August 2023 Summaries
24 posts from GitLab
Filter
Month:
Year:
Post Summaries
Back to Blog
Git offers various branching strategies that enhance organization, efficiency, and code quality, with the cascading merge approach, facilitated by the ucascade bot, being particularly effective for maintaining consistency across multiple product releases. By utilizing GitLab Flow and release branches, development teams can manage multiple releases efficiently, although applying bug fixes across different stable branches can be time-consuming. The cascading merge strategy simplifies this by centralizing updates in a single branch and propagating them automatically to others, thus reducing manual merge requests. The process involves setting up the ucascade bot on a Kubernetes cluster, configuring GitLab project access tokens, deploying the bot, and creating a GitLab webhook to automate merge request handling. This method ensures that changes are consistently applied across all release branches, streamlining the development process and maintaining a single source of truth.
Aug 31, 2023
504 words in the original blog post.
GitLab's journey to creating the DevOps Platform category began with Dmitriy Zaporozhets developing an open-source collaboration tool out of personal necessity, which gradually evolved due to contributions from a global community and strategic decisions made by GitLab's leadership. Initially, GitLab was not intended to form a new market category, but through collaborative innovation and willingness to integrate different functionalities, such as source code management (SCM) and continuous integration (CI) into a single platform, it distinguished itself from a multitude of specialized point solutions. This integration, prompted by team member Kamil Trzciński, ultimately led to the creation of the first DevOps platform, recognized by analysts like Gartner and Forrester. GitLab's operating principle of "disagree, commit, and disagree" played a crucial role in its success, allowing for decisions that defy conventional wisdom and management opinions. The company's commitment to openness and innovation continues as it aims to pioneer a new category, AllOps, which would unify all research and development processes, including DevSecOps, ModelOps, and DataOps, into a single application.
Aug 30, 2023
1,180 words in the original blog post.
GitLab is planning to update its URL structure over the next few releases to improve predictability and consistency, primarily affecting settings pages but also cleaning up other URLs across the platform. These changes are intended to address deviations from original page title designations over time, aiming for a more logical sitemap. The updated URLs will initially be implemented as 301 redirects, with a complete removal of old routes scheduled for the 17.0 release in May 2024, allowing users time to transition. Users are encouraged to provide feedback on these changes and are assured that existing bookmarks and dependencies on the current URLs will remain functional until the planned removal.
Aug 30, 2023
376 words in the original blog post.
The Manjaro project, a well-regarded open-source operating system, joined the GitLab Open Source Partners community, adopting GitLab as its development platform in 2018 to enhance data sovereignty, empower its volunteer contributors, and expand monitoring capabilities. By hosting its own dedicated GitLab instance, Manjaro gained greater control and autonomy over its development infrastructure, benefitting its core group of 16 developers who maintain over 3,000 packages with the help of GitLab's sophisticated CI/CD functionality. This transition has also improved the project's visibility into potential issues and failures, while aligning it with similar open-source projects like GNOME and KDE, thus fostering a broader network effect within the open-source ecosystem.
Aug 29, 2023
355 words in the original blog post.
Google Cloud and GitLab have announced a partnership to integrate GitLab's DevSecOps capabilities with Google Cloud's infrastructure, aiming to simplify and secure the software development process. This collaboration will merge GitLab's source code management, CI/CD workflows, and security features with Google's Cloud console and Artifact Registry, addressing developer concerns about the complexity and security risks of using multiple tools. The integration will allow developers to manage their entire DevSecOps lifecycle within a unified, cloud-hosted environment, reducing the need for self-hosted solutions and enhancing security from the start. It will also enable seamless access to GitLab projects through the Google Cloud Console and utilize Google's Software Supply Chain Security to enforce governance and policy throughout the development lifecycle. The joint solution promises to streamline security processes by consolidating security scanning results and metadata, offering transparency regarding software content, and enforcing security policies with Google's Binary Authorization. This partnership is poised to deliver faster, more secure software development, with early access available through a waitlist for those interested in the program.
