ProdgatorDocs
Provider adapters

GitLab CI adapter

Reference for the GitLab CI adapter. Webhook events, verification, status mapping and limits.

The GitLab adapter turns GitLab webhook events into Prodgator runs, jobs and deployments. To set it up, see Connect GitLab. Only gitlab.com is supported.

Events

GitLab event ()Prodgator record
Pipeline HookPipeline run; also wakes the merge request gate of the commit
Job HookJob (stage) of a run; a finished job wakes the merge request gate of the commit
Deployment HookDeployment
Merge Request HookMerge request gate (see Pull request gates on GitLab) and SPACE metrics; actions , , , , , , , and
Push HookPolicy sync from the repository, only for a push to the default branch that changes

Other events (Tag Push Hook, Release Hook, Note Hook and the rest), other merge request actions and other pushes are acknowledged and dropped.

Compared with GitHub

GitHub eventGitLab event
Pipeline HookSame records
Job HookSame records
, Deployment HookSame records; a deployment waits for approval
NoneGitLab has no external deployment rule; Prodgator approves protected environments through the API instead
, Merge Request HookGates and SPACE metrics. GitLab approvals count as reviews; review comments are not read
, , Pipeline Hook, Job HookWake the merge request gate when the commit's pipeline or a job finishes
Pipeline HookMerge train pipelines are merge request pipelines
Push HookPolicy sync from the repository
Dependabot, code scanning and secret scanning alertsNone usedGitLab findings come from uploaded reports
, (tags)Release Hook, Tag Push HookNot used on either provider

Webhook verification

Each connection has its own webhook URL, , and its own secret token. GitLab sends the token in the header. Prodgator compares it with the connection's stored token and answers if it does not match.

Status mapping

GitLab statusProdgator statusPipelines tab
, , , , Queued
Running
Awaiting approval
Success
Failed
Cancelled
Cancelled

Field mapping

GitLab fieldProdgator field
Run ID
Branch
Commit
Duration
, else Release name
(Deployment Hook)Release name of the deployment
Repository
Actor
Job name
Job status

Deployments

Every Deployment Hook is recorded, for any environment. A deployment to an unprotected environment is marked Not gated.

Protected environment approvals are sent with the approver's own linked GitLab account, because GitLab records the token's owner as the approver. See Approve deployments.

Re-run a job

and above can re-run one finished job from its row. Prodgator calls with the connection's token, never a person's linked account. A retried manual job waits as manual; Prodgator does not start it.

Logs

Prodgator reads job logs through the GitLab API with the connection's token.

Limits

  • Self-managed GitLab is not supported.
  • Merge request pipelines show the source branch.
  • Parent and child pipelines show as separate runs.
  • If GitLab only allowed per-project webhooks (no Premium), projects added to the group later are not covered. Reconnect the group to add them.
  • Policy files in a GitLab project bind its deployment environments by environment name only; a in a binding is ignored, since GitLab deployments name no workflow.
  • GitLab lists at most 20 commits in a Push Hook. A push with more is treated as changing the policy folder, and Prodgator reads the default branch to find out.

On this page