CuraDevOps

tag: Gitlab · 17 items

2026-08-27 · GitLab Blog · source ↗ #agent-scm#git-scalability#gitlab
  • Platform/SRE — Skip
  • CI/CD — Skip
  • Leader — Learn: GitLab’s own data — 40% more CI/CD pipelines, 50% more code pushes, 500% larger codebases over one year — frames why agent-scale SCM is a near-term architectural concern; worth tracking as a signal when evaluating long-term SCM platform direction, though no vendor-neutral decision is actionable yet.
2026-08-21 · GitLab Blog · source ↗ #gitlab#ai-gateway#data-residency
  • Platform/SRE — Plan: If your org runs GitLab Dedicated, the AI Gateway for Duo Agent Platform is now deployable inside your single-tenant environment, keeping AI-processed data in your chosen AWS region. Evaluate this quarter whether to enable it as part of your agentic DevOps rollout.
  • CI/CD — Skip
  • Leader — Learn: Organizations using GitLab Dedicated for compliance or data-residency reasons can now extend that boundary to AI agent workloads — shapes thinking on how to pursue agentic DevOps without relaxing data-sovereignty requirements.
2026-08-21 · GitLab Blog · source ↗ #gitlab#minor-release#eol
  • Platform/SRE — Plan: Teams self-hosting GitLab should plan an upgrade to 19.3 and note that it reaches EOL on 2026-11-19, meaning another upgrade cycle must be scheduled within the quarter to stay on a supported version.
  • CI/CD — Plan: Review the 19.3 release notes for any pipeline syntax, runner, or artifact-handling changes; schedule adoption before the 2026-11-19 EOL to avoid running unsupported GitLab CI infrastructure.
  • Leader — Skip
  • Signals: GitLab 19.3 reaches EOL in 90d (2026-11-19)
2026-08-21 · GitLab Blog · source ↗ #gitlab#automation#ai-assisted
  • Platform/SRE — Skip
  • CI/CD — Plan: New GA capability in GitLab 19.3 that lets domain experts author Custom Flows via natural language instead of learning the Flow Registry YAML schema; worth evaluating this quarter to reduce the bottleneck between process knowledge and automation authorship.
  • Leader — Skip
  • Signals: GitLab 19.3 reaches EOL in 90d (2026-11-19)
2026-08-21 · GitLab Blog · source ↗ #gitlab#sast#security
  • Platform/SRE — Plan: Teams self-hosting GitLab should note that 19.3 reaches EOL 2026-11-19 (~90 days); plan an upgrade to 19.4 or later before that date to stay on a supported version.
  • CI/CD — Learn: GitLab 19.3 GA adds bulk false-positive dismissal and agentic SAST remediation for existing vulnerability backlogs — worth evaluating if your pipelines already produce GitLab SAST findings, but no urgent action is required.
  • Leader — Skip
  • Signals: GitLab 19.3 reaches EOL in 90d (2026-11-19)
  • Platform/SRE — Learn: A practical walkthrough integrating OpenTofu, GitLab CI/CD, and Argo CD into a unified IaC + GitOps platform pattern — useful design reference, but no GA capability change or deadline requiring action.
  • CI/CD — Learn: Illustrates how to wire GitLab pipelines to OpenTofu provisioning and Argo CD deployments end-to-end; worth reviewing as a pipeline design reference, but nothing here forces a pipeline change.
  • Leader — Skip
2026-08-18 · GitLab Blog · source ↗ #gitlab#security-patch#ci-cd
  • Platform/SRE — Plan: If running a self-managed GitLab instance, upgrade to the patched version in your release line; no public PoC or KEV listing is confirmed from the title alone, so this is urgent-but-scheduled rather than emergency.
  • CI/CD — Act: GitLab CI users on self-managed instances should upgrade to 19.2.4, 19.1.6, 19.0.8, or 18.11.11 promptly — a critical patch to the CI/CD platform itself can directly break or compromise pipelines and should be treated as an outage-level priority.
  • Leader — Skip
  • Signals: major release (19.0)
  • Platform/SRE — Skip
  • CI/CD — Learn: GitLab’s improved Scope+Offset fingerprinting reduces duplicate vulnerability findings from reformats and comment additions; worth knowing when evaluating SAST signal quality in GitLab pipelines, but no pipeline change is needed today.
  • Leader — Skip
  • Platform/SRE — Plan: This GA expansion lets platform teams consolidate Kubernetes (ESO), Terraform/OpenTofu, and Vault CLI secrets into a single OpenBao-backed store — worth evaluating this quarter as a replacement for fragmented per-tool secret stores, with no forcing deadline yet.
  • CI/CD — Learn: GitLab CI/CD secret support landed in v19.0 already; the new ESO and Terraform integrations are primarily platform-side — no pipeline changes required today, but the unified API surface is worth noting for future supply-chain design.
