Repository navigation
Expand file tree
/
Copy pathpillar.example
More file actions
159 lines (157 loc) · 6.06 KB
/
Copy pathpillar.example
File metadata and controls
159 lines (157 loc) · 6.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
# vi: set ft=yaml:
gitlab:
version: latest # latest or version like 14.8.3
root_password: xxxxxxxxxxxxxxxxxxx
distribution: ce # ce or ee, see https://about.gitlab.com/handbook/marketing/strategic-marketing/tiers/#history-of-ce-and-ee-distributions
domain: gitlab.example.com
acme_account: example.com # use either acme_account or ssl_certificate + ssl_certificate_key
#ssl_certificate:
# file: /etc/ssl/example.com/ssl.crt
# contents: |
# -----BEGIN CERTIFICATE-----
# ...
# -----END CERTIFICATE-----
#ssl_certificate_key:
# file: /etc/ssl/example.com/ssl.key
# contents: |
# -----BEGIN PRIVATE KEY-----
# ...
# -----END PRIVATE KEY-----
#redirect: # optional, add custom nginx config with redirect from other domain
# domain: gitlab.old-example.com
# acme_account: old-example.com # use either acme_account or ssl_certificate + ssl_certificate_key
# #ssl_certificate:
# # file: /etc/ssl/example.com/ssl.crt
# # contents: |
# # -----BEGIN CERTIFICATE-----
# # ...
# # -----END CERTIFICATE-----
# #ssl_certificate_key:
# # file: /etc/ssl/example.com/ssl.key
# # contents: |
# # -----BEGIN PRIVATE KEY-----
# # ...
# # -----END PRIVATE KEY-----
#nginx_configs: # optional, deploy arbitrary configs to /etc/gitlab/nginx/conf.d/
# custom-redirect.conf: |
# server {
# listen 80;
# listen 443 ssl;
# server_name old.example.com;
# ssl_certificate /etc/ssl/old.example.com/ssl.crt;
# ssl_certificate_key /etc/ssl/old.example.com/ssl.key;
# return 301 https://gitlab.example.com$request_uri;
# }
# # Use together with config_additions: nginx['default_server_enabled'] = false
# # to block direct access via server IP (returns 403 instead of showing GitLab).
# # ssl_reject_handshake drops the TLS handshake for HTTPS without needing a cert.
# default-server.conf: |
# server {
# listen 80 default_server;
# listen 443 ssl default_server;
# ssl_reject_handshake on;
# server_name _;
# return 403;
# }
mattermost: # optional, enable bundled mattermost instance
domain: mattermost.example.com
acme_account: example.com
#ssl_certificate:
# file: /etc/ssl/example.com/ssl.crt
# contents: |
# -----BEGIN CERTIFICATE-----
# ...
# -----END CERTIFICATE-----
#ssl_certificate_key:
# file: /etc/ssl/example.com/ssl.key
# contents: |
# -----BEGIN PRIVATE KEY-----
# ...
# -----END PRIVATE KEY-----
pages: # optional, enable pages
domain: pages.example.com
acme_account: example.com
namespace_in_path: True # setting for gitlab_pages['namespace_in_path']
#ssl_certificate:
# file: /etc/ssl/example.com/ssl.crt
# contents: |
# -----BEGIN CERTIFICATE-----
# ...
# -----END CERTIFICATE-----
#ssl_certificate_key:
# file: /etc/ssl/example.com/ssl.key
# contents: |
# -----BEGIN PRIVATE KEY-----
# ...
# -----END PRIVATE KEY-----
#redirect: # optional, add custom nginx config with redirect from other domain to the pages
# domain: gitlab.old-example.com
# acme_account: old-example.com # use either acme_account or ssl_certificate + ssl_certificate_key
# #ssl_certificate:
# # file: /etc/ssl/example.com/ssl.crt
# # contents: |
# # -----BEGIN CERTIFICATE-----
# # ...
# # -----END CERTIFICATE-----
# #ssl_certificate_key:
# # file: /etc/ssl/example.com/ssl.key
# # contents: |
# # -----BEGIN PRIVATE KEY-----
# # ...
# # -----END PRIVATE KEY-----
google_oauth2:
app_id: xxxxxxxxxxxx-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.apps.googleusercontent.com
app_secret: xxxxxxxxxxxxxxxxxxxxxxxx
usage_ping_enabled: 'false'
monitoring_whitelist: ['127.0.0.0/8', '1.2.3.4/32']
smtp:
address: smtp.gmail.com
port: 587
user_name: gitlab@example.com
password: xxxxxxxxxxxxxxxxxxxxx
domain: smtp.gmail.com
email_from: gitlab@example.com
incoming_email:
address: gitlab+%{key}@example.com
email: gitlab@example.com
password: xxxxxxxxxxxxxxxxxxxxx
host: imap.gmail.com
port: 993
mailbox_name: inbox
postgresql:
md5_auth_cidr_addresses: "1.2.3.4/32 2.3.4.5/32"
sql_user_password: xxxxxxxxxxxxxxxxxxxxxxxxxxxxx
cron:
backup_cmd: "find /var/backups/gitlab_backups -name '*_gitlab_backup.tar' -delete >/dev/null; gitlab-backup create SKIP=registry >/dev/null"
registry_garbage_collect_cmd: "gitlab-ctl registry-garbage-collect -m >/dev/null"
# double \\ is for salt escape of escape
clean_job_artifacts_cmd: 'find /var/lib/gitlab_artifacts -type f \\( -name job.log -o -name artifacts.zip -o -name metadata.gz \\) -mtime +30 -delete -exec sleep 0.001 \\; >/dev/null; find /var/lib/gitlab_artifacts -mindepth 1 -type d -empty -delete -exec sleep 0.001 \\; >/dev/null'
#config_additions: |
# sidekiq['queue_groups'] = ['*'] * 8 # https://docs.gitlab.com/ee/administration/sidekiq/extra_sidekiq_processes.html
# sidekiq['max_concurrency'] = 10 # has been deprecated since 16.9 and was removed in 17.0. Starting with GitLab 17.0, `sidekiq['max_concurrency']` will be removed.
# # Disable bundled default_server so a custom one can be defined via nginx_configs.
# # Required when adding your own default_server block (e.g. the 403 catch-all above).
# nginx['default_server_enabled'] = false
post_install: |
#!/bin/bash
echo "run post install script"
# example for rsnapshot_backup
rsnapshot_backup:
sources:
gitlab1.example.com:
- type: RSYNC_SSH
data:
- UBUNTU
- /opt/gitlab
- /opt/acme
- /var/backups/gitlab_backups
#- /var/lib/gitlab_docker_registry
#- /var/lib/gitlab_artifacts
#- /var/opt/gitlab/mattermost
checks:
- type: .backup
backups:
- host: gitlab1.example.com
path: /var/backups/gitlab1.example.com
- host: backup1.example.com
path: /var/backups/gitlab1.example.com