September 2019 Summaries
29 posts from GitLab
Filter
Month:
Year:
Post Summaries
Back to Blog
GitLab's decision to adopt ECharts as their primary charting library stemmed from their need to streamline and accelerate their data visualization processes across the DevOps lifecycle. Initially considering D3.js, they found it too complex and time-consuming given their ambitious growth and hiring plans. After evaluating several options, GitLab chose ECharts for its robust, flexible chart types and the ability to customize and integrate with existing designs, which significantly boosted their development velocity compared to D3.js. Despite some challenges, such as language barriers in documentation, ECharts' growing international community and supportive core team have facilitated a successful partnership, enabling GitLab to expand charting capabilities from the Monitor stage to the Secure and Manage stages, thereby enhancing their product development processes.
Sep 30, 2019
758 words in the original blog post.
The text discusses the widespread use of plugins within Jenkins, highlighting both their advantages and potential drawbacks. While plugins offer extensive customization and flexibility, allowing users to tailor their Jenkins environment without significant investment in additional tools, they also introduce challenges such as security vulnerabilities, maintenance issues, and dependency management. With over 1,600 community-contributed plugins, Jenkins users must navigate potential problems, including outdated or unsupported plugins and the risk of brittle pipelines due to numerous dependencies. The text illustrates how the ease of plugin installation can lead to security concerns, as demonstrated by a CyberArk experiment that showcased how a plugin could be exploited to gain unauthorized access to a Jenkins master. Despite these challenges, plugins remain a valuable asset for DevOps teams, but they require careful management and consideration of both their pros and cons. The text suggests that while plugins can be beneficial, organizations should evaluate their necessity for basic tasks and consider the overall impact on their CI/CD environment.
Sep 27, 2019
865 words in the original blog post.
At the GitLab Commit user conference in Brooklyn, Eddie Zaneski from Digital Ocean showcased how GitLab's Auto DevOps functionality can simplify the creation and deployment of CI/CD pipelines to Kubernetes clusters in under 20 minutes. He demonstrated the process using a hypothetical startup, emphasizing the importance of a secure DevOps pipeline for attracting venture capital interest. Auto DevOps provides an out-of-the-box solution that automates complex tasks like building applications into containers, checking for vulnerabilities, and deploying to Kubernetes clusters. The demo highlighted the seamless integration between GitLab and Kubernetes, allowing for easy configuration and management of clusters, as well as the installation of essential applications such as Helm, Ingress, Prometheus, and Cert-Manager. Additionally, Eddie presented the flexibility of GitLab's open-source nature by illustrating how users can customize their pipelines using the available source code. The demonstration underscored the efficiency and adaptability of GitLab's tools in managing CI/CD pipelines, appealing to both novice and experienced users.
Sep 26, 2019
1,334 words in the original blog post.
In the nine months since GitLab's bug bounty program went public, external security researchers have significantly enhanced the platform's security by submitting 1,016 reports and earning $395,000 in bounties. To improve the program further, GitLab has implemented a faster payout process, beginning with a partial bounty distributed when a report is triaged, with the balance paid upon resolution. This iterative approach aims to expedite payments and encourage ongoing community feedback. GitLab also values the contributions of repeat reporters, acknowledging their efforts at events like the HackerOne H1-702. To celebrate its first anniversary, GitLab is hosting a hacking contest from October 1 to November 30, 2019, with rewards for categories such as most reputation points, best-written report, and most innovative report, with the winners announced on December 12. The event underscores GitLab's commitment to collaboration and the idea that everyone can contribute to strengthening its security ecosystem.
Sep 24, 2019
666 words in the original blog post.
GitLab's all-remote workforce allows employees to work from anywhere in the world, providing them with the autonomy to create workspaces that suit their lifestyles. This flexibility enables team members like Erich Wegscheider and Caroline to balance their careers with travel, working from diverse locations such as Bali and various European cities. The GitLab visiting grant encourages employees to connect with colleagues worldwide, reimbursing travel costs to facilitate these interactions. Despite the freedom remote work offers, challenges such as coordinating across time zones and maintaining routines persist, requiring digital nomads like Mike Miranda to be intentional about their schedules. Nevertheless, team members are encouraged to embrace the adventure and enjoy their unique experiences while maintaining their professional responsibilities.
