{"id":35591347,"url":"https://github.com/hiall-fyi/pve-secure-gitlab-lxc","last_synced_at":"2026-04-03T13:04:23.549Z","repository":{"id":331856440,"uuid":"1127806622","full_name":"hiall-fyi/pve-secure-gitlab-lxc","owner":"hiall-fyi","description":"Production-ready, security-hardened GitLab CE installation script for Proxmox LXC containers","archived":false,"fork":false,"pushed_at":"2026-01-11T11:09:52.000Z","size":38,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-01-11T15:56:32.945Z","etag":null,"topics":["automation","bash-script","deployment","devops","gitlab","gitlab-ce","homelab","infrastructure","installation-script","letsencrypt","linux","lxc","lxc-container","proxmox","proxmox-ve","security","security-hardening","self-hosted","ssl","ubuntu"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/hiall-fyi.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-01-04T16:24:16.000Z","updated_at":"2026-01-11T11:09:46.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/hiall-fyi/pve-secure-gitlab-lxc","commit_stats":null,"previous_names":["hiall-fyi/pve-secure-gitlab-lxc"],"tags_count":4,"template":false,"template_full_name":null,"purl":"pkg:github/hiall-fyi/pve-secure-gitlab-lxc","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hiall-fyi%2Fpve-secure-gitlab-lxc","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hiall-fyi%2Fpve-secure-gitlab-lxc/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hiall-fyi%2Fpve-secure-gitlab-lxc/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hiall-fyi%2Fpve-secure-gitlab-lxc/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/hiall-fyi","download_url":"https://codeload.github.com/hiall-fyi/pve-secure-gitlab-lxc/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hiall-fyi%2Fpve-secure-gitlab-lxc/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28399632,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-13T14:36:09.778Z","status":"ssl_error","status_checked_at":"2026-01-13T14:35:19.697Z","response_time":56,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["automation","bash-script","deployment","devops","gitlab","gitlab-ce","homelab","infrastructure","installation-script","letsencrypt","linux","lxc","lxc-container","proxmox","proxmox-ve","security","security-hardening","self-hosted","ssl","ubuntu"],"created_at":"2026-01-04T23:16:46.011Z","updated_at":"2026-04-03T13:04:23.536Z","avatar_url":"https://github.com/hiall-fyi.png","language":"Shell","funding_links":["https://buymeacoffee.com/hiallfyi"],"categories":[],"sub_categories":[],"readme":"# Proxmox LXC GitLab CE — Secure Installation Script\n\n\u003cdiv align=\"center\"\u003e\n\n\u003c!-- Platform Badges --\u003e\n![Proxmox](https://img.shields.io/badge/Proxmox-VE%208.x-E57000?style=for-the-badge\u0026logo=proxmox\u0026logoColor=white) ![GitLab CE](https://img.shields.io/badge/GitLab-CE-FC6D26?style=for-the-badge\u0026logo=gitlab\u0026logoColor=white) ![Ubuntu](https://img.shields.io/badge/Ubuntu-24.04%20LXC-E95420?style=for-the-badge\u0026logo=ubuntu\u0026logoColor=white) ![Security](https://img.shields.io/badge/Security-Hardened-00C853?style=for-the-badge\u0026logo=security\u0026logoColor=white)\n\n\u003c!-- Status Badges --\u003e\n![Version](https://img.shields.io/badge/Version-1.3.0-purple?style=for-the-badge) ![License](https://img.shields.io/badge/License-MIT-blue?style=for-the-badge) ![shellcheck](https://img.shields.io/badge/shellcheck-passing-brightgreen?style=for-the-badge\u0026logo=gnu-bash\u0026logoColor=white) ![Maintained](https://img.shields.io/badge/Maintained-Yes-green.svg?style=for-the-badge)\n\n\u003c!-- Community Badges --\u003e\n![GitHub stars](https://img.shields.io/github/stars/hiall-fyi/pve-secure-gitlab-lxc?style=for-the-badge\u0026logo=github) ![GitHub forks](https://img.shields.io/github/forks/hiall-fyi/pve-secure-gitlab-lxc?style=for-the-badge\u0026logo=github) ![GitHub issues](https://img.shields.io/github/issues/hiall-fyi/pve-secure-gitlab-lxc?style=for-the-badge\u0026logo=github) ![GitHub last commit](https://img.shields.io/github/last-commit/hiall-fyi/pve-secure-gitlab-lxc?style=for-the-badge\u0026logo=github)\n\n\u003c!