Home / Companies / GitLab / Blog / January 2022

January 2022 Summaries

20 posts from GitLab

Filter
Month: Year:
Post Summaries Back to Blog
Modern software development, particularly in building a DevOps team, involves understanding various key roles and the skills required for each position to ensure a cohesive and efficient workflow. Developers are now expected to handle a range of responsibilities from security to automation, often utilizing Agile methods, while operations engineers focus on cloud management and integrating monitoring and analytics. An evangelist plays a crucial role in promoting DevOps within the company, aligning business objectives with team efforts, and ensuring budget allocation. Project and release managers track progress and solve logistical challenges, while QA testers and automation engineers emphasize the importance of testing throughout the development process. Security engineers need to integrate security measures proactively, and UX professionals advocate for user-centric designs. Additional roles like site reliability engineers and infrastructure engineers are also vital, and the current hiring landscape, exacerbated by the Great Resignation, suggests reskilling as a viable strategy. Trainings such as those offered by the DevOps Institute can help develop both technical and soft skills, which are essential for fostering collaboration and communication within DevOps teams.
Jan 25, 2022 754 words in the original blog post.
The COVID-19 pandemic has accelerated cloud adoption across various industries as businesses faced challenges such as closed offices, disrupted supply chains, and the need for remote work, pushing them to migrate applications, data, and infrastructure to public cloud providers like AWS and Google Cloud. Despite the growing trend, many CIOs remain cautious, as cloud migration and modernization require significant effort and expertise, often hindered by legacy systems and workflows. GitLab emerges as a crucial DevOps platform that aids this transition by providing an integrated toolset for managing source code, CI/CD pipelines, and security protocols, streamlining the cloud migration process. It enables organizations to implement consistent, repeatable methodologies that improve project success, highlighting the importance of adopting modern software development strategies and DevOps tools to support hybrid and multi-cloud models. The platform's ability to automate and facilitate the cultural shift towards agile workflows empowers cross-functional teams to work collaboratively, enhancing the overall efficiency and effectiveness of cloud migration efforts.
Jan 25, 2022 699 words in the original blog post.
Zoopla embarked on a journey to enhance its engineering department's performance through the adoption of DORA metrics, a set of key performance indicators derived from the research by the DevOps Research and Assessment group. These metrics include production deploy frequency, lead time, mean time to recover, change fail rate, and time to onboard, which collectively provide insights into the efficiency and quality of software delivery processes. By utilizing tools like GitLab, Blameless, and Jenkins to collect and visualize data, Zoopla successfully improved its deployment frequency from weekly to around 40 times per day, reduced lead time from 10 days to under two, and decreased the change failure rate from 60% to between 1-5%. The company also focused on cultural and procedural changes such as automating deployment pipelines, enhancing incident response, and standardizing infrastructure management with tools like Terraform. These efforts not only streamlined processes but also transformed the company culture, aligning with Zoopla's ambition to join elite performing organizations. Future plans include further automation of metrics collection and expanding the DORA framework as a cornerstone of their engineering strategy, supported by partnerships and ongoing training initiatives.
Jan 24, 2022 973 words in the original blog post.
Value Stream Management (VSM) is crucial for modern businesses, especially as companies increasingly function as software entities, necessitating innovation and rapid delivery to remain competitive. VSM emphasizes customer-centered development, focusing on optimizing the flow of value rather than just features, thereby reducing bottlenecks and shortening time to market. GitLab's DevOps Platform incorporates Value Stream Analytics to provide a comprehensive view of team performance, tracking the median time spent across stages like Issue, Plan, Code, Test, Review, and Staging. This tool helps identify inefficiencies and improve software delivery processes by analyzing metrics such as Deployment Frequency and Lead Time for Changes. Being part of GitLab's single-application ecosystem, these analytics facilitate seamless data integration across all development stages, offering insights without needing external tools, and are customizable at the group level.
Jan 24, 2022 663 words in the original blog post.
GitLab's recent blog post introduces the ModelOps stage, a new initiative designed to integrate machine learning (ML) algorithms within GitLab, enhancing its capabilities by incorporating data science workloads. ModelOps is organized into three primary groups: DataOps, MLOps, and AI Assisted, each addressing specific challenges faced by data professionals. DataOps focuses on processing and preparing data for business use, while MLOps is dedicated to building, testing, and deploying AI/ML models. The AI Assisted group aims to automate tasks by enriching GitLab features with ML, such as issue labeling and code review assignments. The overarching goal of ModelOps is to bridge the gap between data science and DevOps by fostering collaboration, facilitating the deployment of data science models into production environments, and ultimately empowering GitLab users to build and integrate data-rich applications. This initiative reflects GitLab's commitment to evolving its platform to meet the growing demands of modern software development, though the details of the rollout remain subject to change.