Sep 23, 2019
1,662 words in the original blog post.
In the evolving landscape of continuous integration and continuous delivery (CI/CD) tools, CloudBees has been actively acquiring companies like Electric Cloud and Codeship to enhance Jenkins' capabilities and move towards becoming an end-to-end software delivery lifecycle (SDLC) solution. These acquisitions aim to integrate continuous delivery functionalities directly into Jenkins, which traditionally lacked built-in CD features. Meanwhile, CloudBees is developing new platforms like Jenkins X and the CloudBees SDM to address Jenkins' known issues, such as unreliability and plugin maintenance challenges, by creating more distributed and cohesive systems. The broader industry trend shows a push towards consolidation, with several companies acquiring or developing new features to streamline toolchains and accelerate software delivery. GitLab emphasizes its all-in-one platform approach, offering integrated SDM, packaging, delivery, monitoring, and security without the need for plugins, contrasting with Jenkins' strategy of enhancing its platform through acquisitions and new developments.
Sep 20, 2019
661 words in the original blog post.
GitLab's first-ever user conference, GitLab Commit Brooklyn, was a dynamic and unconventional event that took place in the Williamsburg area of Brooklyn, attracting over 400 attendees for a day filled with engaging activities and learning opportunities. The conference featured a unique blend of technical demonstrations, including a CI/CD pipeline session that humorously involved a "screaming chicken," and presentations from notable figures such as Eddie Zane of DigitalOcean. Attendees enjoyed the informal atmosphere, moving between indoor and outdoor spaces, which facilitated lively discussions about DevOps challenges, fueled by an open coffee bar. The event concluded with a social gathering at a bowling alley, encapsulating the blend of professional insight and relaxed networking that characterized the day. The conference set itself apart from typical user events by eschewing traditional settings and offering a refreshing, interactive experience, with plans for a follow-up event in London and recent news of GitLab's $268 million in Series E funding.
Sep 18, 2019
439 words in the original blog post.
As more teams invest in iterative development for business improvement, the integration of DevOps practices extends beyond software development to include infrastructure teams like ITOps and System Admins. Emphasizing the need for automated workflows akin to CI/CD in application delivery, the collaboration between GitLab and HashiCorp highlights the fusion of application and infrastructure delivery processes. HashiCorp's Terraform, an open-source tool for infrastructure as code, allows users to define infrastructure configurations and manage them through Terraform Cloud, enhancing automation and collaboration. This setup lets teams work efficiently in CI/CD pipelines by leveraging webhooks and APIs, while integrating with version control systems like GitLab to maintain best practices. Terraform Cloud's features, like remote state management and the Sentinel policy framework, ensure secure and efficient infrastructure provisioning. Additionally, ongoing efforts with GitLab and HashiCorp aim to enhance secrets management through integration with HashiCorp's Vault, with future insights to be shared in subsequent blog posts.
Sep 17, 2019
708 words in the original blog post.
At GitLab's inaugural user conference in Brooklyn, the company announced several significant developments, including receiving $268 million in Series E funding to advance its DevOps solutions. Key announcements included plans for enhanced integration with Amazon's Elastic Kubernetes Service (EKS) and HashiCorp's Vault Project, aimed at improving infrastructure as code and automating security processes. GitLab also revealed a collaboration with VMware, enabling GitLab Enterprise deployment on VMware Cloud marketplace, and celebrated KDE's decision to adopt GitLab for its developer community. These initiatives reflect GitLab's vision of creating a comprehensive DevSecOps platform that integrates developers, operations, and business teams into a unified workflow. Additionally, GitLab was recognized as the 32nd top private cloud company on the Forbes 2019 Cloud 100 list, underscoring its prominence in the industry.
Sep 17, 2019
610 words in the original blog post.
