Home / Companies / GitLab / Blog / March 2022

March 2022 Summaries

22 posts from GitLab

Filter
Month: Year:
Post Summaries Back to Blog
Interactive training labs by Kontra Application Security, a ThriveDX company, have been integrated into the GitLab DevOps platform, providing developers with interactive security training directly within the Merge Request and pipeline experiences. This integration facilitates quick learning and resolution of vulnerabilities identified through automated security scans and other sources such as penetration tests or bug bounty programs. Kontra offers scalable and advanced security simulations designed to equip developers with the skills needed to build and maintain secure application code by simulating real-life security incidents. These short, engaging training sessions, available in multiple programming languages and frameworks, help developers understand the risk and impact of vulnerabilities from an attacker's perspective, and address the gap in traditional security education that often lacks actionable content. The training is prominently placed within GitLab's vulnerabilities management features, allowing developers and security professionals to access relevant tutorials directly from vulnerabilities details pages, enhancing their ability to proactively prevent and resolve security issues.
Mar 31, 2022 691 words in the original blog post.
The blog post series explores using GitLab as a GitOps tool, focusing on managing Kubernetes deployments with a GitLab agent. The article builds on previous tutorials, guiding users to self-manage a GitLab agent for Kubernetes, enabling it to handle its deployment and upgrades within a GitOps framework. This approach offers benefits such as code-based management, facilitating processes like Merge Requests and approvals, and simplifying upgrades by managing agent configurations in code. The tutorial explains using kpt and kustomize for managing deployment manifests and Bitnami's Sealed Secrets for secure secret management. It highlights the role of inventory policies in managing resources and the importance of appropriate role-based access control (RBAC) settings. Finally, the article demonstrates automating deployment updates through GitOps pipelines and provides an example of upgrading agent deployments by modifying version settings, emphasizing the streamlined management of multiple deployments. This installment concludes the series on GitOps with GitLab.
Mar 30, 2022 1,524 words in the original blog post.
In March, the U.S. government updated its Secure Software Development Framework (SSDF) to better protect software supply chains from increasing threats. The framework, released by the National Institute of Standards and Technology (NIST), emphasizes tighter controls throughout the software development lifecycle and introduces security early in the DevOps process. It outlines four key practices: preparing organizations, protecting software, producing well-secured software, and responding to vulnerabilities. The goal is to standardize secure software development practices across all government agencies and their suppliers, enhancing their defense against potential threats. GitLab, a comprehensive DevOps platform, is highlighted as a tool that aligns with the SSDF by integrating security into the development lifecycle and providing features such as strong policy management, security dashboards, and vulnerability scanning. This alignment supports agencies in automating supply chain security without overburdening resources, ensuring compliance with the SSDF and other mandates.
Mar 29, 2022 712 words in the original blog post.
Busy developers often struggle to write secure code due to time and resource constraints, but the integration of Secure Code Warrior with GitLab aims to address these challenges by providing actionable, secure coding guidance directly within GitLab's DevOps Platform. Announced with GitLab's 14.9 release, this partnership empowers developers by delivering scan results that highlight vulnerabilities, allowing them to quickly access relevant training resources from Secure Code Warrior's extensive library of interactive coding challenges. By offering contextual, bite-sized learning modules, developers can efficiently build skills to recognize and fix specific vulnerabilities, such as Cross-Site Request Forgery (CSRF), thereby enhancing their muscle memory for secure coding practices. This integration not only accelerates the merge request rate and release quality but also automates remediation support, allowing AppSec teams to focus on risk monitoring and security enhancement. As more development teams adopt this workflow, they can produce secure software more swiftly, and the ongoing collaboration between Secure Code Warrior and GitLab seeks to further refine and expand these capabilities.
Mar 24, 2022 533 words in the original blog post.
GitLab has announced that starting August 15, 2026, user limits will be enforced on all remaining Free GitLab.com namespaces with private visibility. Affected users will receive notifications at least 60 days prior to enforcement, guiding them on available options. This change applies to top-level private groups created on or after December 28, 2022, under the Free tier of GitLab SaaS, with a user cap set at 5 users per group. Exceptions include top-level groups with public visibility, paid SaaS and self-managed subscriptions, and members of community programs like GitLab for Open Source, Education, and Startups. Public namespaces are excluded from these limits. Organizations impacted by these changes are advised to consider upgrading to a paid tier or switching to self-managed deployment options, which offer advanced features and support for larger projects. These measures aim to sustain the Free tier offering while supporting DevOps for teams of all sizes.
Mar 24, 2022 669 words in the original blog post.
