Home / Companies / GitLab / Blog / June 2022

June 2022 Summaries

20 posts from GitLab

Filter
Month: Year:
Post Summaries Back to Blog
Gild Investment Trust's DevOps transformation using GitLab and Kubernetes highlights the complexities and unintended consequences of automation in CI/CD processes, as outlined in a fictional case study. The project led by Dakota, Ingrid, and Sasha aimed to optimize compute resources, but encountered issues when resource constraints caused CI job failures. To address this, larger GitLab Runner pods were introduced, allowing developers to select appropriate resources through tagging. However, this led to increased developer time spent on optimizing CI jobs, resulting in a significant opportunity cost and revealing a pattern of "scaled human toil." The story serves as a cautionary tale about the pitfalls of over-optimizing for local efficiencies at the expense of broader organizational productivity, emphasizing the importance of balancing automation efforts with human efficiency and the necessity of considering solution architecture perspectives within DevOps practices.
Jun 29, 2022 3,107 words in the original blog post.
GitLab has introduced Streaming Audit Events to provide real-time visibility into changes within GitLab groups and projects, allowing users to respond immediately to modifications and maintain compliance. These events can drive automation, such as onboarding new team members or restoring changed settings, by sending notifications to a chosen HTTPS destination. Pipedream simplifies this process by enabling seamless integration with GitLab's audit events, allowing users to connect APIs, transform data, and trigger actions across over 700 apps. With Pipedream, users can automate workflows and handle events without the need for setting up and maintaining servers, enhancing the efficiency of managing GitLab projects. Both GitLab and Pipedream support open-source contributions, encouraging the creation of innovative workflows that leverage these capabilities. This integration empowers users to maintain a secure and compliant environment by automatically addressing changes and facilitating immediate action.
Jun 27, 2022 679 words in the original blog post.
A use-after-free bug in certain versions of PostgreSQL can lead to segmentation faults, affecting PostgreSQL 12 versions earlier than 12.7 and PostgreSQL 13 versions earlier than 13.3, with patches available in PostgreSQL 12.7 and 13.3, respectively. This bug potentially impacts GitLab EE versions 14.9 and later and GitLab CE versions 15.1 and later if they use an affected PostgreSQL version, while Omnibus GitLab instances with a bundled PostgreSQL server remain unaffected due to shipping with patched versions. Instances using impacted PostgreSQL versions are strongly encouraged to upgrade to the latest minor version for enhanced stability and security, with more information available in the issue documentation.
Jun 23, 2022 157 words in the original blog post.
Swell, an eCommerce platform provider, has integrated GitLab as its key DevOps, project management, and support ticketing tool since 2021, utilizing it across various organizational functions. Swell employs GitLab Premium for product development, platform infrastructure, and review operations, facilitating environments for every merge request to mirror production for testing purposes. The company has transitioned from bare-metal servers to GitLab's container management solutions, enhancing their CI/CD processes, and significantly reducing image build and deployment times. GitLab's comprehensive features support Swell's fully remote work culture by enabling transparent and asynchronous communication, with all employees using the platform for tasks ranging from issue resolution to knowledge management. Swell is expanding its use of GitLab’s security and compliance tools, while also leveraging the platform for team management through a unique Kanban approach. Despite GitLab's ongoing feature development, Swell remains committed to the platform, valuing its thoroughness and the guidance provided by GitLab's handbook, which has also influenced internal documentation and practices.
Jun 23, 2022 883 words in the original blog post.
GitLab has compiled a set of 10 questions to help DevOps teams assess their current capabilities and identify areas for improvement across various aspects of their operations. These questions explore key areas such as release speed, process automation, changes in DevOps roles, integration of security, and the adoption of advanced technologies like AI and low-code tools. Additionally, they prompt teams to evaluate their technology stack, governance, and compliance strategies, as well as to consider advanced practices like Infrastructure as Code and GitOps. By examining these areas, teams can uncover inefficiencies, future-proof their tech stack, and ensure that career growth and role assessments are part of their ongoing strategy to maintain a productive and effective DevOps environment.
Jun 22, 2022 587 words in the original blog post.