GitLab has successfully raised $268 million in a Series E funding round, elevating the company's valuation to $2.75 billion, led by existing investors Goldman Sachs and ICONIQ, along with nine new investors. The funding is aimed at enhancing GitLab's DevOps platform offerings, including monitoring, security, and planning, to help enterprise customers accelerate product market entry. With the DevOps tools market predicted to reach $15 billion by 2023, GitLab's CEO Sid Sijbrandij highlights the competitive advantage of a unified DevOps application that fosters collaboration among development, operations, and security teams. GitLab currently serves over 100,000 organizations, has experienced a 143% annual recurring revenue growth rate, and was ranked 32nd in the Forbes 2019 Cloud 100 as the only cloud-agnostic DevOps tool maker. The company has grown from fewer than 10 employees in 2015 to more than 800 team members across 55 countries, with over 4,800 active code contributors and an average of 180 improvements per monthly release. The latest funding was announced during GitLab Commit, the company's first user conference, showcasing the journey and customer-driven innovation that have fueled its rapid growth.
Sep 17, 2019
481 words in the original blog post.
Marshall Cottrell of MRI Technologies discussed at GitLab Commit how NASA transitioned into modern application development by implementing a Kubernetes-based platform called APPDAT, leveraging GitLab for integrated DevSecOps lifecycle management. This initiative, which began in 2018, aimed to modernize NASA's outdated Oracle-based SCM solution with open-source technologies and establish a unified toolchain for software delivery, addressing the agency's previous fragmented approach to software development. MRI's goals included empowering teams to manage resources, fostering open collaboration, and eliminating data silos, all while adhering to cloud-native and Zero Trust principles. The modernization effort has allowed NASA to adopt a culture of collaborative development, syncing existing tools with the new platform and preparing for future projects like the Artemis program's planned lunar data center. The focus on collaboration and change management was as critical as the technical choices in creating a modern platform that supports both developers and non-developers seamlessly.
Sep 17, 2019
607 words in the original blog post.
Security testing has evolved from being solely the domain of security teams to a collaborative effort integrated into the DevOps model, where developers play a crucial role in ensuring code security throughout the software development lifecycle. Despite this shift, challenges persist, such as developers' reluctance to prioritize vulnerability remediation and the perception of security testing as a development bottleneck. To address these issues, developers should embrace security as a fundamental aspect of their workflow by adhering to key principles: promoting security awareness, conducting frequent and early testing, ensuring code changes are verified by peers, maintaining detailed logs of code changes and dependencies, and employing a diverse array of testing methods. By shifting security processes left in the development pipeline, employing tools for automated testing, and fostering a culture of collective responsibility, teams can achieve a DevSecOps model that enhances efficiency and reduces security risks, ultimately benefiting both developers and security professionals.
Sep 16, 2019
1,022 words in the original blog post.
GitLab's inaugural Commit event in Brooklyn is designed to break away from traditional conference settings by taking the form of a neighborhood block party on September 17, with activities spread across eight venues including the Williamsburg Hotel and Brooklyn Bowl. Attendees are encouraged to tailor their experience by scheduling sessions across three thematic tracks: cloud native, DevOps in action, and powered by GitLab, each color-coded for easy navigation. The event promises a quirky and inclusive atmosphere with interactive sessions, networking opportunities, and amenities like complimentary coffee at Kinfolk 90. The day concludes with a networking event at Brooklyn Bowl featuring food, beverages, and bowling, while the Williamsburg Hotel's Library offers attendees personal interactions about GitLab's offerings. There are still opportunities to join this dynamic event and its counterpart in London in October.
Sep 13, 2019
475 words in the original blog post.
GitLab, an all-in-one DevOps solution, faces challenges due to its increasing memory requirements as new features are added, prompting some users to switch to lighter alternatives. To address this, GitLab has established a dedicated Memory team focused on reducing the application's memory footprint from 8GB to 1GB, enabling it to run on devices like a Raspberry Pi. The team is exploring multiple strategies, including migrating from Unicorn to the more memory-efficient Puma server, investigating memory bottlenecks, and improving development practices around code complexity and memory usage. Initial tests with Puma have shown promise, and the team is also addressing memory issues with the Sidekiq background processor. The Memory team, albeit small, is actively recruiting to expand its expertise and workload capacity, aiming to achieve significant memory reductions by the 12.3 release.
Sep 13, 2019
933 words in the original blog post.
