April 2022 Summaries
25 posts from GitLab
Filter
Month:
Year:
Post Summaries
Back to Blog
Since the introduction of System R in 1974, relational databases, particularly SQL databases, have dominated the data persistence landscape, with PostgreSQL emerging as a significant improvement over both its predecessors and other potential successors. Despite the rise of specialized solutions like OLAP databases, which are better suited for analytical workloads, the traditional relational database architecture has persisted, particularly in Online Transaction Processing (OLTP). Michael Stonebraker's research highlighted inefficiencies in the traditional architecture, suggesting that a shift to single-threaded, in-memory databases could offer significant performance improvements, though this approach comes with tradeoffs that have limited its adoption. PostgreSQL has become the leading variant of conventionally architected databases, with its flexibility and feature set making it a popular choice for many enterprises, including GitLab, which transitioned from MySQL to PostgreSQL in 2019. While the NoSQL movement highlighted some limitations of traditional databases, modern relational engines like PostgreSQL have incorporated many of these features, rendering NoSQL more of a feature set than a distinct category.
Apr 29, 2022
1,517 words in the original blog post.
Leveraging the GitLab DevOps Platform, a project was initiated to efficiently analyze and address community questions and feedback on GitLab by automating data collection from StackOverflow using tools like the StackOverflow API, Kubernetes, and open-source Python libraries such as scikit-learn, Streamlit, and Spacy. The project consists of two main components: a Loader that retrieves and preprocesses StackOverflow questions and a Visualizer that generates dashboards from this data. This automated pipeline, which incorporates TF-IDF for feature engineering, allows developers to identify prevalent topics, particularly around GitLab CI and Docker, thus facilitating the creation of targeted educational content while enabling developers to work independently across projects. The initiative has proven successful in pinpointing community needs and suggests further potential for content localization and feature development, with an emphasis on continuous improvement and community collaboration.
Apr 28, 2022
899 words in the original blog post.
GitLab emphasizes the importance of DevOps in fostering collaboration among previously siloed teams and highlights its commitment to integrating DevOps tools into a single platform. This approach eliminates the inefficiencies of using disparate tools, which require complex integrations, and allows companies like Siemens, T-Mobile, and UBS to streamline their software development processes, enhancing time-to-market and reducing costs. GitLab's new logo, featuring the DevOps infinity loop, symbolizes its growth and the evolution of DevOps, while also reinforcing its dedication to iteration and quick feedback loops. The company aspires to be a central resource for knowledge and career advancement in DevOps, inviting users to engage with their monthly feature releases and upcoming events to explore the platform's capabilities further.
Apr 27, 2022
599 words in the original blog post.
GitLab's success is significantly attributed to its community of active contributors known as "GitLab Heroes," who enhance the platform by sharing best practices and contributing to code development. Niklas van Schrick, a Developer trainee, exemplifies these values by promoting transparency and collaboration within the community, particularly through his experiences with self-hosted GitLab instances. His journey began in 2019 with Java development in Minecraft, where he initially struggled with understanding the language due to focusing on frameworks. This experience taught him the importance of self-research and learning from mistakes. In 2020, he embraced version control with GitLab, which improved his workflow and bug tracking, and stressed the benefits of joining a developer community for learning and improving code quality. His active participation in open-source projects, starting with a simple typo fix, led to becoming a GitLab Hero, demonstrating the value of community engagement and contribution in enhancing both personal skills and the collective development environment.
Apr 26, 2022
635 words in the original blog post.
The rapidly evolving DevOps industry is creating diverse career opportunities, notably in roles like Site Reliability Engineer (SRE), DevOps Engineer, and the emerging DevOps Platform Engineer. Each role requires technical expertise and coding skills but serves distinct functions within a DevOps team. SREs, a role originated by Google, focus on maintaining system reliability and uptime, often requiring collaboration across teams and offering a higher salary range compared to DevOps Engineers, who aim to streamline production and automation processes with a potentially better work-life balance. The nascent role of DevOps Platform Engineer integrates development principles to expedite software delivery across the entire lifecycle, though specific career data for this role is still emerging. The demand for DevOps positions is high, driven by the industry's constant evolution, which offers extensive learning opportunities and professional growth. Essential skills for a successful DevOps career include flexibility, communication, collaboration, and technical proficiencies such as CI/CD, coding, cloud computing, and automation. The future of DevOps will likely involve adapting to shifts in technology and practices, with trends like serverless architecture, DevSecOps, and low-code/no-code development gaining traction.
