我正在尝试按照https://docs.gitlab.com/omnibus/gitlab-mattermost/README.html配置Gitlab Mattermost。我正在使用非捆绑的nginx服务器,其配置如所述here。 Gitlab的其余部分目前正在运作;我可以转到http://code.my.company.com访问它。
Mattermost可能配置正确,但我似乎无法找到有关如何使用Mattermost配置非捆绑nginx的任何信息。特别是,我想知道proxy_pass
应该是什么。
Gitlab sample configuration file使用proxy_pass http://gitlab-workhorse
。在同一文件的顶部附近,他们将其定义为unix:/home/git/gitlab/tmp/sockets/gitlab-workhorse.socket
。这适用于Gitlab本身(正如我们希望的那样!),但我不知道用于Mattermost的proxy_pass
是什么。
正如您在下面的nginx配置文件中看到的,我通过简单地复制/粘贴大部分正常的Gitlab nginx配置(包括proxy_pass http://gitlab-workhorse
行)来创建nginx配置的Mattermost部分。毫不奇怪,这只会导致http://code.my.company.com:1337转发给正常的Gitlab,而不是Mattermost。
这是我的/etc/nginx/sites-available/default
文件(此文件中的所有评论都是我的;如果您想查看原始评论,请参阅the source):
## Most of this is copy/pasted from https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/support/nginx/gitlab
## A few of the paths are different from the current version,
## perhaps because the Gitlab-suggested nginx config was different when I installed Gitlab
upstream gitlab-workhorse {
server unix:/var/opt/gitlab/gitlab-workhorse/socket;
}
map $http_upgrade $connection_upgrade_gitlab {
default upgrade;
'' close;
}
## Mattermost config, mostly copy/pasted from the server{} block below
server {
listen 0.0.0.0:1337 default_server;
listen [::]:1337 default_server;
server_name code.my.company.com;
location / {
client_max_body_size 0;
gzip off;
proxy_read_timeout 300;
proxy_connect_timeout 300;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade_gitlab;
proxy_pass http://gitlab-workhorse;
}
}
## normal Gitlab config
server {
listen 0.0.0.0:80 default_server;
listen [::]:80 default_server;
server_name code.my.company.com;
server_tokens off;
root /opt/gitlab/embedded/service/gitlab-rails/public;
access_log /var/log/nginx/gitlab_access.log;
error_log /var/log/nginx/gitlab_error.log;
location / {
client_max_body_size 0;
gzip off;
proxy_read_timeout 300;
proxy_connect_timeout 300;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade_gitlab;
proxy_pass http://gitlab-workhorse;
}
}
以下是/etc/gitlab/gitlab.rb
:
external_url 'http://code.my.company.com'
mattermost_external_url 'http://code.my.company.com:1337'
nginx['enable'] = false
mattermost_nginx['enable'] = false
mattermost['gitlab_enable'] = true
mattermost['gitlab_id'] = "HiddenForStackOverflowPost"
mattermost['gitlab_secret'] = "HiddenForStackOverflowPost"
mattermost['gitlab_scope'] = ""
mattermost['gitlab_auth_endpoint'] = "http://code.my.company.com/oauth/authorize"
mattermost['gitlab_token_endpoint'] = "http://code.my.company.com/oauth/token"
mattermost['gitlab_user_api_endpoint'] = "http://code.my.company.com/api/v3/user"
答案 0 :(得分:1)
以下是来自docs工作的Mattermost nginx配置的示例:
upstream backend {
server 10.10.10.2:8065;
}
proxy_cache_path /var/cache/nginx levels=1:2 keys_zone=mattermost_cache:10m max_size=3g inactive=120m use_temp_path=off;
server {
listen 80;
server_name mattermost.example.com;
location /api/v3/users/websocket {
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
client_max_body_size 50M;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Frame-Options SAMEORIGIN;
proxy_buffers 256 16k;
proxy_buffer_size 16k;
proxy_read_timeout 600s;
proxy_pass http://backend;
}
location / {
client_max_body_size 50M;
proxy_set_header Connection "";
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Frame-Options SAMEORIGIN;
proxy_buffers 256 16k;
proxy_buffer_size 16k;
proxy_read_timeout 600s;
proxy_cache mattermost_cache;
proxy_cache_revalidate on;
proxy_cache_min_uses 2;
proxy_cache_use_stale timeout;
proxy_cache_lock on;
proxy_pass http://backend;
}
}
您需要将10.0.0.2:8065
替换为运行Mattermost的IP(或主机)和端口。如果您也想设置SSL,请查看文档here(此示例配置来自)。