Jan 21, 2022 1,354 words in the original blog post.
Container Host Security in GitLab enhances containerized infrastructure protection by utilizing Falco, a cloud-native security tool, to monitor and detect runtime threats within Kubernetes containers. The blog post details the deployment of Falco using GitLab-Managed Apps and CI/CD pipelines, offering insights into setting up Falco rules to detect and alert on potential malicious behaviors. It covers the integration process of Falco with a Kubernetes cluster, the configuration of custom rules, and the setup of various alert channels to report rule violations. Additionally, the post showcases an example project, Initech Infrastructure, for practical demonstration and elaborates on creating custom Falco rules for specific security needs. The document provides guidance on verifying rule functionality through Falco logs and outlines the types of alerts that can be configured, emphasizing the importance of proactive threat detection and response in maintaining secure container environments.
Jan 20, 2022 1,046 words in the original blog post.
GitLab's Scalability team implemented a series of improvements to enhance server-side efficiency in handling Git fetch traffic, resulting in a 9x reduction in CPU utilization, primarily through the introduction of the Gitaly pack-objects cache. This cache has significantly reduced server load, particularly in managing highly concurrent CI pipelines, and while the changes are not visible to users, they enhance the stability and availability of GitLab.com. A prior solution, the CI pre-clone script, effectively minimized data transfer per CI job but required manual setup, lacked integration, and was prone to maintenance issues, leading to the development of the more robust pack-objects cache. A benchmark demonstrated that after enabling the pack-objects cache, server CPU utilization during a simulated CI pipeline decreased from 100% to 40%, and the benchmark run time improved from 27 seconds to 7.5 seconds. This advancement, incorporated in GitLab version 14.6, underscores a broader effort to optimize Git HTTP efficiency, which is central to GitLab CI operations, in comparison to Git SSH.
Jan 20, 2022 1,042 words in the original blog post.
Over the past six months, a survey with more than 600 participants assessed current DevOps practices, revealing insights into how this approach is shaping modern software development and business operations. The survey showed that DevOps is increasingly popular, with 35% of respondents having adopted it in the past one to three years, and 15% having more than five years of experience. The methodology promotes faster and safer software development, greater collaboration, and cross-functional processes, with nearly a quarter of organizations involving everyone in their DevOps teams. Changes within teams include blurred traditional roles and increased cross-functionality, with dev, sec, ops, and test roles evolving and merging. Planning and collaboration processes are well-established for 50% of the respondents, while 43% are in the process of refining these methods. Additionally, 36% of participants use an "out of the box" DevOps platform, while many employ a hybrid approach combining homegrown and purchased solutions.
Jan 19, 2022 363 words in the original blog post.
In a remote, asynchronous work environment, the Monitor team at GitLab explored the necessity of synchronous collaboration through a Lightning Decision Jam (LDJ) to reflect on their progress and future direction in incident management. Despite the team's global distribution and usual reliance on asynchronous communication, they recognized the value of a real-time, structured session to collectively identify challenges and ideate solutions. The LDJ, conducted via Zoom and Mural with time-boxed brainstorming and dot voting, allowed team members to generate and prioritize ideas, leading to actionable GitLab issues for future milestones. The session not only facilitated alignment and focus on their objectives but also fostered team cohesion by providing an opportunity for real-time interaction, which is particularly valuable given the global circumstances. The team plans to experiment with asynchronous LDJs in the future to give members more time for reflection and participation at their convenience, highlighting the importance of diverse interaction methods for maintaining engagement and ensuring every team member has a voice in shaping their work.
Jan 19, 2022 1,049 words in the original blog post.
In the current DevOps landscape, the "Everything-as-Code" approach is becoming increasingly important, particularly in cloud-native environments where standardizing DevOps processes is crucial. This approach leverages as-Code technologies across various stages of the software development lifecycle, including Build-as-Code, Test-as-Code, Security-as-Code, and Deployment-as-Code, to enhance efficiency, scalability, auditability, and collaboration. As-Code solutions are integral to cloud-native technologies like Kubernetes, utilizing formats such as YAML and JSON for configuration management. Pipelines-as-Code are central to the CI/CD workflow, acting as the automation core that integrates all as-Code components to ensure reliable and predictable application deployment. They allow for centralized repositories, ensuring consistency with organizational standards and facilitating team collaboration, version control, and speed to production. The benefits of as-Code methodologies are maximized within Pipelines-as-Code, which underpin automated GitOps, DevOps, and SecOps workflows, driving agility and value delivery.
