Home / Companies / GitLab / Blog / January 2024

January 2024 Summaries

22 posts from GitLab

Filter
Month: Year:
Post Summaries Back to Blog
The tutorial provides a step-by-step guide to setting up a Google Kubernetes Engine (GKE) cluster with ArgoCD pre-installed using Terraform, designed to be completed in under 10 minutes. It begins by instructing users to import a GitLab Terraform GKE ArgoCD template and integrate their Google Cloud Platform (GCP) credentials to deploy the cluster. The guide details the necessary roles for GCP service accounts and explains how to encode the service account key for secure storage within GitLab CI/CD variables. Once deployment is complete, users can connect to their GKE cluster, access the ArgoCD Initial Admin Secret, and set up port forwarding to access ArgoCD via a web browser. The tutorial concludes by encouraging users to explore additional resources for enhancing their GitOps experience using ArgoCD and GitLab.
Jan 31, 2024 487 words in the original blog post.
GitLab's Hosted Runners for GitLab Dedicated, now in Beta, provide fully managed runners for CI/CD jobs, offering an efficient and flexible solution for handling complex runner fleets. These runners, available to existing GitLab Dedicated customers by invitation, are Linux-based, auto-scaling, and ensure complete isolation from other tenants, adhering to GitLab Dedicated's principles. The Beta release aims to simplify the management of CI/CD jobs, with additional features planned based on customer feedback before moving to limited and general availability.
Jan 31, 2024 159 words in the original blog post.
Southwest Airlines Co. is enhancing its software development processes by eliminating repetitive tasks to allow developers to concentrate on larger projects, leveraging GitLab's platform to streamline workflows. Jim Dayton, the company's vice president and CISO, emphasized the importance of removing obstacles from developers' paths to foster creativity and problem-solving. Southwest, which has collaborated with GitLab since 2019, is implementing self-service capabilities and knowledge management to reduce context switching and improve productivity. The airline is also embracing a DevOps approach and plans to migrate teams to enterprise pipelines for consistent software development. Additionally, Southwest is exploring the potential of artificial intelligence to enhance efficiency, particularly through generative AI that can aid in vulnerability explanation, code suggestions, and workflow optimization. While AI is not seen as a replacement for developers, it is expected to simplify their tasks and enhance collaboration, especially in a remote work environment.
Jan 30, 2024 776 words in the original blog post.
The automotive industry, facing unique challenges in the digital age due to modern cars' advanced functionalities, requires robust data security and streamlined development processes. GitLab, as a Trusted Information Security Assessment Exchange (TISAX) certified organization, addresses these needs by maintaining high standards of information security, particularly for the European automotive sector. TISAX certification offers assurance that GitLab complies with the Information Security Assessment (ISA) requirements, with GitLab achieving Assessment Level 2 to align with its all-remote operations. GitLab's commitment to security is further evidenced by its Information Security Management System (ISMS), which encompasses customer data, software, and internal information assets to support its SaaS subscriptions. This dedication ensures that GitLab's DevSecOps platform provides automotive customers with secure, reliable, and efficient service, reinforcing its mission to support agile collaboration and regulatory compliance.
Jan 30, 2024 428 words in the original blog post.
Artificial intelligence (AI) is increasingly integral to software development as organizations seek ways to optimize efficiency and productivity across the software development lifecycle (SDLC). According to GitLab's 2023 report, developers spend only a quarter of their time writing new code, dedicating the rest to tasks like code improvement, testing, and security. GitLab is addressing this through AI-enhanced features such as Code Suggestions, which automates routine coding tasks, and Duo Chat, which aids in understanding and creating code. These tools are part of the GitLab Duo suite, which includes 15 AI-assisted features designed to streamline various stages of the SDLC, from code generation and testing to security analysis and documentation. GitLab Duo Pro offers additional organizational controls and is available at an introductory price, emphasizing efficiency and governance. The AI-driven capabilities help mitigate workflow bottlenecks, enhance software quality, and ensure data privacy by not using customer code for AI training. The integration of these AI solutions into popular development environments further supports developers in creating innovative and secure software more rapidly.
Jan 29, 2024 758 words in the original blog post.
GitLab has partnered with the CHAOSS project to integrate their DEI Project Badging program, which aims to foster diversity, equity, and inclusion in open source communities by enabling projects to signal their commitment to inclusivity and highlight their efforts to support new members. This initiative responds to challenges identified in a Linux Foundation report, which highlighted barriers faced by underrepresented groups in open source communities, such as feeling unwelcome and exclusionary practices. The DEI Project Badging system encourages projects to create DEI Project Statements, which are reviewed by CHAOSS, and successful projects receive a badge signifying their inclusive status. GitLab's collaboration involves integrating this badging process with GitLab tools, making it easier for projects to participate. Supported by several open source partners, this initiative aims to create a more equitable ecosystem and inspire collaborative improvement across the industry. GitLab is committed to diversifying its open source communities as part of its broader DEI strategy, inviting the community to join in these efforts.
