Skip to main content
integration · gitlab

GitLab Integration — gitlab.com and Self-Managed

What does the GitLab integration do?

zop.dev connects to gitlab.com or a self-managed GitLab with a single access token carrying read_api and read_repository scopes. Nested groups resolve correctly out of the box, and the connection is verified live against the API before it saves rather than failing at first build.

Coverage by category

Point zop.dev at gitlab.com or your self-managed GitLab with a single token and deploy straight from your projects. Nested groups work out of the box, and the connection is verified live before it saves.

read_api and read_repository, nested groups included

Uses the official GitLab API with a personal or group access token carrying read_api and read_repository scopes. For self-managed instances, provide your server URL; the API path is handled automatically. Project listing honors your membership, including nested subgroup paths.

Create the token, paste it, pick your projects

  1. In GitLab, create a personal or group access token with read_api and read_repository.
  2. Settings > Integrations > GitLab; paste the token (and server URL for self-managed).
  3. Pick projects and branches in the deploy flow.

Projects, branches, clones and self-managed support

Project and branch listing, clone access for builds, self-managed GitLab support, nested group support.

Personal or group token

A group access token is usually the better choice: it survives the person who created it leaving, and its reach is bounded to the group rather than to an individual’s full account. Personal tokens work identically and are the faster path for a trial.

Both need read_api and read_repository. Nothing more: zop.dev does not need write scope to build and deploy from a project.

Self-managed instances

Point the connection at your own host and the same two scopes apply. The verification step calls the API on save, so a firewall rule or an expired certificate surfaces immediately rather than as a confusing build failure days later.

Limits worth knowing before you connect

Token expiry follows your GitLab policy; rotate in place via the integration's edit form.

faq · gitlab

GitLab integration: common questions

What scopes does the GitLab token need?

read_api and read_repository, and nothing beyond them. zop.dev does not need write scope to list projects, clone code and deploy.

Does self-managed GitLab work?

Yes. Supply your server URL and the same two scopes apply; the API path is handled for you. The connection is verified against the API on save, so a firewall rule or an expired certificate surfaces immediately rather than as a confusing build failure days later.

Personal or group access token?

A group access token is usually better: it survives the person who created it leaving, and its reach is bounded to the group rather than to one individual's whole account. Personal tokens behave identically and are the faster path for a trial.

no live rules

No active rule family targets GitLab Integration — gitlab.com and Self-Managed today. Rules that used to are retired, and retired rules publish no pages and fire no findings. Scheduling and permissions coverage are unaffected.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·