Jayson Salazar, a security engineer at GitLab since January 2019, discusses the challenges and rewards of working in security operations within an all-remote, cloud-native company. He emphasizes the importance of having a detailed understanding of the environment one is trying to protect, which he found challenging due to GitLab's complex technological infrastructure. Salazar focuses on improving GitLab's detection capabilities by developing tools for data analysis and enhancing security processes and documentation. He advises cybersecurity professionals to maintain a questioning mindset and avoid complacency to perform meaningful work. Salazar critiques the belief that cloud migration is inherently more secure, advocating for proper workforce training before such transitions. He expresses concern about the future of cybersecurity, urging more attention to security analytics and large-scale governance. Salazar reveals his passion for Korean cuisine, particularly Bulgogi, and enjoys discussing politics, listening to music, and writing poetry in his free time.
Sep 13, 2019
1,761 words in the original blog post.
GitLab, a globally distributed company with an all-remote workforce, allows its team members to tailor their work environments to fit their lifestyles and personal needs, whether that involves creating home offices, working in shared spaces, or embracing a nomadic lifestyle. Employees like Shane Rice and Alessio Caiazza have adapted their home and coworking setups to suit their personal preferences and work-life balance, highlighting the flexibility afforded by GitLab's remote-first approach. Meanwhile, team members such as Nicole Schwartz and Kerri Miller exemplify the adventurous spirit of remote work by traveling across the U.S. while maintaining their professional responsibilities, relying on cafes, coworking spaces, and even local bakeries for internet access. The key to their success lies in flexibility, resourcefulness, and a supportive network of colleagues, which allows them to thrive and grow in their careers, regardless of location. This exploration of diverse working setups underscores the autonomy and adaptability inherent in GitLab's remote work culture, which will be further examined in the series' continuation focusing on global travel integration.
Sep 12, 2019
1,358 words in the original blog post.
Serverless architecture, while not truly devoid of servers, offers a promising approach to managing infrastructure by outsourcing server responsibilities to cloud providers, leading to significant operational efficiency and scalability. This model allows developers to deploy code without managing physical servers, paying only for actual usage, which can make it cost-effective and scalable. However, this also introduces challenges such as increased dependency on vendors, potential security vulnerabilities due to the architecture's reliance on APIs, and unpredictable costs due to its elastic nature. Despite these concerns, serverless is seen as a valuable tool within the broader landscape of computing options, including Kubernetes and traditional infrastructure. It has sparked discussions about its impact on traditional operations roles, but it is unlikely to render sysadmins obsolete; rather, it represents an evolving tool that complements existing technologies. Companies like GitLab are exploring ways to integrate serverless with other platforms to offer a multifaceted approach to DevOps, emphasizing that serverless is just one of many strategies available to enhance innovation and operational efficiency.
Sep 12, 2019
1,327 words in the original blog post.
In GitLab, managing continuous integration (CI) pipelines is crucial to maintaining stable source code and preventing broken master branches, which can undermine trust and block deployment streams. The text discusses two critical GitLab features, Pipelines for Merged Results and Merge Trains, designed to address issues related to outdated source branches and concurrent merges. Pipelines for Merged Results ensure that CI pipelines run on merge commits rather than outdated feature branches, thereby validating the merge requests against the latest master branch before actual merging. This approach helps developers avoid the tedious task of continually rebasing their merge requests. Meanwhile, Merge Trains act as a queuing system to handle multiple simultaneous merges, ensuring that pipelines are tested sequentially and issues are detected before they can disrupt the master branch. These tools not only enhance the reliability of the CI process but also maintain development speed by allowing optimistic assumptions about the sequence of merges. The features empower maintainers and developers with greater confidence in code quality and stability, encouraging them to adopt advanced CI/CD practices.
Sep 11, 2019
1,367 words in the original blog post.
CI/CD for GitHub allows users to host their code on GitHub while leveraging GitLab's CI/CD capabilities, which can be used with any Git repository. Initially offered as a premium feature for GitLab Self-Managed users, it was made available for free on GitLab.com to support the vast number of repositories on GitHub. Though initially set for a limited time, the free use of this feature for private repositories has been extended multiple times, currently allowing usage until March 22, 2020, for Free or Bronze users on GitLab.com. This extension, which continues to support open-source projects with Gold features for free, is meant to encourage more users to utilize GitLab's CI/CD tools by automatically mirroring GitHub repos to GitLab.com. The decision to extend the free offering was based on previously established reasoning that remains relevant, and GitLab continues to seek user feedback to improve the offering.
