If you're self-hosting gitlab-ce (which should really be open to internal traffic only) and want one more layer of protection from all this stuff, it's easy to throw it behind http basic auth. In your gitlab.rb:
nginx['custom_gitlab_server_config'] = "auth_basic 'Restricted';\n auth_basic_user_file /etc/gitlab/.htpasswd;\n location ^~ /.well-known { root /var/www/letsencrypt; auth_basic off;}"