Apr 25, 2022
1,288 words in the original blog post.
Start-ups and small to medium-sized businesses (SMBs) face numerous challenges, but adopting a DevOps platform can significantly alleviate these issues by streamlining software development, automating tasks, and enhancing collaboration, which in turn fosters growth in a competitive market. With the majority of U.S. businesses being small, they are often burdened by worker overload, time constraints for collaboration, and the pressure to meet market demands, leading to high failure rates. A DevOps platform helps by easing worker fatigue, promoting better work/life balance, and ensuring efficient task completion, thereby increasing customer satisfaction through faster software development and deployment. It also enhances communication and collaboration across departments, leading to innovative and well-rounded products, while enabling SMBs to adapt swiftly to market changes and efficiently manage limited resources. By providing tools for automation and collaboration, a DevOps platform empowers small businesses to multiply their technological capabilities, allowing them to do more with less and maintain agility in an unpredictable market.
Apr 25, 2022
747 words in the original blog post.
In March 2020, Tangram Vision's founders Brandon Minor and Adam Rodnitzky had to quickly adapt their collaboration strategy due to the Covid-19 lockdowns, transitioning to a remote work model that relied heavily on GitLab's DevOps platform. This platform became central to the company's operations, enabling seamless remote engineering collaboration and project management, while reinforcing the company's values of transparency and openness. Tangram Vision's platform simplifies complex perception tasks for robotics engineers by providing tools for sensor integration, calibration, and diagnostics, which significantly reduce engineering time. The company has also launched a centralized user hub for sensor data and a multiplexing module, both aimed at streamlining sensor management. The team values GitLab for its comprehensive features, such as integrated code hosting, merge requests, and CI/CD processes, which enhance workflow efficiency and documentation. This approach not only supports Tangram Vision's internal operations but also aligns with their mission to democratize computer vision engineering through transparency and education.
Apr 21, 2022
848 words in the original blog post.
Accelerated cloud adoption necessitates tools for swift software delivery and performance evaluation, with DORA metrics playing a pivotal role in aligning software development with business objectives, enhancing software velocity, and fostering a collaborative culture. These metrics, derived from the Accelerate State of DevOps 2021 report, include deployment frequency, lead time for changes, time to restore service, and change failure rate, which are essential for assessing software delivery performance. Companies like Zoopla have successfully utilized DORA metrics to boost deployment frequency and automation, gaining insights into process workflows and improving measurement and analytics, which in turn enhance team performance and align engineering efforts with business priorities. By leveraging platforms such as the GitLab DevOps platform, organizations can gain visibility into their DevOps lifecycle, identify bottlenecks, and drive continuous improvement, ultimately promoting a culture of innovation and collaboration, all while ensuring that technical debt does not compromise quality.
Apr 20, 2022
743 words in the original blog post.
GitLab has become an approved vendor under California's Software Licensing Program (SLP), allowing state and local agencies, including educational institutions, to purchase GitLab software licenses at discounted rates. This agreement facilitates the procurement process, providing broader access to GitLab's comprehensive DevOps solution, which aims to enhance the efficiency and security of software delivery. California's SLP, managed by the Department of General Services since 1994, aims to simplify software license acquisition for government entities. Bob Stevens, GitLab's area vice president for Public Sector Federal, emphasizes the potential benefits for public agencies adopting automated DevOps practices through this contract. By collaborating with channel partners like Acuity Technical Solutions, Launch Consulting, and Veteran Enhanced Technology Solutions, GitLab seeks to support public sector transformation and improve collaboration in software development. Michelle Hodges, GitLab's vice president of global channels, highlights the company's commitment to providing its platform to a broader network of customers, aiming to streamline and advance their software development processes.
Apr 19, 2022
291 words in the original blog post.
GitLab 15.0 introduces significant updates, including new features and the removal of previously deprecated ones, reflecting its ongoing commitment to improving performance, scalability, and user experience. This major release includes breaking changes, such as the removal of audit events for repository push events, which were disabled by default due to performance concerns, and adjustments to the external status check API that now requires specific status fields. OAuth implicit grant authorization is no longer supported, and OAuth tokens must have an expiration. GitLab has enforced expiration on SSH keys and personal access tokens for enhanced security. Certain features, like required pipeline configurations, are now exclusive to the Ultimate tier, aligning with GitLab's tiering strategy. The release also discontinues support for the omniauth-kerberos gem, pushes rules to supersede CODEOWNERS, and introduces changes to the Runner API endpoints. The update affects various API fields and configuration settings, emphasizing a move towards more robust, secure integrations and modernized dependency management. The release also marks the end of support for certain languages and tools in Dependency Scanning, such as Python 3.6 and retire.js, and the deprecation of legacy infrastructure and features related to logging, tracing, and security protocols. Users are encouraged to transition to alternative solutions and updated configurations to ensure compatibility and leverage the latest GitLab capabilities.