Jan 29, 2024 1,765 words in the original blog post.
With the latest GitLab 16.7 release and GitLab Runner 16.7, a new feature has been introduced that enhances the CI/CD log experience for jobs with multi-line commands by enabling collapsible output sections in the job log. This feature, activated by the FF_SCRIPT_SECTIONS flag, allows users to view all executed commands in a collapsible format when using the Bash shell, aiding in debugging by displaying multi-line scripts more clearly in the log. Previously, multi-line commands were not fully visible in the log output, making it difficult to debug without referring back to the source pipeline file. While this feature currently supports only the Bash shell, future updates aim to extend compatibility to other shells, like Powershell, and include additional improvements, such as timestamps for each log line to track command durations. Users are advised that this information is subject to change and should not be used for purchasing or planning purposes, as the development and release of features remain at GitLab's discretion.
Jan 25, 2024 894 words in the original blog post.
Terraform is a widely recognized tool for infrastructure orchestration, yet its complexity can make it challenging to learn, especially with unfamiliar providers. GitLab Duo Code Suggestions and its AI-powered code creation facilitate this learning curve by offering accelerated coding assistance in multiple programming languages, including Terraform for infrastructure as code (IaC). This integration allows teams to quickly adopt new Terraform providers and modules, reducing onboarding time for new users by providing context-aware suggestions that minimize the need for extensive documentation review. Users can set up GitLab Duo Code Suggestions by installing the relevant IDE extensions, configuring their GitLab settings, and integrating third-party support if needed. Once configured, users can create Terraform plans with the assistance of GitLab Duo, which provides contextual suggestions for resources like load balancers on platforms such as Google Cloud. The tool promises to enhance development speed while ensuring data privacy through its use of advanced language models.
Jan 24, 2024 430 words in the original blog post.
Release notes are an essential tool for software users to understand updates, with well-crafted notes providing a narrative around new features, improvements, and known issues. While automated tools can generate basic release notes, manually writing them offers a chance to contextualize changes, enhancing user appreciation. The Good Docs Project utilizes GitLab for streamlined release note creation, employing a template that organizes key updates into a readable format. This template, along with GitLab's work management features, simplifies the process of crafting informative release notes, exemplified by the recent Dragon release. The project encourages customization of the template to suit specific needs, emphasizing that tailored, well-organized release notes can be efficiently produced, benefiting from GitLab's tools to manage milestones, issues, and releases. The collaboration between GitLab and the Good Docs Project exemplifies the advancement of open-source documentation practices, inviting others to explore and contribute to the ongoing improvement of technical documentation standards.
Jan 23, 2024 781 words in the original blog post.
GitLab has introduced support for Windows 2022 on its SaaS runners, currently in Beta, as part of its efforts to transition these runners to general availability, while simultaneously announcing the deprecation of Windows 2019 and its associated tags with the upcoming release of GitLab 17.0. To streamline tag usage, the new tag saas-windows-medium-amd64 will replace the older tags shared-windows and windows-1809, and users must update their .gitlab-ci.yaml files to avoid job disruptions after the transition period. The update emphasizes the unavailability of alternative image versions, requiring users to adapt their configurations to the new Windows 2022 image, which includes updated pre-installed software components. Failure to update tags will result in jobs being stuck post-GitLab 17.0, necessitating prompt action to ensure a seamless migration.
Jan 22, 2024 313 words in the original blog post.
In GitLab 16.0 and subsequent releases 16.5, 16.6, and 16.7, the Registration Features program has been expanded to offer free self-managed users running GitLab Enterprise Edition access to 16 additional paid features by registering with GitLab and sharing activity data through Service Ping. These features include group wikis for managing documentation across multiple projects, issue analytics for monthly issue tracking, custom text options in emails for compliance, and contribution analytics to overview group member activities. Other enhancements include group file templates, group webhooks, a Service Level Agreement countdown timer, project membership locks, user permission reports, advanced search capabilities, and insights into group DevOps adoption. Users can also benefit from cross-project pipelines with artifact dependencies, linking feature flag issues, merged results pipelines, and the use of GitLab CI/CD with external repositories like GitHub. These new features are available in addition to the ones introduced in GitLab 16.0 and earlier, and participation details for self-managed users are provided in the GitLab documentation.
