Deployment Overview of GitLab on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful installation, the server must meet the following requirements:
-
Operating System: Compatible with Debian-based (Ubuntu, Debian) or RPM-based (CentOS, Rocky Linux, AlmaLinux) distributions.
-
Privileges: Root or sudo access is required for package installation and service configuration.
-
Network Requirements:
-
Access to the internet to download repository keys and packages.
-
DNS resolution capabilities (dnsutils/bind-utils).
-
Ports: The application requires standard web ports (80, 443) to be open for HTTPS traffic via Let's Encrypt.
FQDN of the final panel on the hostkey.in domain¶
The application is configured with a specific Fully Qualified Domain Name (FQDN) based on the server ID and the predefined domain template.
| Parameter | Value |
|---|---|
| Prefix | gl |
| Domain | hostkey.in |
| Full template | gl{Server_ID}.hostkey.in |
Application installation process¶
The installation method depends on the operating system detected on the host:
Debian-based Systems (Ubuntu, Debian)¶
-
The system performs an update of the package cache and installs essential prerequisites including
curl,gnupg,ca-certificates, andapt-transport-https. -
A dedicated GitLab CE repository key is added to
/etc/apt/keyrings/gitlab-ce.gpg. -
The GitLab CE repository is added to the system sources list.
-
The
gitlab-cepackage is installed via the APT package manager. -
The application is configured using the
gitlab-ctl reconfigurecommand.
RPM-based Systems (CentOS, Rocky Linux, AlmaLinux)¶
-
Necessary utilities such as
bind-utilsandcurlare installed. -
The
firewalldservice is stopped and disabled to prevent connectivity issues. -
An official GitLab installation script is executed via
curlto add the appropriate repositories. -
The system packages are updated, and
gitlab-ceis installed using the YUM package manager. -
The application is configured using the
gitlab-ctl reconfigurecommand.
Access Rights and Security¶
-
Firewall: On RPM-based systems,
firewalldis explicitly stopped to ensure service availability. -
SSL/TLS: The application uses Let's Encrypt for automated SSL certificate management. Automatic renewal is enabled within the GitLab configuration.
-
Authentication: An initial root password is set during the installation process to secure the administrative account.
Custom Scripts and Additional Setup¶
The deployment includes several post-installation actions:
-
Configuration Modification: The
/etc/gitlab/gitlab.rbfile is modified to set theexternal_url, configure theinitial_root_password, and enable Let's Encrypt auto-renewal. -
Tagging: The server is tagged with its web panel URL for management purposes.
Application Update Instructions¶
To update the GitLab application, use the package manager corresponding to your distribution:
For Debian/Ubuntu:
For CentOS/Rocky/AlmaLinux:
After updating packages, it is recommended to run the reconfiguration command to apply any changes:
Location of configuration files and data¶
The primary configuration file for GitLab is located at:
/etc/gitlab/gitlab.rb
Available ports for connection¶
-
HTTPS:
443(Standard web access) -
HTTP:
80(Used for Let's Encrypt challenges)