Unable to configure Gitlab to work behind nginx over https
I'm attempting to run gitlab-omnibus behind nginx reverse-proxy over https externally (http internally).
- Gitlab's config structure and properties change so often that most manuals online are obsolete/don't work.
- There is no step-by-step manual on how to do this officially.
I'm at my wits end here, so in my last attempt this is what I've done so far:
-
VM#1 Ubuntu 18 LTS, installed gitlab-ee according to instructions. Changed external url to https://gitlab.example.com. letsencrypt to false, listen https to false, port to 8081. Also, I tried changing
nginx_custom_gitlab_server_configtolocation ^~ /.well-known {\n alias /opt/gitlab/embedded/service/gitlab-rails/public/.well-known;\n}\n, because I read it somewhere, but that also doesn't work with or without this. -
VM#2 Ubuntu 18 LTS, with nginx. Config:
server {
listen 443 ssl;
server_name gitlab.example.com;
server_tokens off;
client_max_body_size 40M;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
location ~ /.well-known {
allow all;
}
location / {
proxy_pass http://192.168.1.15:8081;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Protocol $scheme;
proxy_set_header X-Url-Scheme $scheme;
proxy_set_header X-Forwarded-Ssl on;
proxy_redirect off;
}The nginx log at VM#2 reports:
2021/09/19 01:34:46 [error] 12490#12490: *3906 connect() failed (111: Connection refused) while connecting to upstream, client: 10.38.254.252, server: gitlab.example.com, request: "GET / HTTP/1.1", upstream: "http://192.168.1.15:8081/", host: "gitlab.example.com"
Everything is updated as of 19.9.2021.