Gitlab: Difference between revisions
Add example for setting feature flags declaratively |
m style improvements |
||
| (6 intermediate revisions by 3 users not shown) | |||
| Line 5: | Line 5: | ||
== Installation == | == Installation == | ||
=== Generate Secrets === | |||
<syntaxhighlight lang=console> | |||
# install -d -m 0700 /var/lib/gitlab/secrets | |||
# sh -c 'openssl rand -hex 32 > /var/lib/gitlab/secrets/activeRecordPrimaryKey' | |||
# sh -c 'openssl rand -hex 32 > /var/lib/gitlab/secrets/activeRecordDeterministicKey' | |||
# sh -c 'openssl rand -hex 32 > /var/lib/gitlab/secrets/activeRecordSalt' | |||
# chown -R gitlab:gitlab /var/lib/gitlab/secrets | |||
# chmod 700 /var/lib/gitlab/secrets | |||
# chmod 0600 /var/lib/gitlab/secrets/* | |||
</syntaxhighlight> | |||
< | === Nix Configuration === | ||
services.gitlab = { | <syntaxhighlight lang="nix">services.gitlab = { | ||
enable = true; | enable = true; | ||
databasePasswordFile = pkgs.writeText "dbPassword" "zgvcyfwsxzcwr85l"; | databasePasswordFile = pkgs.writeText "dbPassword" "zgvcyfwsxzcwr85l"; | ||
| Line 17: | Line 26: | ||
dbFile = pkgs.writeText "dbsecret" "we2quaeZ"; | dbFile = pkgs.writeText "dbsecret" "we2quaeZ"; | ||
jwsFile = pkgs.runCommand "oidcKeyBase" {} "${pkgs.openssl}/bin/openssl genrsa 2048 > $out"; | jwsFile = pkgs.runCommand "oidcKeyBase" {} "${pkgs.openssl}/bin/openssl genrsa 2048 > $out"; | ||
activeRecordPrimaryKeyFile = "/var/lib/gitlab/secrets/activeRecordPrimaryKey"; | |||
activeRecordDeterministicKeyFile = "/var/lib/gitlab/secrets/activeRecordDeterministicKey"; | |||
activeRecordSaltFile = "/var/lib/gitlab/secrets/activeRecordSalt"; | |||
}; | }; | ||
}; | }; | ||
| Line 32: | Line 44: | ||
services.openssh.enable = true; | services.openssh.enable = true; | ||
systemd.services.gitlab-backup.environment.BACKUP = "dump"; | systemd.services.gitlab-backup.environment.BACKUP = "dump";</syntaxhighlight> | ||
</ | |||
After applying the configuration head to http://localhost and login with username <code>root</code> and the password specified in <code>initialRootPasswordFile</code>. | After applying the configuration head to http://localhost and login with username <code>root</code> and the password specified in <code>initialRootPasswordFile</code>. | ||
| Line 46: | Line 57: | ||
Query info about your Gitlab instance | Query info about your Gitlab instance | ||
<syntaxHighlight lang= | <syntaxHighlight lang=console> | ||
gitlab-rake gitlab:env:info | $ gitlab-rake gitlab:env:info | ||
</syntaxHighlight> | </syntaxHighlight> | ||
Check for configuration errors | Check for configuration errors | ||
<syntaxHighlight lang= | <syntaxHighlight lang=console> | ||
gitlab-rake gitlab:check | $ gitlab-rake gitlab:check | ||
</syntaxHighlight> | </syntaxHighlight> | ||
| Line 134: | Line 145: | ||
Apparently, it can happen that no root user is created (or at least not fully created in the database) when building the system with a newly configured Gitlab service. | Apparently, it can happen that no root user is created (or at least not fully created in the database) when building the system with a newly configured Gitlab service. | ||
In this case, it can help to stop the Gitlab service, drop the postgres database and reboot the system. This sequence instantiates the Gitlab root user. With that, it's possible to log in with user "root" and the password configured in "initialRootPasswordFile".<syntaxhighlight lang= | In this case, it can help to stop the Gitlab service, drop the postgres database and reboot the system. This sequence instantiates the Gitlab root user. With that, it's possible to log in with user "root" and the password configured in "initialRootPasswordFile".<syntaxhighlight lang=console> | ||
# stop the gitlab stack | $ # stop the gitlab stack | ||
systemctl stop gitlab.service | $ systemctl stop gitlab.service | ||
# drop the database | $ # drop the database | ||
sudo -u postgres dropdb gitlab | $ sudo -u postgres dropdb gitlab | ||
# reboot (just starting the gitlab service again seems not to be sufficient) | $ # reboot (just starting the gitlab service again seems not to be sufficient) | ||
sudo reboot | $ sudo reboot | ||
</syntaxhighlight> | </syntaxhighlight> | ||
| Line 156: | Line 167: | ||
IdentitiesOnly yes | IdentitiesOnly yes | ||
PreferredAuthentications publickey | PreferredAuthentications publickey | ||
Note: If you want to just be able to copy the url from the clone Gitlab menu consider changing the git user to the generated "gitlab" user or create some other user yourself. See gitlabs reference [https://docs.gitlab.com/omnibus/settings/configuration/#change-the-name-of-the-git-user-or-group Change the name of the git user or group] | |||
<references /> | <references /> | ||
== See also == | |||
* [[Gitea]], a web app, Git development repository and project management. | |||
* [[Forgejo]], a web application offers Git development repositories and project management. Community fork of Gitea. | |||
[[Category:Server]] | [[Category:Server]] | ||
[[Category:Web Applications]] | [[Category:Web Applications]] | ||
[[Category:NixOS Manual]] | [[Category:NixOS Manual]] | ||