Sep 09, 2019
307 words in the original blog post.
Dependencies are essential tools for developers, offering time-saving benefits that can accelerate the development process, yet they come with challenges akin to managing a monolithic architecture where minor changes can lead to widespread issues. These dependencies, though useful, are metaphorically like flammable bricks in software, where even a small change or oversight, such as a deleted code or a missed patch, can lead to significant problems, including security vulnerabilities and zero-day attacks. To mitigate these risks, dependency scanning tools have become increasingly popular, providing developers with a comprehensive overview of dependencies and their known vulnerabilities, and offering automated or manual scanning options for proactive incident prevention. Additionally, auto-remediation tools play a critical role by identifying vulnerabilities, suggesting solutions, and potentially applying fixes automatically, thus reducing the window of opportunity for cyber threats and ensuring that updates do not disrupt the functionality of an application. In essence, while dependencies streamline certain aspects of coding, it is vital for developers to manage them with care, employing tools like dependency scanners and auto-remediation to not only protect their software but also to build future projects with precision and strategic foresight.
Sep 09, 2019
569 words in the original blog post.
In the fourth installment of GitLab's Zero Trust series, the focus is on implementing data zones and an authentication scoring system to enhance access control. Zero Trust at GitLab emphasizes individual authentication and asset authorization, where data is grouped into zones—RED, ORANGE, YELLOW, and GREEN—according to its classification, with access restrictions based on these categories. A novel authentication scoring system assesses access eligibility, considering factors like device management and geolocation, to determine the level of access to different data zones. While the RED ZONE requires the highest security measures and encryption, lower zones permit access under specific conditions. The aim is to prevent unnecessary access restrictions or excessive permissions while documenting and automating control processes to facilitate seamless management and accommodate GitLab's growth. Future posts promise a deeper exploration of these systems and their application in overcoming infrastructure challenges.
Sep 06, 2019
1,281 words in the original blog post.
Robert Mitchell, GitLab's Manager of Strategic Security, discusses his role in enhancing the company's security measures, emphasizing the importance of transparency and addressing human error in cybersecurity. He highlights the challenges of working across time zones from Sydney and the rewarding experience of contributing to GitLab's rapid growth. Mitchell is heavily involved in initiatives like Zero-Trust Networking, focusing on identity and authentication to secure the company's all-remote infrastructure. He believes that human error is a major cause of security breaches and advocates for user-friendly solutions like two-factor authentication to mitigate risks. Mitchell also notes the potential of integrating security with DevOps and leveraging new technologies, like machine learning, to improve security practices. He stresses the need for more research on the human side of security, particularly in understanding and preventing mistakes. Outside of work, Mitchell enjoys riding his motorbike and relishing South East Asian cuisine.
Sep 05, 2019
1,406 words in the original blog post.
GitLab is making significant investments in enhancing user experience by expanding its team of product designers, UX researchers, and technical writers, aiming to shift from a reactive to a proactive approach in addressing UX challenges. The company introduced UX Scorecards to evaluate and improve critical workflows, utilizing a grading system from A to F to prioritize efforts and track progress. During the second quarter of 2019, the team identified and assessed 15 essential workflows, highlighting areas needing improvement, such as sign-in processes and automated testing setups. The goal for the third quarter is to enhance seven workflows by one grade letter, with the product team focusing on refining the GitLab.com Free Trial experience and the integration of Kubernetes clusters. This initiative is part of a broader strategy to create a user experience that not only meets but exceeds customer expectations, ultimately contributing to increased customer satisfaction and business growth.
Sep 05, 2019
882 words in the original blog post.
In 2016, the author transitioned to remote work, initially facing challenges with time zone differences and career advancement due to limited company culture support for all-remote work. However, joining GitLab, which embraces an all-remote ethos, provided an opportunity to experience true location independence without sacrificing professional growth. The author is currently on a transformative journey with the WiFi Tribe, exploring co-working and co-living spaces across continents, which has revitalized their work-life balance and sense of community. This experience underscores the importance of a supportive remote work culture, as GitLab's structure allows the author to fulfill both travel and career aspirations simultaneously, especially as the company anticipates significant growth.
Sep 04, 2019
844 words in the original blog post.