  • Leader — Learn: The consolidated single-store model (one audit trail, one access model across Kubernetes, IaC, and pipelines) is worth tracking as a vendor-consolidation data point when revisiting secrets-toolchain standards, but no pricing or license forcing function exists yet.
2026-08-07 · GitLab Blog · source ↗ #gitlab#confidential-ai#self-hosted
  • Platform/SRE — Plan: Teams running GitLab Self-Hosted in regulated environments can now configure the Duo AI Gateway to proxy through Privatemode’s confidential-compute backend — worth scheduling this quarter to evaluate setup and network path requirements alongside any existing compliance review.
  • CI/CD — Learn: The prospect of GitLab Duo Agent Platform driving multi-step agentic flows as native CI jobs is a meaningful design shift to track, but there are no pipeline migrations or deprecations to act on today.
  • Leader — Plan: For regulated orgs blocked from AI coding tools by IP or compliance constraints, this materially changes the vendor-risk calculus — evaluate Privatemode as a compliant model-provider path for GitLab Duo during the next planning cycle before competitors further compound their AI productivity lead.
2026-08-04 · GitHub Changelog · source ↗ #migration#github-enterprise#gitlab
  • Platform/SRE — Skip
  • CI/CD — Plan: If a GitLab-to-GitHub migration is on the roadmap, GEI reaching GA means self-serve tooling is now available for scoping the pipeline migration project.
  • Leader — Plan: If your org is evaluating consolidating from GitLab to GitHub Enterprise Cloud, the GA of self-serve migration tooling removes a key friction point worth including in the next planning cycle.
  • Signals: GA announcement
2026-08-03 · GitLab Blog · source ↗ #security#ai-coding#gitlab
  • Platform/SRE — Skip
  • CI/CD — Learn: Describes an integration pattern where Claude flags issues at authoring time and GitLab enforces controls through merge, dependency update, and infra change stages; worth tracking as AI-assisted supply-chain governance matures, but no concrete pipeline change to make today.
  • Leader — Learn: Outlines a governance model for agentic coding at scale — pairing Claude security guidance with GitLab policy enforcement — relevant for leaders setting standards around AI-assisted development, but no licensing or cost decision is triggered here.
2026-07-17 · GitLab Blog · source ↗ #gitlab#security-review#ai-assisted
  • Platform/SRE — Skip
  • CI/CD — Learn: Public beta feature worth tracking for GitLab shops — it layers intent-based analysis over existing SAST to catch authorization and workflow flaws before merge, but it’s pre-GA so nothing to enable in production pipelines yet.
  • Leader — Learn: AI-assisted logic-flaw detection is a meaningful gap-fill beyond signature-based scanners; worth monitoring as it approaches GA to assess whether it changes the org’s AppSec toolchain or reduces security-review cycle time.
  • Platform/SRE — Skip
  • CI/CD — Learn: The GA headless mode lets Duo run inside CI jobs and scripts, which could reshape how teams add AI-assisted triage or automation steps to pipelines — worth evaluating, but no migration or deadline attached.
  • Leader — Learn: For orgs already on GitLab, this signals how AI assistance is extending across the full delivery lifecycle — useful context for AI toolchain strategy discussions, but no licensing, pricing, or vendor-risk forcing function yet.
  • Signals: GA announcement
  • Platform/SRE — Skip
  • CI/CD — Learn: Beta feature that auto-opens MRs to patch vulnerable dependencies and iterates until the pipeline passes — worth evaluating once GA, but pre-GA status caps this at Learn for now.
  • Leader — Learn: Beta capability targeting the OWASP dependency backlog and compliance remediation windows (PCI-DSS/FedRAMP 30-day deadlines); monitor for GA before considering for the golden path.
  • Signals: breaking-change flagged
Learn archived GitLab 19.2 released
2026-07-17 · GitLab Blog · source ↗ #gitlab#release#ci-cd
  • Platform/SRE — Learn: GitLab 19.2 is a new minor release that may affect self-managed GitLab instances, but no summary or enrichment signals are available to identify breaking changes, security fixes, or upgrade urgency.
  • CI/CD — Learn: A new GitLab minor release typically includes CI/CD pipeline features worth evaluating, but no details are present in this item to determine whether any pipeline changes are warranted.
  • Leader — Skip
2026-07-17 · GitLab Blog · source ↗ #gitlab#agentic-workflows#ci-cd
  • Platform/SRE — Skip
  • CI/CD — Plan: Custom Flows are now GA in GitLab 19.2, enabling event-triggered, AI-driven multi-step pipeline sequences (e.g., analyze failure → generate fix → commit → notify). Teams on GitLab should evaluate whether encoding trusted delivery sequences as Flows reduces manual handoffs and pipeline runbook debt.
  • Leader — Learn: GitLab’s agentic flow model represents a meaningful shift in how AI is integrated into the delivery lifecycle — moving from single-turn chat to orchestrated, human-approved sequences. Worth tracking as input to dev-platform strategy and AI tooling evaluation, but no strategic decision is forced by this release.
  • Signals: GA announcement