Apr 18, 2022
3,620 words in the original blog post.
Static and dynamic websites serve different purposes, with dynamic sites offering personalized, interactive experiences often managed through content management systems, while static sites deliver consistent content to all users via pre-rendered HTML, CSS, and JavaScript files. Static site generators (SSGs) like Hugo, Zola, Jekyll, Hexo, GatsbyJS, and Astro facilitate the creation of static websites by converting plain text and markup into deployable static files, offering benefits such as speed, security, and scalability due to their lack of a database dependency and the simplicity of static files. These SSGs vary in their programming languages, frameworks, and features, with some providing extensive plugin ecosystems and others focusing on simplicity and ease of use. Hugo, for example, is noted for its ease of installation and robust feature set, while Zola emphasizes a content-driven approach with its Tera templating engine. Each SSG has its strengths, from Jekyll's beginner-friendly Ruby environment to GatsbyJS's React-based modular system that supports dynamic API-driven content. Evaluating the right SSG involves considering project-specific needs, preferred languages, framework familiarity, and community support, with the option to create custom SSGs for tailored features and functionalities.
Apr 18, 2022
2,140 words in the original blog post.
Shopify's eCommerce platform, utilized by 1.75 million sellers, can pose challenges when scaling development efforts, which can be streamlined using GitLab CI/CD pipelines for theme deployments. This approach involves developing locally on a feature branch, merging changes into the main branch to update the staging theme, and then creating a tag in GitLab to automatically update the live theme. The process emphasizes security by using GitLab variables for credentials and protecting variables and branches. Essential steps include setting up variables in GitLab's CI/CD settings, configuring a config.yml file to map these variables for deployments, and using a .gitlab-ci.yml file to define pipeline stages for staging and production deployments via ThemeKit CLI. Code pushed to the main branch triggers staging deployments, while production deployments require tagging and pushing the tag. This workflow can be further refined with merge request approvals and additional GitLab features, with acknowledgments to Alex Gogl for contributions to the tutorial.
Apr 14, 2022
626 words in the original blog post.
Continuous integration and continuous delivery (CI/CD) are essential components of successful DevSecOps implementations, facilitating faster and more reliable software deployments by automating the stages of software development and delivery. Although CI/CD can seem daunting due to its complexity, modern tools enable teams to start quickly with minimal setup. CI/CD involves a pipeline where software undergoes various automated tests to ensure code quality, functionality, and security, minimizing manual intervention and errors. Continuous delivery automatically deploys tested code to servers, allowing for staged releases across development, testing, and production environments, while continuous deployment takes it a step further by automating the entire process. Implementing CI/CD should focus on enhancing developer experience with quick feedback loops, and should incorporate strategies like containerization, security integration, and AI-powered tools to optimize the pipeline. Starting small with targeted improvements and leveraging tools like pre-commit hooks and static code analysis can provide quick wins, building momentum for broader adoption within an organization. Platforms like GitLab offer comprehensive solutions that integrate CI/CD pipelines with version control and security testing, helping teams achieve faster deployment cadences and efficient workflows.
Apr 13, 2022
1,405 words in the original blog post.
A single, end-to-end DevOps platform can significantly enhance the efficiency and growth potential of small to medium-sized businesses (SMBs) by streamlining application development and fostering innovation. By integrating continuous integration and delivery, along with DevSecOps principles, such platforms allow SMBs to rapidly iterate and implement customer feedback, improving satisfaction and reducing change failure rates. Enhanced security measures are embedded early in the development process, leading to more secure and trusted software offerings. The collaborative nature of DevOps encourages company-wide communication and innovation, which is particularly advantageous for SMBs with smaller teams. Furthermore, a unified DevOps platform supports happier and more productive employees by providing necessary tools and automation, thus reducing manual tasks and context switching. Ultimately, the adoption of a DevOps platform helps SMBs maintain agility, make better decisions, and effectively compete with larger enterprises by optimizing resource use and scaling capabilities.
