4 ms·
If you're self-hosting gitlab-ce (which should really be open to internal traffic only) and want one more layer of protection from all this stuff, it's easy to
by showerst 5y ago
If you're self-hosting gitlab-ce (which should really be open to internal traffic only) and want one more layer of protection from all this stuff, it's easy to throw it behind http basic auth. In your gitlab.rb:
nginx['custom_gitlab_server_config'] = "auth_basic 'Restricted';\n auth_basic_user_file /etc/gitlab/.htpasswd;\n location ^~ /.well-known { root /var/www/letsencrypt; auth_basic off;}"
- Naac 5y agoA different comment thread recommending http basic auth: https://news.ycombinator.com/item?id=29761966 https://news.ycombinator.com/item?id=29761966
- czbond 5y agoDo internal hosted versions not have auth built in ?
- 0x0 5y agoIt keeps the riff-raff away when a new gitlab 0day appears in some obscure public/guestuser visible API
- paxys 5y agoA more standard way is to use `auth_request`, which passes every incoming request to some auth server to get a yes/no response. And this service can be as simple or complicated as you'd like.