Skip to main content
Version: 0.5.4

GitLab CE on Aruba Cloud

Deploy GitLab Community Edition — a complete DevOps platform with Git hosting, CI/CD, issue tracking, and container registry — on Aruba Cloud using Terraform and cloud-init.

Provider version: arubacloud/arubacloud ~> 0.5 | Terraform: ≥ 1.9


Introduction​

GitLab CE is a self-hosted alternative to GitHub and GitHub Actions. This example deploys:

  • GitLab CE via the official Omnibus package on a single VM
  • Automatic Let's Encrypt TLS when a letsencrypt_email is provided
  • Separate SSH port 2222 for git operations (port 22 reserved for admin access)
  • Web UI, CI/CD runners (bring your own), and container registry ready

DNS first: With HTTPS, GitLab requests a Let's Encrypt certificate during install. Set your A record for gitlab_hostname → VM public IP before running terraform apply.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectgitlab-prodProject container
arubacloud_vpcgitlab-prod-vpcVirtual Private Cloud
arubacloud_subnetgitlab-prod-subnetBasic subnet
arubacloud_securitygroupgitlab-prod-vm-sgSecurity group
arubacloud_securityrulegitlab-prod-vm-sshAdmin SSH ingress (22)
arubacloud_securityrulegitlab-prod-vm-httpHTTP ingress (80)
arubacloud_securityrulegitlab-prod-vm-httpsHTTPS ingress (443)
arubacloud_securityrulegitlab-prod-vm-gitsshGit SSH ingress (2222)
arubacloud_elasticipgitlab-prod-vm-eipVM public IP
arubacloud_blockstoragegitlab-prod-boot100 GB boot disk (Performance)
arubacloud_keypairgitlab-prod-keypairSSH public key
arubacloud_cloudservergitlab-prod-vmCloudServer VM

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO8A16 — 8 vCPU / 16 GB~€80
Boot disk100 GB Performance~€15
Elastic IP—~€3
Total~€98/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 0.5
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair
  • A domain name with DNS control (required for HTTPS / Let's Encrypt)

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content
gitlab_hostnamePublic FQDN for GitLab (e.g. gitlab.example.com)
gitlab_root_passwordInitial password for the root user (min 8 chars)

Optional​

VariableDefaultDescription
letsencrypt_email""Email for Let's Encrypt — enables auto-TLS when set
app_name"gitlab"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO8A16"CloudServer flavor (min recommended)
vm_disk_size_gb100Boot disk size in GB (min 50)
ssh_cidr"0.0.0.0/0"CIDR for admin SSH access

Outputs​

OutputDescription
gitlab_urlGitLab web UI URL
vm_public_ipPublic IP address of the VM
ssh_commandSSH admin command
git_ssh_cloneExample SSH clone URL (port 2222)

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/gitlab

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Set gitlab_hostname to your FQDN. Set letsencrypt_email to enable HTTPS with auto-TLS.

3. Point DNS before applying (HTTPS only)​

If using letsencrypt_email, create the DNS A record for gitlab_hostname → Elastic IP before running apply.

4. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 5–10 minutes (longer with Let's Encrypt).

5. Log in​

Navigate to the gitlab_url output and log in with:

  • Username: root
  • Password: value of gitlab_root_password

SSH Git Clone​

GitLab CE listens for git SSH operations on port 2222 (port 22 is reserved for admin SSH). Configure your SSH client:

Host gitlab.example.com
HostName gitlab.example.com
Port 2222
User git

Then clone normally with git clone git@gitlab.example.com:<user>/<project>.git.


References​