-- Support --\u003e\n[![Buy Me A Coffee](https://img.shields.io/badge/Support-Buy%20Me%20A%20Coffee-FFDD00?style=for-the-badge\u0026logo=buy-me-a-coffee\u0026logoColor=black)](https://buymeacoffee.com/hiallfyi)\n\n**🚀 One command to go from bare Proxmox host to a fully hardened, production-ready GitLab CE — in about 15 minutes.**\n\n**No manual steps, no missed security settings, no guesswork. Just run the script and start pushing code.**\n\n[Quick Start](#-quick-start) • [Features](#-features) • [Storage Guide](#-storage-configuration-guide) • [Troubleshooting](#-troubleshooting) • [Support](#-support)\n\n\u003c/div\u003e\n\n---\n\n## Why This Script?\n\nSetting up GitLab CE on Proxmox the manual way means creating an LXC container, configuring storage, installing packages, generating SSL certificates, hardening nginx, setting up a firewall, and hoping you didn't miss a step. It's easily a couple of hours of work, and one wrong setting can leave your instance exposed.\n\nThis script does all of that in a single command. You answer a few questions (or pass flags for automation), and 15 minutes later you have a running GitLab with security hardening that would take most admins a full afternoon to configure by hand.\n\n- **One command** — from bare Proxmox host to running GitLab, fully configured\n- **Security by default** — unprivileged container, TLS 1.2/1.3, security headers, firewall, rate limiting — all automatic\n- **Flexible storage** — Simple Mode (one disk, recommended) or Advanced Mode (separate volumes for compliance)\n- **Smart defaults** — auto-detects VMID, gateway, DNS; just press Enter for standard setups\n- **SSL options** — self-signed (works instantly for internal use) or Let's Encrypt (for public domains)\n\n---\n\n## Quick Start\n\n**Prerequisites:** Proxmox VE 7.0+, 150GB+ available LVM space, root access. Ubuntu 24.04 LXC template auto-downloads if missing.\n\n### 1. Download\n\n```bash\nwget https://raw.githubusercontent.com/hiall-fyi/pve-secure-gitlab-lxc/main/pve-secure-gitlab-lxc.sh\nchmod +x pve-secure-gitlab-lxc.sh\n```\n\n### 2. Run\n\n\n**Interactive Mode** (recommended for first-time users):\n\n```bash\n./pve-secure-gitlab-lxc.sh\n```\n\n**Non-Interactive — Simple Mode** (recommended):\n\n```bash\n./pve-secure-gitlab-lxc.sh \\\n  --vmid 110 --hostname gitlab --cpu 4 --ram 8192 \\\n  --storage-mode simple --rootfs-size 50 \\\n  --ip 192.168.1.110/24 --gateway 192.168.1.1 --dns 8.8.8.8 \\\n  --url https://gitlab.local --storage local-lvm\n```\n\n**Non-Interactive — Advanced Mode**:\n\n```bash\n./pve-secure-gitlab-lxc.sh \\\n  --vmid 120 --hostname gitlab --cpu 4 --ram 8192 \\\n  --storage-mode advanced --bootdisk 20 --datadisk 100 --logdisk 10 --configdisk 2 \\\n  --ip 192.168.1.120/24 --gateway 192.168.1.1 --dns 8.8.8.8 \\\n  --url https://gitlab.local --storage local-lvm\n```\n\n### 3. Access GitLab\n\n1. Visit your GitLab URL (e.g., `https://gitlab.local`)\n2. Login with username `root` and the password displayed at installation completion\n3. **Change the root password immediately!**\n\n---\n\n## Features\n\n### What You Get\n\n- **Fully updated system** — both your Proxmox host and the new container get the latest security patches before GitLab is installed\n- **Isolated container** — GitLab runs in an unprivileged LXC container, so a compromise inside GitLab can't easily reach your host\n- **SSL out of the box** — choose self-signed (works instantly for internal use) or Let's Encrypt (for public-facing setups)\n- **Pick your GitLab version** — install the latest stable release, or pin a specific version for reproducibility\n- **Multiple network bridges** — works with vmbr0, vmbr1, vmbr3, or whatever your network setup looks like\n- **Safe re-runs** — if a previous install failed, the script detects leftover resources and offers to clean them up\n- **Smart defaults** — auto-detects your next available VMID, gateway, and DNS, so you can just press Enter through most prompts\n\n### Security (configured automatically)\n\nYour GitLab instance is hardened from the