Aug 29, 2023
568 words in the original blog post.
GitLab's Gitaly project has achieved full support for SHA-256 repositories, marking a significant step toward enhancing security by transitioning from the older SHA-1 algorithm to the more secure SHA-256. SHA-256 produces a 64-character hash for data inputs, compared to the 40-character hash generated by SHA-1, which has become less secure due to potential hash collisions, as evidenced by Google's 2017 findings. The Git project has removed the "experimental" label from SHA-256, making it fully operational in Git version 2.42.0, aligning with federal regulations such as NIST and CISA guidelines that recommend moving away from SHA-1 by 2030. Despite the milestone, GitLab still requires further integration work before SHA-256 repositories can be universally adopted within its application. While the transition to SHA-256 is crucial for organizations concerned with security, personal projects may continue using SHA-1 without significant risk. Users can experiment with SHA-256 locally by initializing new repositories with this hashing algorithm to observe its functionality and advantages.
Aug 28, 2023
741 words in the original blog post.
The Good Docs Project recently celebrated the release of version v1.0.0, codenamed "Capilano," marking a significant achievement for the community focused on enhancing software documentation through best practices. Utilizing GitLab for project management, the release process is structured into four phases: scheduling, planning, tracking, and releasing, ensuring organized and timely updates twice a year. Each release is thematically named after a famous bridge, symbolizing the project's goal of "bridging the documentation gap." The planning phase involves brainstorming sessions and user research to set goals, while tracking leverages GitLab's features to monitor progress with tools like milestones and burndown charts. On release day, the Tech Team finalizes the release by tagging it, generating artifacts, and publishing them on the project's website, followed by a three-week break for contributors. This structured approach allows the project to maintain momentum, engage the community, and continuously improve documentation templates, inviting new participants to join the ongoing efforts.
Aug 24, 2023
1,296 words in the original blog post.
The text provides a comprehensive tutorial on building a text-based adventure game in C++ using GitLab Duo Code Suggestions as an interactive guide. The tutorial emphasizes hands-on learning, guiding users through setting up the development environment with VS Code and Clang, and progressively constructing a game where players explore the fictional Dragon Realm. It introduces programming concepts such as variables, conditionals, loops, and structs, using these to create dynamic gameplay elements like player choices and inventory management. The player can navigate various locations, interact with the environment, and collect items, with the game's structure allowing for continuous exploration. Through the step-by-step process, the tutorial not only teaches C++ programming but also highlights the utility of AI-assisted coding tools to enhance learning and streamline development.
Aug 24, 2023
6,425 words in the original blog post.
In response to declining adoption and usability issues with the Environments feature at GitLab, a remote design sprint was conducted, led by Viktor Nagy and another product manager, to devise an innovative solution. This sprint, inspired by the process created by Jake Knapp at Google, involves a structured, time-boxed method for tackling significant problems through design, prototyping, and rapid testing with minimal investment. Key aspects of running a successful remote design sprint include thorough planning, accommodating time zone differences, and fostering strong partnerships between product designers and managers. Utilizing tools such as GitLab issues, Mural boards, Zoom, and Google Drive, the team collaborated asynchronously to overcome the challenges posed by geographical dispersion. The sprint concluded with a clear direction for the Environments feature, fostering a shared understanding among team members and demonstrating the effectiveness of the design sprint process in addressing complex issues, ultimately resulting in documentation to aid future projects.
Aug 23, 2023
1,328 words in the original blog post.
Google Cloud Next '23, held from August 29-31 at the Moscone Center in San Francisco, marked the return of in-person events with GitLab showcasing its AI-powered DevSecOps platform. GitLab's presence included a booth, a pop-up meeting experience, and various speaking sessions highlighting their collaboration with Google Cloud to enhance AI capabilities. Key sessions featured GitLab executives like Vice President of Sales Patty Cheung and Chief Product Officer David DeSanto, who discussed leveraging Google's VertexAI and Codey frameworks for AI-assisted services. The event offered opportunities for networking, technical Q&A, and hands-on panels, emphasizing the integration of AI tools in accelerating software development and improving productivity. Attendees were encouraged to meet GitLab representatives, participate in sessions such as "What's new with generative AI at Google Cloud," and engage in discussions about prompt engineering and AI initiatives.