As DevOps teams increasingly integrate development, operations, and security functions into a unified platform, the complexity and cost of maintaining disparate toolchains become significant challenges. Cindy Blake from GitLab emphasizes that tools should support rather than dictate software development processes, yet outdated and fragmented toolchains often hinder efficiency and governance across the software development lifecycle (SDLC). A 2022 Gartner report highlights the issues organizations face with homegrown toolchains, which can exacerbate technical debt and limit business agility. GitLab 15 is presented as a solution, offering a comprehensive platform that facilitates automation, improves visibility, and simplifies compliance and governance by consolidating tools into a single environment. This approach not only reduces operational overhead but also enhances efficiency and consistency through automation, ultimately allowing DevOps teams to focus on innovation rather than toolchain maintenance.
Jun 21, 2022 845 words in the original blog post.
GitLab 15 introduces significant enhancements to its security features, building on the foundation laid by previous versions to further modernize DevOps capabilities and improve collaboration between developers and security professionals. This release enhances application security with features such as container scanning available across all tiers, audit changes, and expanded dependency scanning support. Notably, some security tools previously exclusive to GitLab Ultimate have been moved to the GitLab Free Tier, allowing broader access to essential security features like SAST and secret detection. The Ultimate tier continues to offer additional scanners and advanced functionalities, such as developer lifecycle enhancements and vulnerability management tools, which aid in efficient vulnerability triage and promote secure software development. The release emphasizes the integration of security measures throughout the software development lifecycle, aiming to streamline processes, maintain compliance, and automate manual tasks, thereby enhancing both security and efficiency for teams using GitLab.
Jun 21, 2022 895 words in the original blog post.
Organizations often face challenges in building a data-driven DevOps culture, particularly in identifying the right metrics to measure success across diverse teams. Value Stream Analytics (VSA) can help visualize and manage the DevOps process, from ideation to customer delivery, by providing insights at each stage of software development. DORA metrics, developed through extensive research, offer a standardized way to assess software delivery performance, focusing on deployment frequency, lead time for changes, time to restore service, and change failure rate. Integrated within GitLab, VSA uses these metrics to create a single source of truth that allows teams to identify bottlenecks and improve efficiency. VSA's detailed stage-by-stage analysis helps organizations answer critical questions about delivery speed and quality, making it an essential tool for benchmarking against industry standards and understanding DevOps maturity.
Jun 20, 2022 635 words in the original blog post.
GitLab offers a diverse range of resources and activities to engage its users, including a DevOps quiz designed to test and enhance knowledge about the field, with the promise of revealing a DevOps maturity score upon completion. The platform promotes various blog posts that explore topics such as the integration of Gitaly with Kubernetes, innovative teaching methods in software development using GitLab, and the impact of AI on DevSecOps. GitLab encourages community interaction by inviting users to share thoughts and feedback in their community forum. Additionally, GitLab promotes its intelligent orchestration platform for DevSecOps, offering a free trial to help teams enhance their development processes.
Jun 16, 2022 214 words in the original blog post.
The text explores the importance of integrating DevOps principles into business processes, focusing on maximizing flow, establishing feedback loops, and fostering a culture of continuous experimentation and learning. It argues that while technical features and financial gains are often emphasized, true value comes from improving systems at all organizational levels. The author highlights the challenges of balancing technical and business pressures, suggesting that GitLab's platform can facilitate this transformation by offering a unified tool that supports the entire software development lifecycle (SDLC). By adopting the Three Ways from The DevOps Handbook, organizations can optimize their workflows, enhance quality through quick feedback, and encourage innovation in a trusting environment. The text also underscores the significance of making valuable lessons and improvements accessible throughout an organization, thereby driving efficient and sustainable growth.
Jun 15, 2022 1,922 words in the original blog post.
Observability has emerged as a crucial evolution from traditional monitoring systems in modern software infrastructure, providing a more comprehensive and intuitive view of application performance and user experience. Unlike static monitoring, which focuses on specific metrics such as CPU usage or memory and often requires manual configuration, observability offers a holistic perspective by automatically correlating data across logs, metrics, and tracing, thus revealing "unknown unknowns" that traditional systems might miss. This capability is not only vital for technical troubleshooting, reducing mean time to resolution and preventing costly outages, but also for aligning software performance with business objectives, as it links infrastructure KPIs to business KPIs. The three fundamental pillars of observability—logs, metrics, and tracing—are augmented by additional data such as error tracking and real user monitoring, enabling organizations to gain a full-spectrum view of their infrastructure. As the industry progresses, tools like OpenTelemetry promote standards for observability, facilitating quicker implementations and broader adoption. Observability's integration into the software development lifecycle, particularly in DevOps practices, helps catch potential issues early in CI/CD pipelines and ensures that application code is well-instrumented, thus streamlining the identification of production incident root causes and enhancing operational excellence.