Apr 12, 2022
831 words in the original blog post.
GitLab is advancing to the second phase of migrating its Container Registry to a new version featuring a PostgreSQL backend, which will improve storage visibility, performance, and functionalities such as metadata for tags and UI redesign. The update addresses limitations of the previous Docker Distribution registry by allowing better API feature development through enhanced metadata storage. Starting from April 18, 2022, this migration will proceed in phases—first with GitLab.org repositories, then moving to Free, Premium, and Ultimate tiers, concluding by July 8, 2022. The migration focuses on tagged images, leaving behind untagged ones, which will become inaccessible but are subject to continuous online garbage collection if they remain unreferenced for over 24 hours. A short read-only period will be enforced per repository to ensure consistency, but the process is automated, requiring no user action unless they wish to preserve untagged images by tagging them. GitLab encourages users to activate Container Registry cleanup policies to aid this transition, which ultimately aims to provide a modern and scalable product.
Apr 12, 2022
771 words in the original blog post.
GitLab can be effectively utilized as a GitOps tool, as explored in a series of tutorials that apply DevOps best practices like version control, collaboration, and CI/CD tooling to infrastructure automation. The tutorials guide users through various scenarios, such as provisioning infrastructure with GitLab and Terraform, connecting and managing Kubernetes clusters, handling secrets management, and employing CI/CD tunnels for cluster access. They also cover using Auto DevOps for managing deployments and executing GitOps-style application delivery by connecting application and manifest projects. The series culminates in demonstrating how to enable a GitLab agent for Kubernetes to manage itself, offering a comprehensive approach to using GitLab for infrastructure automation.
Apr 07, 2022
353 words in the original blog post.
In response to the critical Spring remote code execution vulnerabilities, CVE-2022-22965 and CVE-2022-22963, GitLab promptly activated its Security and Engineering teams to assess the potential impact on their products and third-party software. They confirmed that neither GitLab.com nor self-managed GitLab instances use the vulnerable Spring components, and no signs of exploitation or compromise have been detected. GitLab continues to monitor the situation and will provide updates through their blog and security alerts. They encourage users to subscribe to their security alerts mailing list for important notifications and recommend consulting their security practices and secure configuration advice for self-managed instances.
Apr 07, 2022
204 words in the original blog post.
Seventeen years after the Linux community adopted Git as its go-to open-source version control system, it remains an indispensable tool for developers worldwide, known for its fast branching capabilities and significant role in DevOps. Originally created by Linus Torvalds to replace BitKeeper, Git's name has sparked humorous theories, with Torvalds jokingly acknowledging his own ego and others suggesting meanings like "global information tracker." Git's impact is evidenced by its widespread use, with 85% of DevOps professionals from a 2021 survey using it for source control. To honor its anniversary, a variety of Git tips and tricks are shared, including command autocompletion, efficient use of Git blame, and keeping merge requests tidy, while also reflecting on its 15th anniversary celebration and the tool's simplicity that continues to benefit developers.
Apr 07, 2022
549 words in the original blog post.
Small and medium-sized businesses (SMBs), regardless of their size, can significantly benefit from adopting a DevOps platform to enhance their software development processes. DevOps fosters a collaborative atmosphere that transcends technical roles, encouraging innovation by integrating diverse ideas from across the organization. This approach is crucial for SMBs aiming to deliver products quickly and efficiently, helping them compete against larger, more established companies by boosting speed and efficiency. Automation within DevOps reduces manual workload, allowing small teams to focus on other projects, while integrating security early on minimizes future vulnerabilities. Additionally, DevOps helps prevent organizational silos by promoting communication and collaboration, which is easier to establish in smaller companies and essential as they grow. By leveraging these advantages, SMBs can remain agile and responsive in a competitive market.
Apr 06, 2022
834 words in the original blog post.
GitLab emphasizes the significance of metrics in fostering a successful DevOps practice, focusing on seven key metrics to gauge engineering efficiency and productivity. These include master pipeline stability, with a target above 95%, to ensure the main branch's integrity; review app deployment success rate, targeting above 99%, to verify code stability in the first deployed environment; and Time to First Failure (TtFF) aiming for less than 15 minutes to expedite feedback to engineers. GitLab also tracks the age of open S1 and S2 bugs, targeting under 100 and 300 days, respectively, to prioritize actionable work. Additionally, they measure merge request pipeline duration, with a goal of under 45 minutes, for efficient code merging, and MR pipeline costs, aiming below 7.50, to balance cost and speed. Through these metrics, GitLab invites others to compare and discuss their effectiveness and applicability in different DevOps contexts.