GitLab Secure facilitates the integration of security into everyday code development by providing a suite of tools aimed at identifying and mitigating vulnerabilities in real time. These tools include Static Application Security Testing (SAST) for detecting potential vulnerabilities before deployment, secret detection to identify exposed credentials, Dynamic Application Security Testing (DAST) for runtime vulnerability analysis, dependency scanning for monitoring external libraries, and container scanning to check Docker images for security issues. Additional features such as license management and code quality analysis ensure compliance and maintain high code standards. GitLab's Security Dashboard offers a centralized view of vulnerabilities, enabling developers to track and manage risks effectively. GitLab is also exploring advanced security measures like Interactive Application Security Testing (IAST), fuzzing, and auto remediation to enhance the security posture further, aiming to automate and streamline the resolution of vulnerabilities, thereby protecting applications from potential threats.
Sep 03, 2019
1,089 words in the original blog post.
GitLab's annual summit, now known as "Contribute," has grown significantly since its inception in 2013, reflecting the company's expansion, with attendance expected to nearly double each year. Contribute is not a typical conference or incentive trip but a unique opportunity for GitLab team members to connect, collaborate, and build community in person, crucial for an all-remote company. Logistical challenges, such as accommodating a rapidly increasing number of attendees at suitable venues, are a primary focus, requiring careful planning and partnership with destination management companies to ensure a seamless experience. The event features a variety of sessions, including workshops, unconference sessions, and team-building activities, designed to foster knowledge exchange and personal connections among attendees. Feedback from participants highlights the value of face-to-face interactions, especially for new hires who benefit from meeting their colleagues early in their tenure. The corporate events team continuously iterates on the program, incorporating feedback to enhance the event's effectiveness and enjoyment, while maintaining a focus on creating meaningful connections and experiences for all participants.
Sep 02, 2019
1,915 words in the original blog post.
The upcoming GitLab Commit event in Brooklyn is anticipated with enthusiasm, not because of GitLab as a product or company, but due to the opportunity it provides for collaboration among the broader GitLab community, referred to as "GitLabbers." This term encompasses not just employees but over 2000 external contributors who have shaped GitLab through its open core model. The event promises to be a transformative experience with professionals from diverse industries like Delta Airlines and Goldman Sachs sharing insights on leveraging DevOps for organizational benefits, covering topics such as developer efficiency, code quality, CI/CD, and innersourcing. Attendees will not only gain insights into GitLab but will also contribute to its future, highlighting the significance of the community's role in driving GitLab's evolution.
Sep 02, 2019
381 words in the original blog post.
At GitLab Connect Chicago, Robert Ross, chief data officer at the Cook County Assessor's Office, discussed how the office is utilizing GitLab to enhance transparency by publishing the code used for property assessments. This initiative marks a significant shift from traditional paper record-keeping and opaque policy-making to a more open, software-driven approach where "policy is code and code is policy." The office faced challenges such as replicating data formats, overcoming legacy systems, and receiving no support from the previous administration. Despite these obstacles, they have made substantial progress by making their algorithms public through GitLab repositories, a move unprecedented in the realm of county assessors. This transparency allows property owners to understand how their property values are determined, aiming to set a new standard for open governance and hoping to foster a political culture where transparency is seen as advantageous.
Sep 02, 2019
496 words in the original blog post.
In September, various GitLab community meetups are happening worldwide for enthusiasts and professionals interested in mastering Git and GitLab tools. Events include Mexico City's GitLab Meetup on September 12, focusing on enhancing development flow, while the same day in Irvine, California, the Orange County GitLab Users Group will delve into building effective CI/CD pipelines. On September 16, the first GitLab meetup in Curitiba, Brazil, will offer tips and tricks, followed by the GitLab France Meetup on September 19, which will discuss the benefits of GitLab in NoOps adoption. Frankfurt's inaugural GitLab Meetup on September 20 will cover automating pipelines with GitLab-CI, Helm, and Kubernetes. The Tampa DevOps Meetup will feature GitLab on September 25, and the GitLab Nigeria Community will introduce Git and GitLab to newcomers in Ayetoro on September 28. Those interested in joining or initiating local meetups can check the GitLab Meetups page for more information.
Sep 02, 2019
301 words in the original blog post.