Skip to content

Deployment Overview of GitLab on Server

Prerequisites and Basic Requirements

To ensure a successful installation, the server must meet the following requirements:

  • Operating System: Compatible with Debian-based (Ubuntu, Debian) or RPM-based (CentOS, Rocky Linux, AlmaLinux) distributions.

  • Privileges: Root or sudo access is required for package installation and service configuration.

  • Network Requirements:

  • Access to the internet to download repository keys and packages.

  • DNS resolution capabilities (dnsutils/bind-utils).

  • Ports: The application requires standard web ports (80, 443) to be open for HTTPS traffic via Let's Encrypt.

FQDN of the final panel on the hostkey.in domain

The application is configured with a specific Fully Qualified Domain Name (FQDN) based on the server ID and the predefined domain template.

Parameter Value
Prefix gl
Domain hostkey.in
Full template gl{Server_ID}.hostkey.in

Application installation process

The installation method depends on the operating system detected on the host:

Debian-based Systems (Ubuntu, Debian)

  1. The system performs an update of the package cache and installs essential prerequisites including curl, gnupg, ca-certificates, and apt-transport-https.

  2. A dedicated GitLab CE repository key is added to /etc/apt/keyrings/gitlab-ce.gpg.

  3. The GitLab CE repository is added to the system sources list.

  4. The gitlab-ce package is installed via the APT package manager.

  5. The application is configured using the gitlab-ctl reconfigure command.

RPM-based Systems (CentOS, Rocky Linux, AlmaLinux)

  1. Necessary utilities such as bind-utils and curl are installed.

  2. The firewalld service is stopped and disabled to prevent connectivity issues.

  3. An official GitLab installation script is executed via curl to add the appropriate repositories.

  4. The system packages are updated, and gitlab-ce is installed using the YUM package manager.

  5. The application is configured using the gitlab-ctl reconfigure command.

Access Rights and Security

  • Firewall: On RPM-based systems, firewalld is explicitly stopped to ensure service availability.

  • SSL/TLS: The application uses Let's Encrypt for automated SSL certificate management. Automatic renewal is enabled within the GitLab configuration.

  • Authentication: An initial root password is set during the installation process to secure the administrative account.

Custom Scripts and Additional Setup

The deployment includes several post-installation actions:

  • Configuration Modification: The /etc/gitlab/gitlab.rb file is modified to set the external_url, configure the initial_root_password, and enable Let's Encrypt auto-renewal.

  • Tagging: The server is tagged with its web panel URL for management purposes.

Application Update Instructions

To update the GitLab application, use the package manager corresponding to your distribution:

For Debian/Ubuntu:

sudo apt update
sudo apt upgrade gitlab-ce

For CentOS/Rocky/AlmaLinux:

sudo yum update gitlab-ce

After updating packages, it is recommended to run the reconfiguration command to apply any changes:

sudo gitlab-ctl reconfigure

Location of configuration files and data

The primary configuration file for GitLab is located at:

  • /etc/gitlab/gitlab.rb

Available ports for connection

  • HTTPS: 443 (Standard web access)

  • HTTP: 80 (Used for Let's Encrypt challenges)

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×