Rezilion and GitLab have partnered to integrate Rezilion's DevSecOps technology with GitLab CI, aiming to alleviate the tension between development and security teams by enabling faster and more secure product releases. This integration helps developers detect and remediate vulnerabilities early in the development process, which reduces vulnerability backlogs by up to 70% and prioritizes fixing exploitable vulnerabilities to save time and enhance product delivery. By incorporating Rezilion's capabilities into the GitLab workflow, security validation is shifted left, allowing developers to address threats swiftly and efficiently while maintaining focus on innovation. The integration provides actionable insights within the GitLab CI pipeline, marking non-exploitable vulnerabilities as false positives and allowing for the dynamic identification of software components through a Software Bill of Materials (SBOM). This partnership is expected to be impactful for CISOs, product security team members, and developers by streamlining software vulnerability management and mitigating delays due to vulnerability backlogs.
Mar 23, 2022 586 words in the original blog post.
GitLab's Security team is actively investigating a potential security breach involving the Okta platform to assess any risks to GitLab and its users, though no malicious activity has been detected so far. GitLab uses Okta for single-sign-on access to various SaaS applications and has taken steps to examine logs, communicate with Okta and industry peers, and develop contingency plans to protect against potential threats. Customers using Okta for GitLab access are advised to review their Okta logs for suspicious activity, contact Okta support for guidance, and implement multi-factor authentication (MFA) for enhanced security. GitLab has committed to ongoing investigation and will provide updates and alerts if any potential risks to their product or customers are identified, encouraging users to stay informed through security alerts and communication channels.
Mar 22, 2022 362 words in the original blog post.
Global events that create unrest often lead to an increase in cyberattacks, prompting GitLab's Security department to remind users of essential security practices to mitigate risks, especially concerning the recent theft of private source code repositories. Such attacks, often carried out through credential spraying, phishing, and malware, exploit common user mistakes like password reuse and lack of multi-factor authentication (MFA). GitLab advises enabling MFA, ensuring all systems are up-to-date, using password managers, and being cautious of suspicious emails. For self-managed GitLab users, securing instances and understanding audit logs is crucial, while both self-managed and SaaS customers are encouraged to review GitLab's security best practices and enable notifications for updates. These measures collectively aim to fortify user and organizational defenses against potential cyber threats.
Mar 21, 2022 770 words in the original blog post.
Advancing a DevOps career involves not only honing technical skills but also acquiring a deep understanding of the business side of a company, which can be crucial for transitioning from an individual contributor to a management role. Engaging with the company's history, industry trends, competitive landscape, and customer insights can enrich one's perspective and foster innovative thinking. Utilizing resources such as the company's internal knowledge bases, industry reports, and marketing materials can provide valuable information on market dynamics and customer preferences. Additionally, developing key business skills, including communication, leadership, financial management, and time management, is essential for effective collaboration, project execution, and strategic planning. By integrating business acumen with technical expertise, DevOps professionals can leverage their knowledge to propose impactful ideas that enhance business performance and potentially lead to career advancement.
Mar 17, 2022 931 words in the original blog post.
GitLab has announced a collaboration with TestifySec to integrate the Witness open-source tool into its platform, advancing its Secure Software Supply Chain Direction. This integration addresses the increasing concern of securing software supply chains by documenting the entire process from code creation to deployment, with a focus on creating a Software Bill of Materials (SBOM) and utilizing frameworks like SLSA. Witness enhances security by verifying and recording data from CI systems in a standardized way, shifting security practices left and improving transparency around software components. This approach is in response to recent software supply chain attacks and offers a new method for securing CI systems and their artifacts, making use of verifiable cloud infrastructure data from providers like AWS. GitLab and TestifySec plan to continue developing features around this integration to further enhance security measures.
Mar 16, 2022 511 words in the original blog post.
Obsidian.md is a versatile knowledge base application that uses plain text Markdown files to organize notes, catering to a wide range of users due to its extensibility and compatibility across multiple platforms. Users can leverage community-built plugins to tailor the application to their specific workflows, enhancing features such as linking thoughts, managing files, and publishing notes. Obsidian's unique "Linked Thought" feature allows seamless connections between notes, making it ideal for creating a personal knowledge base or "second brain." While it doesn't support git natively, the Obsidian Git plugin provides robust change tracking and archiving capabilities. The application supports CommonMark and GitHub Flavored Markdown, enabling easy access and editing of notes across different text editors. For those interested in publishing notes online, the application offers a tutorial on using GitLab Pages to create a static site with MkDocs, allowing further customization through themes and extensions. Obsidian is praised for its security, as notes are stored locally, offering users control and privacy over their data.