Jun 14, 2022 1,324 words in the original blog post.
GitLab's journey from its inception in 2011 to the release of GitLab 15 has been marked by significant technological evolution and industry shifts, reflecting broader trends in software development and deployment. Initially focused solely on source code management (SCM), GitLab integrated continuous integration (CI) and continuous delivery (CD), challenging the then-prevailing DIY approach to DevOps. Over time, the platform embraced a more integrated DevOps solution, emphasizing the benefits of fewer tools and more streamlined processes. The cloud, once seen as suitable only for startups, has become the norm for infrastructure, while programming languages like Rust and Go have shifted development closer to the processor. Security and code reviews, once siloed, have become integral to the CI/CD pipeline, promoting incremental improvements and context-aware processes. GitLab's commitment to open source has remained steadfast, fostering community contributions and maintaining its open-source identity. Additionally, the normalization of remote work, once an unconventional practice, underscores the importance of platforms that enable successful asynchronous collaboration.
Jun 13, 2022 808 words in the original blog post.
GitLab prioritizes fostering a collaborative and iterative developer culture, deeply integrating its CREDIT values into its operations to enhance team collaboration and innovation. Engineers are drawn to GitLab for its culture of transparency, remote work flexibility, and global diversity, allowing them to impact projects meaningfully and collaborate across departments. The company encourages a mindset where iteration and the development of "boring solutions" are valued for delivering quick, impactful results, enabling teams to receive immediate feedback and adapt accordingly. GitLab's approach emphasizes dividing projects into milestones for continuous integration and value delivery, fostering a supportive environment where the entire organization shares responsibility for stability, reliability, and safety. This culture not only attracts diverse talent but also ensures that collaboration remains a cornerstone of GitLab's engineering practices, supporting mutual growth and innovation across its teams.
Jun 10, 2022 899 words in the original blog post.
Organizations are adopting tools like Quarkus and GitLab to accelerate software development and delivery in a competitive market. Quarkus, an open-source Kubernetes-native Java stack, is tailored for OpenJDK HotSpot and GraalVM and is valued for its cost savings, speed, and reliability, offering both Java and native application modes. GitLab, the comprehensive DevOps platform, supports the entire DevOps lifecycle and GitOps, facilitating secure, cloud-agnostic code delivery. The integration of Quarkus and GitLab allows for improved collaboration between development and operations teams, fostering innovation and business value delivery. The text outlines a procedure for automating the delivery of a Quarkus application using GitLab Auto DevOps, requiring a Kubernetes cluster and detailing steps such as project setup, Dockerfile configuration, port number and Java version adjustments, and enabling Auto DevOps for seamless deployment.
Jun 09, 2022 1,453 words in the original blog post.
GitLab's success is attributed to its active community of contributors known as "GitLab Heroes," with Jean-Phillippe Baconnais being a notable member who shares his expertise in Kubernetes. Baconnais explores the integration of Kubernetes within GitLab, highlighting how the platform facilitates the deployment and monitoring of applications without leaving its environment. He discusses the evolution from the traditional Kubernetes integration to the introduction of GitLab Agent for Kubernetes in version 14.5, which uses a gRPC protocol for seamless communication between a GitLab instance and a Kubernetes cluster. This agent supports GitOps practices, allowing infrastructure management as code with automatic updates upon project changes. The agent also introduces a CI/CD tunnel to simplify cluster interactions. Despite some features still in development, Baconnais finds the GitLab Agent for Kubernetes an innovative tool for project deployment and shares his experimentation experiences and insights at community events, while noting that GitLab's roadmap and updates remain flexible and are subject to change.
Jun 08, 2022 1,725 words in the original blog post.