Jan 18, 2024 542 words in the original blog post.
DORA metrics, developed by the DevOps Research and Assessment team, are industry-standard measurements used to assess software delivery and operations performance by evaluating key indicators such as deployment frequency, lead time for changes, change failure rate, and time to restore service. GitLab has integrated a DORA Performers score panel into its Value Streams Dashboard to visualize the DevOps performance of different projects, helping executives identify strengths and weaknesses in their organization's DevOps processes. These metrics categorize teams into high, medium, and low performers, providing a framework for assessing DevOps maturity and effectiveness, with high performance indicating superior speed and stability in software delivery. GitLab's platform supports DORA metrics out of the box, facilitating score calculation through its unified data model, and these metrics are also available in CI/CD analytics charts and Insights reports for tracking historical performance. Organizations are encouraged to aim for high DORA scores, as they are associated with better business outcomes like increased efficiency, faster time-to-market, and improved software quality.
Jan 18, 2024 460 words in the original blog post.
GitLab Duo Pro, an add-on available to Ultimate and Premium customers, integrates AI-powered tools like Code Suggestions and Chat (Beta) to enhance DevSecOps workflows by improving developer efficiency and code security. Code Suggestions facilitate code completion and generation, while Chat provides real-time assistance with coding tasks, such as refactoring and test creation, across the software development lifecycle. The package emphasizes a privacy-first approach, ensuring customer code is not used for AI model training, and offers organizational controls to manage AI access. GitLab Duo Pro is available for various deployment options and is currently offered at an introductory price, with an increase planned for February 2024.
Jan 17, 2024 491 words in the original blog post.
In 2024, GitLab plans to enhance its package and container registries by introducing new features aimed at enterprise customers, which will allow them to consolidate artifact management on GitLab and reduce licensing costs associated with tools like JFrog and Sonatype. Key upgrades include a dependency proxy for Maven, npm, PyPI, and NuGet, as well as expanding support for external container registries beyond Docker Hub. These enhancements will streamline package management by allowing GitLab to fetch and cache packages from external repositories, improving pipeline reliability and reducing data transfer costs. Additionally, GitLab will focus on improving the container registry's user interface, performance, and security, including integrating with Google Cloud Platform's Artifact Registry to facilitate easier deployment of container images. These developments are aimed at making the GitLab Package and container registries more efficient, cost-effective, and user-friendly, though the details and timelines are subject to change.
Jan 16, 2024 630 words in the original blog post.
GitLab has introduced GitLab Duo Code Suggestions into general availability, leveraging Anthropic's generative AI model, Claude, to enhance developer productivity through AI-assisted code generation. Integrated within the GitLab Duo portfolio, this feature allows developers to generate complex algorithms or code blocks directly within their IDE by simply providing comments or multi-line comment blocks. This capability not only saves time and reduces effort on repetitive tasks but also ensures accuracy and safety, as Claude is designed to mitigate distracting or unsafe behaviors. GitLab emphasizes that this tool aligns with its principles of transparency and privacy by design, offering developers a reliable and efficient coding companion. Users are encouraged to explore this innovative tool by starting a free trial of GitLab Duo to experience the benefits of AI-assisted code generation.
Jan 16, 2024 427 words in the original blog post.
GitLab's DevSecOps Platform now features native integration with various AWS services via AWS CodeStar Connections and AWS CodePipeline, enhancing the synergy between GitLab and AWS environments. This integration, developed by the AWS CodeSuite service team, is available for GitLab.com SaaS, GitLab Self-Managed, and GitLab Dedicated, allowing seamless connection with AWS services like AWS CodePipeline and Amazon CodeWhisperer Customization Capability. By utilizing CodeStar Connections, GitLab CodePipeline configurations can also incorporate AWS CodeBuild, Amazon SageMaker MLOps Projects, and AWS CodeDeploy. This collaboration between GitLab and AWS aims to provide a superior experience for mutual customers, with comprehensive resources available in the GitLab AWS Integration Index documentation to guide users through these new and existing integrations.
Jan 11, 2024 222 words in the original blog post.
Git version 2.43, released on November 20, 2023, includes several enhancements contributed by GitLab's Git team, such as improved object segmentation and storage optimization through the git repack command with a new --filter option, which allows certain objects to be stored separately, potentially on cheaper storage. Additionally, a --exists option for git show has been introduced to provide a consistent method for checking object existence, addressing edge cases in the process. The --missing option of git rev-list has been extended to include commit objects, aiding in the next-generation repository replication efforts by enabling efficient tracking of new and necessary git objects. Furthermore, an update allows bare repositories to read gitattributes directly from the tree that HEAD points to by default, simplifying processes and reducing technical debt, particularly for Gitaly. Bug fixes include ensuring objects parsed from commit-graphs are checked for existence, with a new environment variable to enforce this check as needed.
