempt this is what I've done so far:

  • VM#1 Ubuntu 18 LTS, installed gitlab-ee according to instructions. Changed external url to https://gitlab.example.com. letsencrypt to false, listen https to false, port to 8081. Also, I tried changing nginx_custom_gitlab_server_config to location ^~ /.well-known {\n alias /opt/gitlab/embedded/service/gitlab-rails/public/.well-known;\n}\n, because I read it somewhere, but that also doesn't work with or without this.

  • VM#2 Ubuntu 18 LTS, with nginx. Config:

server {
	listen 				443 ssl;
	server_name 			gitlab.example.com;
	server_tokens			off;
	client_max_body_size		40M;
	ssl_certificate			/etc/letsencrypt/live/example.com/fullchain.pem;
	ssl_certificate_key		/etc/letsencrypt/live/example.com/privkey.pem;
	location ~ /.well-known {
		allow all;
	}
	location / {
		proxy_pass http://192.168.1.15:8081;
		proxy_set_header Host $http_host;
		proxy_set_header X-Real-IP $remote_addr;
		proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
		proxy_set_header X-Forwarded-Proto $scheme;
		proxy_set_header X-Forwarded-Protocol $scheme;
		proxy_set_header X-Url-Scheme $scheme;
		proxy_set_header X-Forwarded-Ssl on;
		proxy_redirect off;
	}

The nginx log at VM#2 reports:

2021/09/19 01:34:46 [error] 12490#12490: *3906 connect() failed (111: Connection refused) while connecting to upstream, client: 10.38.254.252, server: gitlab.example.com, request: "GET / HTTP/1.1", upstream: "http://192.168.1.15:8081/", host: "gitlab.example.com"

Everything is updated as of 19.9.2021.