In a personal narrative, the writer reflects on their transformative journey from a burnout-prone, sedentary tech career in Austin, Texas, to a rejuvenated lifestyle in Big Sky, Montana, enabled by a remote job at GitLab. They recount how the flexibility of asynchronous work allowed them to balance career ambitions, such as leading a new machine learning team at GitLab, with personal passions for skiing and mountain biking. The pandemic initially delayed their move, but ultimately underscored the importance of prioritizing mental health and work-life balance. Emphasizing GitLab's supportive remote culture, the writer shares how this change improved their well-being and professional output, illustrating the broader trend of employers acknowledging the benefits of employee happiness. The narrative concludes with an invitation to join GitLab, highlighting the company's remote work ethos and its impact on personal and professional fulfillment.
Jun 07, 2022 1,331 words in the original blog post.
GitLab is undertaking a significant architectural change to improve the performance and scalability of GitLab.com by splitting its single PostgreSQL database into two clusters: a main database for general features and a ci database for Continuous Integration-related features. This process, known as functional decomposition, is expected to double the database capacity and enhance performance by increasing available database connections and reducing congestion during peak hours. It promises increased stability by shifting ci writes to a separate cluster, thereby reducing database saturation and related incidents, and allowing more focus on new feature development. The implementation will require a planned downtime of up to 120 minutes on July 2, 2022, during which GitLab.com users will experience complete service disruption. Despite added complexity, GitLab ensures tool and dashboard reusability and has prepared extensively with over 600 merge requests, phased rollouts, and thorough rehearsals to minimize risks and ensure a smooth transition.
Jun 02, 2022 965 words in the original blog post.
GitLab's acquisition of UnReview, a machine learning-based solution, has set the stage for integrating AI-powered code review features into their DevOps platform. This integration aims to automate the process of identifying suitable code reviewers, optimizing review workloads, and enhancing knowledge sharing within teams. By leveraging machine learning, GitLab seeks to provide more accurate reviewer recommendations, taking into account factors such as recent interactions with code and individual expertise in front-end or back-end development. The project has introduced new engineering standards and technologies like Python into GitLab's tech stack, and beta feedback suggests that when the recommendations are accurate, they feel "like magic." The initiative has faced challenges, such as ensuring data cleanliness and establishing new MLOps pipelines, but it has also laid the groundwork for future AI-driven features. Looking ahead, GitLab envisions expanding its use of data for recommendations and automations across its platform, including potential advancements in Intelligent Code Security, which could automatically detect and fix security vulnerabilities in real time.
Jun 02, 2022 1,380 words in the original blog post.
Terraform, an open-source infrastructure as code (IaC) tool developed by HashiCorp, facilitates secure and scalable infrastructure management across multiple servers and clouds using a code-based approach. Primarily aimed at automating infrastructure management tasks for DevOps teams, Terraform supports a wide range of cloud providers like AWS, Google Cloud Platform, and Azure, eliminating the need for agent software on managed infrastructures. Despite its advantages in automation and versatility, there are significant security concerns regarding malicious Terraform modules and providers, which may exfiltrate sensitive data if not properly managed. Terraform's security relies on the integrity of provider signatures, with the potential for modules to be manipulated when sourced from mutable platforms like GitHub. The text emphasizes the importance of controlling the content of modules and providers to safeguard against potential security threats, recommending hosting modules in controlled environments and ensuring provider signatures are verified. Future discussions in the series will explore vulnerabilities in Terraform and its integration with CI/CD processes, aiming to strengthen security practices in Terraform usage.
Jun 01, 2022 2,172 words in the original blog post.
In the final part of the "Learn Python with Pj!" series, the author describes their journey in learning Python through Codecademy and applying the skills to develop a bot using the Twitter API. Having experience with the API in Node.js, they decided to create a Python-based bot that tracks real-time hashtag usage on Twitter. The process involved using the Tweepy library to interact with Twitter's API, employing a configuration file to manage authentication keys securely, and leveraging environmental variables to protect sensitive information. The project, detailed in a file named live_tweets.py, employs a class called LogTweets to filter and display tweets containing specific hashtags. The author emphasizes the importance of documenting and sharing their learning experience, which has not only reinforced their knowledge but also potentially aided others in understanding Python.
Jun 01, 2022 1,561 words in the original blog post.