Mar 15, 2022 2,778 words in the original blog post.
The blog post explores the process and challenges of installing GitLab on the newly released 64-bit Raspberry Pi OS, highlighting that while GitLab supports Raspberry Pi OS, official ARM64 support is still pending. The author describes their experience with a manual installation process, necessitated by compatibility issues with the new OS version, which is based on Debian Linux. Despite the lack of official support, the author was able to successfully install GitLab by adjusting the installation path and using Debian Buster repositories. The post concludes by teasing a future article about setting up a private GitLab server with Tailscale and LetsEncrypt, hinting at the complexities of accessing the server from outside a private network and implementing HTTPs.
Mar 14, 2022 698 words in the original blog post.
GitLab expresses deep sorrow over the Russian military invasion of Ukraine, condemning the violence and emphasizing that their criticism is directed at Russia's leadership, not its citizens. The company prioritizes the health and safety of its 13 Ukrainian team members, maintaining daily contact and providing support to them and their families. GitLab ensures the security and continuity of its services, with no customer data stored in Russia or Ukraine, and has increased threat monitoring. Additionally, GitLab has suspended new business in Russia and Belarus, adapting its practices to the evolving situation. The Sijbrandij Foundation will match donations from GitLab employees to charities aiding those affected by the conflict, as the company extends sympathy and hopes for peace.
Mar 11, 2022 335 words in the original blog post.
DevOps is a transformative approach to software development that combines once-siloed teams, tools, and workflows into a cohesive ecosystem, facilitating more efficient, secure, and collaborative software creation and deployment. This methodology emphasizes automation, shifting security considerations to earlier stages of the development process, and fostering a culture of collaboration across departments, including security, marketing, and executive teams. Key stages in the DevOps lifecycle—planning, creating, verifying, packaging, releasing, configuring, monitoring, protecting, and managing—ensure software is developed with speed and agility while maintaining quality and compliance. Continuous integration and continuous delivery (CI/CD) are central to DevOps, enabling frequent and reliable code updates that help organizations quickly respond to market changes and customer needs. The growing demand for DevOps professionals, coupled with rising salaries in this field, underscores the importance of mastering both technical skills and collaborative practices for those new to DevOps teams.
Mar 10, 2022 894 words in the original blog post.
GitLab employs a collaborative approach to maintain the availability of GitLab.com, using Service Level Indicators (SLIs) to monitor performance across different development groups, each with its own dashboard. The target Service Level Objective (SLO) for GitLab.com's availability is set at 99.95%, and if a group's performance falls below this threshold, efforts are made to identify and resolve the issues affecting feature reliability. The GitLab infrastructure is divided into multiple services that run the same Rails application but handle different types of traffic, requiring isolated and aggregate monitoring to accurately assess performance. This monitoring is facilitated by Grafana dashboards, which display error rates and generate multi-window, multi-burn-rate alerts based on Google's SRE practices. These alerts help bring attention to issues that may not be apparent in larger service aggregations, particularly for features with lower traffic, allowing teams to prioritize necessary improvements. Future discussions will focus on the development and integration of these monitoring tools into GitLab's product prioritization process.
Mar 10, 2022 510 words in the original blog post.
DevOps is a set of practices designed to enhance software development by integrating development and operations teams, resulting in faster code releases and improved quality. It emphasizes automation, continuous integration and delivery, agile planning, and infrastructure as code, while also incorporating security through DevSecOps. Successful DevOps strategies focus on customer satisfaction, encourage collaboration across various teams, and adapt to changing business needs. Communication, feedback, and a willingness to embrace change and occasional failure are crucial elements. A well-defined DevOps roadmap, which includes clear objectives and visual representations, is essential for guiding teams and stakeholders. Despite challenges like selecting appropriate tools and merging different team cultures, the adoption of DevOps continues to grow as organizations recognize the benefits of shorter development cycles, enhanced innovation, and more stable operating environments.
Mar 09, 2022 974 words in the original blog post.
Optimizing a GitLab CI pipeline involves balancing time and cost, and finding a sweet spot that varies for different users and scenarios. The optimization process, which applies to both existing and new pipelines, focuses on reducing the number of jobs and pipelines executed and shortening their execution time. To achieve this, it's essential to understand the pipeline's architecture and current metrics, identify bottlenecks, and visualize the pipeline using Directed Acyclic Graphs (DAGs) to pinpoint the critical path. Strategies for executing fewer jobs include using the rules keyword to determine necessary job executions, making jobs interruptible to avoid redundant processes, and rescheduling non-essential pipelines less frequently. For faster execution, jobs can be run in parallel using DAGs and parent-child pipelines, though this increases complexity and potential costs. Additional techniques include failing fast by detecting errors early, optimizing dependency caching, and using smaller, tailored container images to reduce pull times. Pipeline optimization is both a scientific and artistic process requiring continuous testing, documentation, and analysis to achieve incremental improvements across projects.