start — no manual configuration needed:\n\n- **Unprivileged container** — GitLab can't access your host even if compromised\n- **TLS 1.2/1.3 only** — older, insecure protocols are disabled\n- **HTTPS enforced** — HTTP requests are automatically redirected to HTTPS\n- **Security headers** — HSTS, clickjacking protection, content-type sniffing prevention, and XSS filtering are all enabled\n- **Rate limiting** — brute-force login attempts are throttled automatically\n- **Firewall** — only SSH (22), HTTP (80), and HTTPS (443) are open; everything else is blocked\n\n### Storage\n\n- **Simple Mode** (default) — one disk, all GitLab data in one place. Easy to manage, easy to expand. Recommended for most users.\n- **Advanced Mode** — separate volumes for config, logs, and data. Useful if you need independent snapshots or have compliance requirements.\n\n---\n\n## Storage Configuration Guide\n\n### Quick Comparison\n\n| Feature | Simple Mode ⭐ | Advanced Mode |\n|---------|---------------|---------------|\n| **Complexity** | Low | Medium |\n| **Setup** | 1 parameter | 4 parameters |\n| **Management** | Easy | Requires planning |\n| **Flexibility** | High (auto-sharing) | Medium (fixed sizes) |\n| **Backup** | Single snapshot | Multiple snapshots |\n| **Best For** | 90% of users | Enterprise/Compliance |\n\n**Recommendation**: Start with Simple Mode. You can always migrate to Advanced Mode later.\n\n### Sizing Recommendations\n\n**Simple Mode:**\n\n| Team Size | Recommended Size | Use Case |\n|-----------|------------------|----------|\n| 1-10 users | 30-50 GB | Small team, light usage |\n| 10-50 users | 50-100 GB | Medium team, moderate CI/CD |\n| 50+ users | 100-200+ GB | Large team, heavy CI/CD |\n\n**Advanced Mode:**\n\n| Team Size | Boot | Config | Logs | Data | Total |\n|-----------|------|--------|------|------|-------|\n| 1-10 users | 20G | 2G | 10G | 50G | 82G |\n| 10-50 users | 25G | 3G | 15G | 150G | 193G |\n| 50+ users | 30G | 5G | 20G | 300G | 355G |\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eMonitoring \u0026 Expanding Storage\u003c/strong\u003e\u003c/summary\u003e\n\n**Simple Mode:**\n\n```bash\n# Check total usage\npct exec \u003cVMID\u003e -- df -h /\n\n# Expand (add 50GB)\npct stop \u003cVMID\u003e\nlvextend -L +50G /dev/pve/vm-\u003cVMID\u003e-disk-0\ne2fsck -f /dev/pve/vm-\u003cVMID\u003e-disk-0\nresize2fs /dev/pve/vm-\u003cVMID\u003e-disk-0\npct start \u003cVMID\u003e\n```\n\n**Advanced Mode:**\n\n```bash\n# Check all volumes\npct exec \u003cVMID\u003e -- df -h\n\n# Expand data volume (add 50GB)\nlvextend -L +50G /dev/pve/vm-\u003cVMID\u003e-gitlab-opt\npct exec \u003cVMID\u003e -- resize2fs /dev/mapper/pve-vm--\u003cVMID\u003e--gitlab--opt\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eMigration: Advanced → Simple\u003c/strong\u003e\u003c/summary\u003e\n\n⚠️ **Backup first!**\n\n```bash\n# 1. Backup GitLab\npct exec \u003cVMID\u003e -- gitlab-backup create\n\n# 2. Stop container\npct stop \u003cVMID\u003e\n\n# 3. Remove mount points from config\nvi /etc/pve/lxc/\u003cVMID\u003e.conf\n# Delete lines: mp0, mp1, mp2\n\n# 4. Start and reconfigure\npct start \u003cVMID\u003e\npct exec \u003cVMID\u003e -- gitlab-ctl reconfigure\n\n# 5. Remove old LVs and expand root\nlvremove -f /dev/pve/vm-\u003cVMID\u003e-gitlab-etc\nlvremove -f /dev/pve/vm-\u003cVMID\u003e-gitlab-log\nlvremove -f /dev/pve/vm-\u003cVMID\u003e-gitlab-opt\npct stop \u003cVMID\u003e\nlvextend -L +15G /dev/pve/vm-\u003cVMID\u003e-disk-0\ne2fsck -f /dev/pve/vm-\u003cVMID\u003e-disk-0\nresize2fs /dev/pve/vm-\u003cVMID\u003e-disk-0\npct start \u003cVMID\u003e\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eCleanup Commands\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Clean old CI/CD artifacts (older than 30 days)\npct exec \u003cVMID\u003e -- gitlab-rake gitlab:cleanup:orphan_job_artifact_files\n\n# Clean old logs\npct exec \u003cVMID\u003e -- gitlab-ctl cleanup-logs\n\n# Clean old backups (older than 7 days)\npct exec \u003cVMID\u003e -- find /var/opt/gitlab/backups/ -name \"*.tar\" -mtime +7 -delete\n```\n\n\u003c/details\u003e\n\n---\n\n## SSL Certificate Configuration\n\n### Self-Signed (Default)\n\nBest for internal networks, development, testing. Works immediately, no domain registration needed, 10-year validity.