Jan 18, 2022 620 words in the original blog post.
In January 2022, GitLab.com plans to integrate the GitLab Container Registry with the Google Cloud Content Delivery Network (CDN) to enhance cost-efficiency and performance by redirecting download requests for blobs to the CDN instead of Google Cloud Storage. This change aims to accelerate image downloads for GitLab CI users by utilizing edge caches nearer to users' locations. The transition will commence in late January 2022 with a gradual, percentage-based rollout, initially affecting requests directed to Google Cloud Storage, except for those originating within the Google Cloud Platform. Most users will not notice the change due to automatic handling of redirections by client tools, but those managing allow lists must update them to include the CDN endpoint. Further updates and timelines will be shared in an ongoing issue, with a subsequent blog post to announce the transition's completion.
Jan 13, 2022 407 words in the original blog post.
DevOps is a rapidly expanding field projected to reach $17.7 billion in revenue by 2024, necessitating the demand for more skilled practitioners. Despite the lack of formal DevOps education in degree programs due to its fast-paced nature, individuals can acquire these essential skills through various means. Early exposure to DevOps is beneficial, as it shortens the professional timeline for students and enhances workforce readiness. Students can integrate DevOps into educational settings, explore it independently through online resources, and network with industry professionals at meetups and conferences. Hands-on experience with DevOps tools and contributing to open-source projects are valuable for building a portfolio and gaining practical knowledge. Additionally, earning industry credentials through courses and certifications can further solidify one's expertise and enhance career prospects. GitLab offers resources and opportunities for learning, networking, and contributing to the DevOps community, making it a valuable platform for those seeking to advance in this dynamic field.
Jan 13, 2022 1,406 words in the original blog post.
In 2022, learning a new programming language remains a valuable goal for DevOps professionals aiming to enhance their skills, as highlighted by the DevOps Institute's Upskilling Report. Popular choices among developers include Python, JavaScript, and Go, according to Stack Overflow's 2021 Survey. While JavaScript is widely used, emerging languages such as Python, Go, Rust, Groovy, and Kotlin offer diverse opportunities for growth. Python is praised for its ease of learning and utility in websites, analytics, and DevOps, with resources like Python.org's tutorial available for beginners. Go is noted for its simplicity and is recommended for real-world applications like continuous integration, with GitLab's Brendan O'Leary planning to document his learning journey. Rust, known for producing secure code, has a dedicated fanbase and offers learning resources like The Rust Programming Language book. Groovy, suitable for automation and scripting alongside Java, and Kotlin, favored for data science and Android app development, provide additional avenues for exploration. For those interested in combining skills, a guide is available for using Python and Rust together in production environments with GitLab CI.
Jan 13, 2022 436 words in the original blog post.
GitLab is promoting DevOps education by providing various resources and programs to universities and educational institutions, aiming to bridge the gap between industry demand and educational offerings in the field. Through the GitLab for Education program, educational and research institutions can access free Ultimate licenses for teaching and nonprofit research purposes, while the GitLab for Campuses initiative offers discounted access to DevOps tools for technical administration and IT professionals. Additionally, GitLab offers guest lectures, student contribution workshops, and student organization workshops to help students and educators understand DevOps and participate in open-source projects. These initiatives not only focus on teaching technical skills but also emphasize the cultural and operational changes associated with DevOps, providing students with valuable industry insights and opportunities to build their professional portfolios.
Jan 11, 2022 1,034 words in the original blog post.
Software documentation, though not the most glamorous aspect of DevOps, plays a crucial role in enhancing development and deployment efficiency by unifying efforts across projects and teams and sharing specialized knowledge. Comprehensive, up-to-date documentation is directly linked to a DevOps team's success, as evidenced by the DORA report, which highlights that teams with robust documentation practices are significantly more likely to meet reliability and security targets and maximize cloud usage. Effective documentation involves clear responsibility, user experience considerations, security insights, and continuous updates throughout the development lifecycle. Automation tools within DevOps platforms can streamline documentation by capturing and integrating key data from processes and configurations, thereby aiding in real-time, ongoing documentation efforts. The DORA report emphasizes the foundational role of high-quality documentation in implementing DevOps capabilities, enhancing team performance, and sharing specialized knowledge.