Mar 09, 2022 1,506 words in the original blog post.
Developing an effective DevOps team involves selecting an appropriate organizational model that aligns with the size and needs of a company, while also allowing for flexibility and iteration as the team grows. The ultimate aim is to integrate DevOps principles throughout the organization, eventually making a separate DevOps group unnecessary. Various models exist, such as having Dev and Ops coexist with a DevOps intermediary, maintaining separate but collaborative Dev and Ops teams, forming a single integrated team with high automation, utilizing Ops as infrastructure consultants, or outsourcing DevOps services. Regardless of the model chosen, key characteristics of successful DevOps teams include strong collaboration, communication, autonomy, iterative improvement, and fast feedback. To initiate DevOps, companies should create a roadmap, ensure organizational buy-in, select suitable technologies, automate processes, and establish comprehensive monitoring.
Mar 08, 2022 1,364 words in the original blog post.
Two-factor authentication (2FA) significantly enhances account security, but its effectiveness varies with the method used, with SMS being less secure due to vulnerability to SIM-swapping attacks. GitLab 14.8 introduces the ability to use 2FA hardware to protect SSH keys by supporting ecdsa-sk and ed25519-sk key types, which require a FIDO/U2F device for user authentication. This method combines something you know (such as a password) with something you have (a physical device) to verify identity, increasing security. Updating to OpenSSH 8.8 on macOS was necessary for the author to generate these keys, involving adjustments to the system path. Once generated, the keys were added to GitLab, requiring physical confirmation via a YubiKey for every interaction, thus ensuring that even if the SSH key were compromised, unauthorized access would still be prevented by the need for physical device presence.
Mar 03, 2022 842 words in the original blog post.
Tabnine has partnered with GitLab to integrate its AI-powered code completion technology into GitLab repositories, aiming to enhance developers' productivity by improving code development accuracy and speed. This collaboration allows users to create custom AI models based on their private code, facilitating knowledge sharing, reducing technical debt, and accelerating code reviews and onboarding processes. The integration caters to diverse teams, from small groups to large companies with extensive open-source code bases, by providing tailored suggestions that adhere to team-specific best practices. GitLab's robust hosting platform complements this initiative, enabling seamless automation and deployment of custom models for teams, while facilitating immediate onboarding for new developers. This partnership marks a significant step toward Tabnine's vision of creating a comprehensive development platform that supports developers across various working environments, coding languages, and IDEs, with ongoing improvements based on user feedback.
Mar 02, 2022 438 words in the original blog post.
In this continuation of the author's journey to learn Python, the focus is on understanding lists and loops, which are foundational elements in programming. Lists in Python are similar to arrays in other languages, allowing for the storage and access of data via index numbers, including unique features like negative indexing to retrieve elements from the end of the list. The author explores useful list methods such as `.pop()`, `.append()`, `.insert()`, and `len()`, which manipulate or provide information about lists. The explanation of loops covers the `for` and `while` loop structures, highlighting the readability and ease of use in Python. The `for` loop is used for iterating over elements, while the `while` loop continues executing as long as a specified condition holds true. The author also shares insights from the learning process, including corrections from commenters and the growing familiarity with Python's syntax and logic, especially the natural feel of loops and the importance of proper indentation.
Mar 01, 2022 1,169 words in the original blog post.
For seasoned DevOps engineers looking to transition into a managerial role, it's essential to develop key skills such as effective communication, mentoring, and collaboration, while maintaining technical expertise in areas like systems architecture and programming. Being proactive in expressing interest and having a transition plan can aid in moving into a DevOps manager role, even if the title does not explicitly exist within an organization. Understanding the responsibilities of a DevOps manager, such as mediating team conflicts, setting goals, and advocating for team interests, is crucial, as is building a strong professional network. Engaging in mentorship programs can provide valuable insights, and volunteering for interim leadership roles offers practical experience. Once in a managerial position, successful DevOps managers focus on breaking down silos, fostering a culture of openness, and continuously improving processes and metrics, all while ensuring that team members have access to relevant and engaging training opportunities that fit their schedules.
Mar 01, 2022 873 words in the original blog post.