Aug 22, 2023
764 words in the original blog post.
GitLab's integration with Google Cloud Run offers an efficient strategy for deploying container-based applications by leveraging Auto DevOps, a feature that simplifies and accelerates the CI/CD pipeline using pre-built templates. This tutorial outlines the process of deploying applications to Cloud Run, beginning with the configuration of Google Cloud credentials and the setup of a GitLab project. Developers are guided through adding Auto DevOps to their GitLab project, configuring environment variables necessary for deployment, and modifying the "gitlab-ci.yml" file to incorporate Google Cloud SDK and necessary commands. The tutorial concludes with the deployment of the application to Cloud Run and the completion of dynamic application security testing (DAST) to enhance security. This approach allows teams to benefit from reduced management overhead, accelerated deployment times, and improved application security through serverless technology.
Aug 21, 2023
493 words in the original blog post.
Standards play a crucial role in ensuring the secure and reliable delivery of products and services across various industries, with organizations typically required to adhere to these standards to prevent subpar products and services. In the IT sector, compliance with standards is essential throughout the solution lifecycle, particularly as technology-driven processes generate and handle vast amounts of sensitive data. Improper data management can lead to significant financial losses, emphasizing the importance of compliance. Globally recognized standards such as HIPAA, GDPR, NIST SSDF, PCI DSS, and ISO/IEC 27000 help organizations protect sensitive information and maintain security. GitLab offers comprehensive tools for compliance and security policy management, enabling organizations to develop compliance frameworks, manage security policies, and prepare for audits. Through continuous compliance, businesses can proactively address emerging threats and regulatory changes, fostering trust and efficiency. Regulatory compliance and self-imposed standards differ in terms of origin and scope, with the latter being voluntary and adaptable. Effective compliance management requires a robust compliance culture, regular training, risk assessment, and the integration of compliance into business processes. GitLab's compliance management features help organizations meet regulatory standards, enhance software security, and maintain stakeholder trust.
Aug 17, 2023
2,925 words in the original blog post.
In May 2023, the Create:IDE team undertook the challenging task of merging a large and complex Remote Development integration branch into the master branch of the GitLab Project. The aim was to introduce a new Remote Development feature as part of GitLab 16.0, which required a strategic approach due to its size and the tight deadline. Instead of breaking down the work into smaller parts for individual review, the team opted for a direct merge to meet their release goals, leveraging a velocity-based agile process. This decision was supported by a comprehensive plan to maintain quality through extensive CI/CD monitoring, rigorous testing, and feature flags to minimize risks. The team faced various challenges, including managing application security, database optimization, and code quality, but maintained a collaborative approach through Slack channels and Zoom meetings to ensure smooth communication and issue resolution. Despite deviations from the usual review practices, the merge was a significant milestone, reflecting the team's dedication to delivering innovative solutions while fostering a continuous improvement mindset. As the feature rolled out, the team engaged with the community for feedback and began planning future enhancements, highlighting their commitment to iterative development and user-centric refinement.
Aug 16, 2023
3,552 words in the original blog post.
GitLab 17.0 introduces updates to tag usage for the small SaaS runner on Linux, aligning it with other Linux runners by deprecating tags like "docker" and "linux." Users employing these deprecated tags will experience job configuration issues as jobs will become stuck. To prevent this, users should update their .gitlab-ci.yaml files to use the tag "saas-linux-small-amd64." The runner will continue to execute untagged jobs without changes to their behavior, so users who have not specified a tag will not be affected. The update aims to streamline and standardize tag usage across Linux runners, ensuring consistent performance and configuration.
Aug 15, 2023
242 words in the original blog post.