Apr 05, 2022
721 words in the original blog post.
Modern application development increasingly relies on cloud-native technologies, which present complex challenges for DevOps teams, particularly in achieving full visibility across distributed architectures. Observability, defined as the collection and analysis of data logs, metrics, and traces, is emerging as a critical tool beyond traditional monitoring, enabling teams to react and adapt throughout the software development lifecycle. According to 451 Research, the adoption of observability is driven by the need to understand what is happening within hybrid and multi-cloud infrastructures, allowing for proactive problem-solving and optimization. With more than half of organizations adopting observability at some level, its integration into DevOps processes provides greater flexibility, control, and the ability to turn data into actionable insights. This capability is championed by companies like GitLab, which aims to make observability a default feature in its DevOps platform, thereby enhancing collaboration and reducing production issues through open-sourced solutions and integration with tools like Prometheus and OpenTelemetry.
Apr 05, 2022
912 words in the original blog post.
GitLab's Women's Team Member Resource Group (TMRG) celebrated Women's History Month by highlighting the experiences and advice of women in technology, emphasizing the importance of diversity, inclusion, and mentorship. Key figures such as Michelle Hodges, Sherrod Patching, and Juliet Wanjohi shared insights on career advancement, the significance of authenticity in leadership, and the role of mentorship in professional growth. They encouraged women to embrace their uniqueness, take risks, and actively pursue opportunities. GitLab's commitment to creating an inclusive environment was praised for allowing women to balance career and family without sacrificing one for the other, fostering a culture where voices are heard, and microaggressions are challenged. The event also featured a live speaker series with GitLab VP of UX, Christie Lenneville, further promoting dialogue and learning within the company.
Apr 04, 2022
1,561 words in the original blog post.
In the third installment of the "Learn Python with Pj!" series, the author explores the simplicity and advantages of Python's syntax, particularly in defining functions and manipulating strings. They appreciate Python's straightforward approach to functions using the "def" keyword, which makes code more readable compared to languages like C# and JavaScript. The author demonstrates how to create functions, such as a countdown to Halloween Horror Nights, showcasing Python's ease in handling inputs and string formatting with f-strings. They delve into Python’s string methods, noting how strings behave like lists of characters and the utility of built-in methods like capitalize() and upper(). The author highlights an exercise involving data manipulation of Halloween-themed strings, emphasizing Python's capability in handling unformatted data. Overall, the article celebrates Python's user-friendly nature and looks forward to discussing Dictionaries in the next installment.
Apr 04, 2022
1,401 words in the original blog post.
The article explores how to implement separation of duties and continuous compliance within the GitLab DevSecOps platform, emphasizing the importance of compliance in maintaining corporate ethics and security standards while avoiding legal repercussions. It introduces key roles like developers, compliance officers, and application security engineers, each with distinct responsibilities, to prevent unauthorized changes and ensure only compliant code is pushed. The text details the use of GitLab's Security Policies, which include Scan Execution, Merge Request Approval, and Pipeline Execution Policies, to enforce security scans, require approval for merges, and manage CI/CD jobs. Additionally, it discusses GitLab's Audit Management and Compliance Dashboard, which provides tools like Audit Events and the Standards Adherence report for tracking and verifying compliance within projects and groups. These features collectively enable organizations to maintain development velocity while ensuring robust security and compliance standards.
Apr 04, 2022
1,108 words in the original blog post.
Shadowing Wayne Haber, director of engineering for Growth, Sec, and Data Science at GitLab, provided a transformative experience emphasizing the interconnectedness of team success, inspired by the Ubuntu Philosophy. The shadowing highlighted how individual department issues, whether they be bugs or hiring delays, can ripple across the organization, affecting not just engineering but also marketing and overall company reputation. Contrary to the initial expectation of focusing on hard skills, the experience underscored the importance of human-centric skills like humbleness and collaboration. Participants were immersed in mission-critical meetings, learning how KPIs are set and relationships are built, while being encouraged to actively engage and provide feedback. This exposure fosters a culture of "No Ego" and strengthens the understanding that personal and team successes are intertwined, making it a valuable opportunity to connect with various colleagues across the company.
Apr 01, 2022
544 words in the original blog post.