Jan 11, 2022 1,125 words in the original blog post.
DevOps teams aiming for secure software development must integrate security from the beginning, despite historical tensions between developers and security teams. Overcoming these challenges involves fostering better communication, where both parties understand each other's roles and responsibilities in security, as highlighted by a survey showing increased collaboration within DevOps teams. Employing strategies such as implementing security champions within development teams, providing cross-functional training, and immersive experiences like hacking exercises can bridge the gap. These methods encourage all team members to embrace security as part of their shared responsibility, ultimately transforming DevOps into DevSecOps for improved code quality and faster release times. The right technology and a culture of collaboration are crucial in breaking down stereotypes and fostering a more integrated approach to security within DevOps practices.
Jan 10, 2022 762 words in the original blog post.
This blog post discusses how GitLab can be used as a GitOps tool, specifically focusing on accessing a Kubernetes cluster using GitLab CI/CD through the GitLab Kubernetes Agent. The post highlights the benefits of the CI/CD integration, which offers a streamlined and integrated experience with GitLab features such as container network security and scanning, reducing the need for manual scripting. The CI/CD tunnel, a key feature, allows for seamless cluster connections that can be reused across projects, enhancing efficiency and cost-effectiveness. The article provides instructions on configuring the CI/CD tunnel, sharing connections, and installing GitLab integrated applications like NGINX Ingress and GitLab Runners using a cluster management project template. This setup supports the transition from Helm v2 to v3 and encourages users to extend the project with custom applications. The post concludes by emphasizing the additional possibilities offered by the GitLab Kubernetes Agent beyond traditional GitOps tools, setting the stage for future discussions on using Auto DevOps with the Agent.
Jan 07, 2022 1,427 words in the original blog post.
In 2022, the integration of security into the software supply chain by DevOps teams, a practice known as DevSecOps, is seen as crucial due to high-profile supply chain attacks in previous years. The "Accelerate State of DevOps 2021 Report" by Google Cloud's DORA team, co-sponsored by GitLab, highlights that development teams incorporating security are significantly more likely to achieve their organizational goals, with elite performers excelling in reliability by integrating security early in the development process. Effective DevSecOps requires collaboration between DevOps and security teams to develop best practices and common technical understanding. A newly released guide emphasizes the importance of protecting the supply chain, particularly following incidents like the SolarWinds and Colonial Pipeline attacks, and outlines best practices including applying common security controls, automating controls, and using zero-trust principles. It also details various security scans to enhance supply chain security and offers a quiz to help teams assess their security readiness. Despite the urgency, the report indicates room for improvement, as many DevOps teams still lack comprehensive security practices, but the guide aims to help develop robust security processes and protect organizations from future attacks.
Jan 06, 2022 543 words in the original blog post.
The blog post explores the integration of Liquibase, an established open-source tool for database change management, with the GitLab DevOps platform to enhance CI/CD processes. Liquibase, with over 75 million downloads, allows database teams to manage changes as efficiently as application code, ensuring quality and security. The tutorial provided in the post guides users through setting up Liquibase within a GitLab CI/CD pipeline, demonstrating how to use various Liquibase commands to automate database scripts, check for security and compliance issues, and facilitate easy rollbacks and database snapshots. The integration aims to improve collaboration and communication, key components for successful DevOps implementations, by bringing database change processes in line with existing automation workflows. The detailed instructions walk users through configuring the environment, managing database changes, and running pipelines, ultimately enabling teams to maintain a secure and efficient flow in database development.
Jan 05, 2022 2,008 words in the original blog post.
In June 2021, GitLab announced the acquisition of UnReview, a machine learning solution designed to automatically identify suitable code reviewers, marking the initial staffing of its new ModelOps stage. ModelOps is a comprehensive initiative aimed at integrating and empowering data science workloads within GitLab's DevOps Platform, thereby enhancing its capabilities to include AI and ML workloads alongside traditional software processes. UnReview will be GitLab's first AI-assisted feature, offering suggestions for code reviewers based on project contribution history, which is expected to streamline the code review process by recommending well-suited reviewers for specific changes. GitLab plans to launch a private customer beta of this feature in early 2022, focusing on larger repositories with numerous contributors to maximize the effectiveness of the suggestion algorithm.
Jan 04, 2022 549 words in the original blog post.