GitLab faced challenges with its complex and confusing navigation system based on user feedback, prompting a comprehensive review and redesign process to better align with user needs. Initially, proposed solutions failed to address these concerns effectively, leading the team to focus on revalidating the existing navigation problems and understanding user behavior and mental models. By studying key user personas through diary studies and card sorting exercises, they identified the need for customizable navigation, clearer organization, and streamlined workflows. The redesign process was guided by three main themes from user feedback: reducing overwhelm, enhancing orientation across the platform, and enabling users to resume tasks easily. After developing and testing multiple design concepts, a final navigation solution was launched initially to internal team members and then to external users as an optional toggle. A longitudinal study revealed that users appreciated the improvements, such as the ability to pin items and task-based sidebar categories, although some areas for further iteration were identified, like the need for better pinning features and visual differentiation. Moving forward, GitLab plans to gather ongoing feedback through a new quarterly navigation-focused survey to continuously refine and enhance the navigation experience based on user insights.
Aug 15, 2023
1,279 words in the original blog post.
Learning a new programming language, such as Rust, can expand your software development skills and offer new career opportunities, but choosing a method for learning can be challenging. The tutorial explores how GitLab Duo Code Suggestions, powered by AI, can assist in learning Rust by providing guided experiences and code suggestions within IDEs like VS Code. It details the setup process for a Rust development environment, including installing Rust, setting up GitLab projects, and configuring CI/CD pipelines for automated testing. The tutorial emphasizes practical coding exercises, such as defining variables, exploring flow control, and creating functions, while highlighting the benefits of code suggestions for improving coding efficiency. Additionally, it stresses the importance of incorporating testing into the learning process and provides insights into handling errors and optimizing code quality. The guide concludes with recommendations for further learning through asynchronous operations and community engagement to enhance the Rust programming journey.
Aug 10, 2023
2,680 words in the original blog post.
The blog post provides guidance on how to automatically visualize cybersecurity coverage across the MITRE ATT&CK framework using GitLab by deploying the ATT&CK Navigator web application pre-populated with customized matrices. This process involves forking an example project provided by GitLab, which enables users to create an interactive visualization tool that displays their coverage of techniques across the framework. The MITRE ATT&CK framework is a widely used system for classifying and describing cybersecurity attacks, and the Navigator tool allows organizations to track their offensive and defensive capabilities through interactive matrices. Users can start by forking the example project on GitLab, modifying YAML files to annotate specific techniques, and deploying the application to visualize coverage. The blog highlights the benefits of using this system for understanding trends and identifying potential security gaps, and it encourages users to provide feedback or suggest improvements via GitLab's issue or merge request features.
Aug 09, 2023
1,171 words in the original blog post.
GitLab is enhancing account security by implementing a new requirement for users not registered with two-factor authentication (2FA), which involves confirming a valid email address during login attempts deemed high-risk starting August 16, 2023. This measure is a response to increasing cyber threats like credential stuffing and aims to verify user identities more effectively while adding an extra layer of protection against unauthorized access. For non-2FA users, after entering a username and password, a code will be sent to their email for verification, ensuring adherence to GitLab's high security standards. Additionally, users will have a chance to update their email address once to ensure it is valid and active, facilitating smoother logins in the future. This update underscores GitLab's commitment to providing a secure and trustworthy user experience by continuously safeguarding user accounts.
Aug 08, 2023
318 words in the original blog post.
In November 2022, the Linux Foundation Europe launched Project Sylva, a cloud-native, open-source telecommunications software stack designed through a collaborative effort among major telecommunications providers and vendors, including Telefonica, Telecom Italia, Orange, Vodafone, Deutsche Telekom, Ericsson, and Nokia. The initiative aims to build the foundation for a next-generation telecommunications system openly and collaboratively, with ongoing development taking place on GitLab, where the project has been gaining momentum due to an expanding contributor community. An interview with André Vieira, the project's communications lead, provides insights into Sylva's mission, achievements, challenges, and future directions.