\n\n```bash\n./pve-secure-gitlab-lxc.sh ... --ssl-type self-signed\n# or simply omit --ssl-type (self-signed is default)\n```\n\n### Let's Encrypt\n\nBest for public-facing instances. Requires valid public domain, ports 80/443 accessible from internet.\n\n```bash\n./pve-secure-gitlab-lxc.sh ... --url https://gitlab.example.com --ssl-type letsencrypt\n```\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eLet's Encrypt Troubleshooting\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Check certificate status\npct exec \u003cVMID\u003e -- gitlab-ctl status\n\n# View Let's Encrypt logs\npct exec \u003cVMID\u003e -- cat /var/log/gitlab/nginx/error.log\n\n# Manually trigger certificate renewal\npct exec \u003cVMID\u003e -- gitlab-ctl renew-le-certs\n```\n\n\u003c/details\u003e\n\n---\n\n## Usage Examples\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eSmall Team — Simple Mode (5-10 users)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n./pve-secure-gitlab-lxc.sh \\\n  --vmid 110 --hostname gitlab --cpu 4 --ram 8192 \\\n  --storage-mode simple --rootfs-size 50 \\\n  --ip 192.168.1.110/24 --gateway 192.168.1.1 --dns 8.8.8.8 \\\n  --url https://gitlab.local --storage local-lvm\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eMedium Team — Simple Mode (20-50 users)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n./pve-secure-gitlab-lxc.sh \\\n  --vmid 120 --hostname gitlab-dev --cpu 6 --ram 12288 \\\n  --storage-mode simple --rootfs-size 100 \\\n  --ip 192.168.1.120/24 --gateway 192.168.1.1 --dns 8.8.8.8 \\\n  --url https://gitlab.dev.local --storage local-lvm\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eEnterprise — Advanced Mode (compliance requirements)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n./pve-secure-gitlab-lxc.sh \\\n  --vmid 130 --hostname gitlab-prod --cpu 8 --ram 16384 \\\n  --storage-mode advanced --bootdisk 30 --datadisk 300 --logdisk 20 --configdisk 5 \\\n  --ip 192.168.1.130/24 --gateway 192.168.1.1 --dns 8.8.8.8 \\\n  --url https://gitlab.company.com --storage local-lvm\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003ePublic Deployment with Let's Encrypt\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n./pve-secure-gitlab-lxc.sh \\\n  --vmid 150 --hostname gitlab --cpu 4 --ram 8192 \\\n  --storage-mode simple --rootfs-size 100 \\\n  --ip 203.0.113.150/24 --gateway 203.0.113.1 --dns 8.8.8.8 \\\n  --url https://gitlab.example.com --storage local-lvm \\\n  --ssl-type letsencrypt\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003ev1.0.0 Compatibility (existing automation scripts)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Old v1.0.0 command still works — automatically uses Advanced Mode\n./pve-secure-gitlab-lxc.sh \\\n  --vmid 140 --hostname gitlab --cpu 4 --ram 8192 \\\n  --bootdisk 20 --datadisk 100 --logdisk 10 --configdisk 2 \\\n  --ip 192.168.1.140/24 --gateway 192.168.1.1 --dns 8.8.8.8 \\\n  --url https://gitlab.local --storage local-lvm\n```\n\n\u003c/details\u003e\n\n---\n\n## Post-Installation\n\n### First Login\n\n1. Open your GitLab URL in a browser\n2. Login with username **root** and the password shown at the end of the installation\n3. **Change the root password immediately** — the initial password is also saved to a log file on the host, so treat it as temporary\n\n### What to Do Next\n\n1. **Change Root Password** — click your avatar (top-right) → Edit Profile → Password\n2. **Enable 2FA** — Edit Profile → Account → Two-Factor Authentication\n3. **Create your first users** — Admin Area (wrench icon) → Users → New User\n4. **Add SSH keys** — Edit Profile → SSH Keys — so you can push/pull without typing passwords\n\n### Self-Signed Certificate — Browser Warning\n\nYour browser will show a security warning. This is normal for self-signed certificates.