DevOpsArk + GitLab
Repositories, CI, merge requests and registry
Vendor: GitLab Inc.
What does the DevOpsArk GitLab integration do?
The DevOpsArk GitLab integration connects projects and groups so builds, merge request checks, container registry publishing, secret scanning and deployment provenance are driven from GitLab.
What the GitLab integration provides
- Analyse projects to detect stacks and generate container definitions.
- Post scan and policy results as merge request widgets scoped to the diff.
- Trigger DevOpsArk pipelines from pushes, merge requests and tags.
- Call DevOpsArk stages from existing .gitlab-ci.yml pipelines.
- Publish to the GitLab Container Registry by immutable digest.
- Scan project content and history for committed credentials.
- Link deployed containers back to commits and merge requests.
Exactly what is read, and what can be written
Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.
- Project contents, manifests and lock files
- Commits, branches, tags and merge requests
- GitLab CI pipeline runs and job status
- Group and project membership for ownership mapping
- Container Registry images and tags
- Merge request comments and status checks
- Generated container definitions committed for review
- Images pushed to the GitLab Container Registry
- Environment and deployment records
Connecting GitLab
- 1Create an application
Register DevOpsArk as a GitLab application or supply a group access token.
- 2Select groups
Choose the groups and projects DevOpsArk should analyse.
- 3Configure the pipeline
Trigger DevOpsArk pipelines directly, or add DevOpsArk stages to .gitlab-ci.yml.
- 4Map ownership
Link GitLab groups to services so routing works.
Which modules use GitLab
ArkBuilder
AI-powered build and containerization
Pipelines
CI/CD pipelines with policy and provenance
Scanners
Image, code, IaC and secret scanning
ArkCD
Continuous delivery and progressive rollout
Secrets
Centralised secrets with rotation
Release Management
Coordinated releases across services
GitLab integration: frequently asked questions
Not necessarily. DevOpsArk stages can be invoked from .gitlab-ci.yml so you keep your existing pipelines, or DevOpsArk can run the delivery path itself. Teams commonly begin with the first.
Yes. Self-managed GitLab instances are supported, including those reachable only from inside your network.
Scan and policy results scoped to the changes in that merge request, as a widget and optional required status.
Yes, by immutable digest, with the scan verdict and SBOM recorded against the same build.
Integrations that commonly go with this one
Connect GitLab and see your own data
Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.