Aug 07, 2023
122 words in the original blog post.
GitLab Dedicated, a single-tenancy software-as-a-service offering, was launched to meet the stringent compliance requirements of customers while maintaining efficiency and security. Developed from insights gained from GitLab.com, the multi-tenancy model, GitLab Dedicated addresses automation, databases, monitoring, and availability with unique design decisions tailored to a single-tenant environment. The platform automates the configuration, provisioning, and day-two operations of GitLab instances, relying heavily on the GitLab Environment Toolkit and Terraform for deployment. It utilizes AWS's managed services for databases and ensures high availability with redundant architecture. The bespoke Switchboard application serves as a central management portal for configuration and upgrades. The observability stack benefits from GitLab.com experience but is adapted for the isolated environments of Dedicated instances, addressing compliance and regulatory needs by ensuring data does not leave the customer's AWS account. Unique features such as "Bring your own key" for encryption and PrivateLink networking enhance security and privacy, making GitLab Dedicated a tailored solution for clients with specific compliance demands.
Aug 03, 2023
1,647 words in the original blog post.
During a long car ride with his daughter, the author conceived the idea of creating a simple guessing game application to entertain her, despite not having developed an application in years and lacking knowledge of modern programming languages like Python. By utilizing GitLab Duo Code Suggestions (Beta), an AI-powered feature that assists with coding, the author successfully developed the game using plain text comments, which the AI translated into functional Python code. The application involves guessing a random number between 0 and 10, and after testing it thoroughly in VS Code, the author found it to work flawlessly. To make the game accessible to his daughter on her iPad, the author used GitLab Remote Development workspaces to create a mobile-friendly environment, showcasing the power of cloud-hosted development spaces. While the Code Suggestions feature is still in its beta phase and may experience occasional issues, the author encourages feedback to help improve the tool, emphasizing its potential to enhance programming experiences.
Aug 03, 2023
910 words in the original blog post.
Migrating GitLab resources between instances through direct transfer has seen significant improvements, particularly for handling large projects, by introducing batching in the export and import of project relations such as CI/CD pipelines. This method splits data into smaller, manageable files and utilizes parallel processing to enhance performance, although it may increase the overall migration duration. Key factors influencing migration duration include the hardware resources of the source and destination instances and the complexity and size of the data being migrated. The process allows up to five concurrent entities to be imported, with Sidekiq workers playing a crucial role in speeding up the migration by processing multiple batches. Future plans include making direct transfer limits configurable and removing the 90-minute export timeout to accommodate larger projects, with ongoing improvements aimed at transitioning the feature from beta to general availability.
Aug 02, 2023
1,360 words in the original blog post.
A security expert reflects on the evolution of hardening documentation for GitLab instances, which began as a personal project and grew into official GitLab resources aimed at enhancing security for self-managed and SaaS deployments. The documentation, initially inspired by a popular blog post, offers guidance on applying security controls to protect data and systems, emphasizing the importance of understanding specific threats and regulatory requirements. The author shares insights from decades of field research, including experiences with real-world attack scenarios and the necessity of thorough threat modeling. The journey included setting up a private GitLab instance as a testbed, which was subjected to constant attacks, underscoring the need for robust security measures. The documentation, now part of GitLab's official resources, provides step-by-step advice for hardening GitLab environments, adaptable to various organizational needs, and encourages community feedback and contributions.
Aug 01, 2023
1,404 words in the original blog post.
Free tier users of GitLab can now access medium SaaS runners on Linux, significantly reducing CI/CD execution times compared to the previously available small SaaS runners. This improvement involves utilizing a GCP n2d-standard-4 virtual machine with 4 vCPUs, 16GB RAM, and 50GB of storage for each execution, which can be activated by adding the saas-linux-medium-amd64 tag in the gitlab-ci.yml file of their projects. This development is aimed at enhancing pipeline speeds for Free tier users across all tiers, providing a more efficient experience in their CI/CD processes.
Aug 01, 2023
125 words in the original blog post.