How can I activate Let's Encrypt for my GitLab instance running behind a reverse-proxy?
At the moment I receive the following error:
letsencrypt_certificate[domain.com] (letsencrypt::http_authorization line 6) had an error: RuntimeError: acme_certificate[staging] (/opt/gitlab/embedded/cookbooks/cache/cookbooks/letsencrypt/resources/certificate.rb line 41) had an error: RuntimeError: ruby_block[create certificate for domain.com] (/opt/gitlab/embedded/cookbooks/cache/cookbooks/acme/resources/certificate.rb line 108) had an error: RuntimeError: [domain.com] Validation failed, unable to request certificate, Errors: [{url: https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/531808698/v0nVaQ, status: invalid, error: {"type"=>"urn:ietf:params:acme:error:connection", "detail"=>"Fetching (http:)//domain.com/.well-known/acme-challenge/41JcBNOd3Exv_AEcN9DzgiXUdynQWp5Ip_G8XfX9Wfo: Timeout during connect (likely firewall problem)", "status"=>400}} ]
The topology setup looks like this:
- request on https / http hitting haProxy
- redirects to internal GitLab instance on port 443
Setup was done within docker container according to official documentation, but I think I miss something here.
What am I doing wrong?