\n\n- **Quick**: Click \"Advanced\" → \"Proceed to site\"\n- **Proper**: Add certificate to trusted store:\n\n```bash\npct exec \u003cVMID\u003e -- cat /etc/gitlab/ssl/\u003chostname\u003e.crt \u003e gitlab.crt\n# macOS\nsudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain gitlab.crt\n# Linux\nsudo cp gitlab.crt /usr/local/share/ca-certificates/ \u0026\u0026 sudo update-ca-certificates\n```\n\n---\n\n## Version Management\n\nYou can pin a specific GitLab version during installation, or upgrade later inside the container:\n\n```bash\n# Install a specific version\n./pve-secure-gitlab-lxc.sh --vmid 110 ... --version 16.8.1\n\n# Upgrade GitLab later\npct enter \u003cVMID\u003e\ngitlab-backup create          # always backup first!\napt update\napt upgrade gitlab-ce         # or pin: apt install gitlab-ce=16.9.0-ce.0\ngitlab-ctl reconfigure\ngitlab-ctl restart\n```\n\n---\n\n## Management Commands\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eGitLab Service Management\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\npct exec \u003cVMID\u003e -- gitlab-ctl status          # Check all services\npct exec \u003cVMID\u003e -- gitlab-ctl restart         # Restart all services\npct exec \u003cVMID\u003e -- gitlab-ctl reconfigure     # Reconfigure GitLab\npct exec \u003cVMID\u003e -- gitlab-ctl tail            # View live logs\npct exec \u003cVMID\u003e -- gitlab-ctl tail nginx      # View specific service logs\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eContainer Management\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\npct enter \u003cVMID\u003e              # Enter container\npct status \u003cVMID\u003e             # Check status\npct stop \u003cVMID\u003e               # Stop\npct start \u003cVMID\u003e              # Start\npct reboot \u003cVMID\u003e             # Reboot\npct exec \u003cVMID\u003e -- df -h      # Check disk usage\npct exec \u003cVMID\u003e -- free -h    # Check memory usage\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eBackup and Restore\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Manual backup\npct exec \u003cVMID\u003e -- gitlab-backup create\n\n# List backups\npct exec \u003cVMID\u003e -- ls -lh /var/opt/gitlab/backups/\n\n# Restore\npct exec \u003cVMID\u003e -- gitlab-ctl stop puma\npct exec \u003cVMID\u003e -- gitlab-ctl stop sidekiq\npct exec \u003cVMID\u003e -- gitlab-backup restore BACKUP=\u003ctimestamp\u003e\npct exec \u003cVMID\u003e -- gitlab-ctl restart\npct exec \u003cVMID\u003e -- gitlab-rake gitlab:check SANITIZE=true\n\n# Automated daily backup (add to crontab inside container)\n0 2 * * * /opt/gitlab/bin/gitlab-backup create CRON=1\n0 3 * * * find /var/opt/gitlab/backups/ -name \"*.tar\" -mtime +7 -delete\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eIdentifying Script-Created Resources\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\npct list | grep -i gitlab                              # List containers\npct config \u003cVMID\u003e | grep description                   # Check fingerprint\nlvs -o lv_name,lv_tags | grep gitlab-ce-secure-install # List tagged LVs\n```\n\n\u003c/details\u003e\n\n---\n\n## Performance Tuning\n\nIf GitLab feels slow, you can tune resource allocation. Enter the container and edit `/etc/gitlab/gitlab.rb`:\n\n| Team Size | shared_buffers | max_concurrency | worker_processes | What it helps |\n|-----------|---------------|-----------------|------------------|---------------|\n| \u003c 10 users | 256MB | 10 | 2 | Default — good for small teams |\n| 10-50 users | 512MB | 20 | 4 | Faster CI/CD and page loads |\n| \u003e 50 users | 1GB | 30 | 8 | Heavy usage with many concurrent users |\n\nAfter changes: `gitlab-ctl reconfigure \u0026\u0026 gitlab-ctl restart`\n\n---\n\n## Troubleshooting\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eGitLab service won't start\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\npct exec \u003cVMID\u003e -- gitlab-ctl tail\npct exec \u003cVMID\u003e -- gitlab-rake gitlab:check\npct exec \u003cVMID\u003e -- gitlab-ctl reconfigure\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eCannot access GitLab\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\npct exec \u003cVMID\u003e -- ufw status\npct exec \u003cVMID\u003e -- gitlab-ctl status nginx\npct exec \u003cVMID\u003e -- ls -l /etc/gitlab/ssl/\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eOut of memory\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\npct set \u003cVMID\u003e -memory 16384\npct reboot \u003cVMID\u003e\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eDisk space issues\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\npct exec \u003cVMID\u003e -- df -h\npct exec \u003cVMID\u003e -- gitlab-ctl cleanup-logs\npct exec \u003cVMID\u003e -- find /var/opt/gitlab/backups/ -name \"*.tar\" -mtime +7 -delete\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eReset root password\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\npct enter \u003cVMID\u003e\ngitlab-rails console\n# In console:\nuser = User.find_by(username: 'root')\nuser.password = 'new_password'\nuser.password_confirmation = 'new_password'\nuser.save!\nexit\n```\n\n\u003c/details\u003e\n\nFor other issues, check the installation log at `/var/log/gitlab-ce-install-\u003cVMID\u003e.log` or [open an issue on GitHub](https://github.com/hiall-fyi/pve-secure-gitlab-lxc/issues).\n\n---\n\n## Keeping Your GitLab Secure\n\nThe script sets up a solid security baseline, but there are a few things only you can do:\n\n- **Change the root password right after install** — the initial password is shown in the terminal and saved to a log file on the host\n- **Turn on 2FA for all users** — especially admin accounts\n- **Use SSH keys** — disable password-based Git access when possible\n- **Keep things updated** — run `apt upgrade gitlab-ce` inside the container quarterly, and update host packages monthly\n- **Set up automated backups** — see the Backup and Restore section above. A daily backup with 7-day retention is a good starting point\n- **Restrict network access** — if your GitLab is internal-only, consider limiting access to your LAN IP range in the firewall\n\n---\n\n## Resources\n\n- [GitLab Official Documentation](https://docs.gitlab.com/)\n- [GitLab CE Installation Guide](https://about.gitlab.com/install/)\n- [Proxmox LXC Documentation](https://pve.proxmox.com/wiki/Linux_Container)\n- [GitLab Backup and Restore](https://docs.gitlab.com/ee/raketasks/backup_restore.html)\n\n---\n\n## Support\n\n1. Check installation log: `/var/log/gitlab-ce-install-\u003cVMID\u003e.log`\n2. Check GitLab logs: `pct exec \u003cVMID\u003e -- gitlab-ctl tail`\n3. Check container logs: `pct exec \u003cVMID\u003e -- journalctl -xe`\n4. [Open an issue on GitHub](https://github.com/hiall-fyi/pve-secure-gitlab-lxc/issues)\n\n---\n\n## License\n\n**MIT License** — Free to use, modify, and distribute. See [LICENSE](LICENSE) for full details.\n\n**Made with ❤️ by Joe Yiu ([@hiall-fyi](https://github.com/hiall-fyi))**\n\n---\n\n## Contributing\n\nContributions welcome!\n\n1. Fork the repository\n2. Create feature branch (`git checkout -b feature/AmazingFeature`)\n3. Commit changes (`git commit -m 'Add AmazingFeature'`)\n4. Push to branch (`git push origin feature/AmazingFeature`)\n5. Open a Pull Request\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\n[![Star History Chart](https://api.star-history.com/svg?repos=hiall-fyi/pve-secure-gitlab-lxc\u0026type=Date)](https://star-history.com/#hiall-fyi/pve-secure-gitlab-lxc\u0026Date)\n\n\u003c/div\u003e\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eDisclaimer\u003c/strong\u003e\u003c/summary\u003e\n\nThis project is not affiliated with, endorsed by, or connected to GitLab Inc. or Proxmox Server Solutions GmbH. GitLab and the GitLab logo are registered trademarks of GitLab Inc. Proxmox and the Proxmox logo are registered trademarks of Proxmox Server Solutions GmbH.\n\nThis script is provided \"as is\" without warranty of any kind. Use at your own risk.\n\n\u003c/details\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhiall-fyi%2Fpve-secure-gitlab-lxc","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhiall-fyi%2Fpve-secure-gitlab-lxc","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhiall-fyi%2Fpve-secure-gitlab-lxc/lists"}