Jan 11, 2024 713 words in the original blog post.
Pulumi offers a novel approach to managing infrastructure as code (IaC) by enabling platform engineers to use familiar programming languages like TypeScript, Python, and Go to automate GitLab CI/CD workflows. This method enhances version control, collaboration, and reproducibility, aligning with GitLab's philosophy. Pulumi supports over 150 cloud and SaaS products, including AWS and GitLab, and provides a free individual-use SaaS service for state file and secrets management. The integration between Pulumi and GitLab involves setting up GitLab projects, configuring AWS OpenID Connect providers, and creating CI/CD pipelines using Pulumi's declarative syntax. This setup allows for efficient management of resources and supports continuous integration and delivery by executing Pulumi commands during merge requests and branch updates. The use of general-purpose programming languages in Pulumi facilitates familiar tooling and syntax, enhancing the ease of infrastructure management. Pulumi's integration with GitLab includes features like webhooks for previewing changes directly in merge requests, and the use of Pulumi Policy Packs and Pulumi ESC can further enhance pipeline security and efficiency.
Jan 10, 2024 3,039 words in the original blog post.
GitLab has developed the GitLab Trust Center, a comprehensive and centralized portal powered by SafeBase, designed to enhance transparency and efficiency in managing customer assurance and security documentation. This interactive platform consolidates compliance, security, and privacy credentials, allowing customers to easily access or download necessary documents, some of which require signing an NDA for quick access. The Trust Center supports a self-service approach, enabling customers to submit questionnaires directly through the platform and subscribe for updates on security incidents, thereby streamlining the review process and promoting self-sufficiency. Emphasizing the company's commitment to transparency, the Trust Center also makes available a knowledge base with answers to common vendor review questions, reinforcing GitLab's role as a trusted partner in facilitating secure code development.
Jan 09, 2024 614 words in the original blog post.
In 2023, experts from GitLab and other organizations shared insights into the evolving field of DevSecOps, highlighting both challenges and opportunities, particularly in areas like AI, CI/CD, and security automation. The year's top technical blogs offered tutorials and best practices, such as transitioning from Jenkins to GitLab for enhanced CI/CD environments, using GitLab for U.S. Navy's Black Pearl, and leveraging GitLab's new CI/CD Catalog Beta. Other topics included improving DevSecOps workflows with python-gitlab API automation, integrating MLOps with DevSecOps, and using AI to develop a C++ adventure game. Additionally, insights were provided on automating security testing with GitLab's Red Team and the design inspirations for GitLab Dedicated, emphasizing the importance of adopting DevSecOps practices for improved software development processes.
Jan 09, 2024 593 words in the original blog post.
The GitLab Bug Bounty Program's 2023 recap highlights significant achievements, including awarding $843,639 across 318 valid reports from 1,277 submissions by 511 researchers, with 449 newcomers. The busiest month was June, with payouts exceeding $150,000. Notable contributors include mateuszek for the most valid reports, newcomer js_noob, and yvvdwf for best-written reports, while joaxcar and pwnie were recognized for innovation and impact, respectively. The program introduced 90-day challenges, including a high-stakes account takeover challenge, and hosted an "Ask a hacker AMA" session with @0xn3va, with ongoing updates available on their HackerOne page.
Jan 04, 2024 469 words in the original blog post.
GitLab Duo, an AI-enhanced suite of capabilities, is significantly boosting the efficiency and velocity of software development, impacting DORA metrics like deployment frequency and lead time for changes. This AI-driven advancement has introduced the concept of CI/CD hyperscale, where organizations handle large-scale computing for continuous integration and deployment jobs, with some customers already executing over 3 million jobs monthly. The emergence of AI-powered DevSecOps is expected to double the number of CI/CD jobs annually from 2024, necessitating a shift to consolidated DevSecOps platforms for enhanced efficiency. GitLab advocates for migrating from multiple CI systems to a singular platform to achieve CI/CD hyperscale, highlighting that users of their AI-powered DevSecOps Platform often experience rapid returns on investment. The platform's scalability and flexibility are underscored by the milestone of over 1 billion pipelines run, positioning it as a foundation for continuous improvement and adaptation to the competitive demands of AI-driven software development.
Jan 03, 2024 719 words in the original blog post.