Skip to content

This is the Experimental version (Latest). It is under active development and may change. For the most reliable documentation, use the version selector in the top-right to switch to Stable, or click here to go to the Stable version's homepage.

GitLab Configurations on Web Interface

Last updated:

Some of Configurations and Opstella Integrations are done on Web Interface.

You need to access gitlab.${BASE_DOMAIN} and Login with root User Account.

  1. Sign In to GitLab Instance with root Local Account and Create Access Token for Opstella

    Go to Profile Logo > Preferences > Access Tokens

    Create new Access Token named opstella-platform with the following scope

The scopes ticked in the screenshot, as text:

ScopeWhy
apieverything Opstella does against GitLab (already covers read_api, read_repository, write_repository)
read_userresolve the user behind a request
create_runnerregister the Opstella-managed GitLab Runner
k8s_proxyGitLab’s Kubernetes proxy endpoints
sudo, admin_modeact as another user and perform admin actions
ai_features, read_service_pingonly if those features are used on this instance
  1. Customize Site Information: Go to Admin Area > Settings > Appearance

    • Sign in/Sign up pages : GitLab | <Customer Name>
    • Sign in/Sign up pages > Logo : Upload Logo of Customer
    • Navigation bar : Upload Logo of Customer

Auto DevOps feature that built-in with GitLab may cause unexepected behaviour when integrating with Opstella, you need to disable it.

  1. Sign In to GitLab Instance with root Local Account and then Go to Admin Area > Settings > CI/CD

  2. Open Continuous Integration and Deployment and untick Default to Auto DevOps pipeline for all projects

  3. Scroll down and click Save changes

Alternative: configure with gitlab-rails runner

Section titled “Alternative: configure with gitlab-rails runner”

Everything on this page is also reachable from the GitLab host itself, which is the way through when the web interface is not available yet (no DNS, ports not open, certificate not trusted).

/tmp/gl-setup.rb
# 1. Disable instance-wide Auto DevOps
ApplicationSetting.current.update!(auto_devops_enabled: false)
# 2. Create the Access Token for Opstella
want = %w[api read_api read_user create_runner k8s_proxy read_repository
write_repository ai_features sudo admin_mode read_service_ping]
use = want & Gitlab::Auth.all_available_scopes.map(&:to_s)
root = User.find_by_username('root')
t = root.personal_access_tokens.create!(name: 'opstella-platform', scopes: use,
expires_at: 365.days.from_now.to_date)
File.write('/tmp/pat.line', "export GITLAB_OPSTELLA_PLATFORM_TOKEN='#{t.token}'\n")
File.chmod(0600, '/tmp/pat.line')
Terminal window
sudo gitlab-rails runner -e production /tmp/gl-setup.rb
# move the token to the Bastion Host without printing it, then remove the source
sudo cat /tmp/pat.line >> $BASE_WORKING_DIR/shell-values/tools/gitlab.vars.sh
sudo rm -f /tmp/pat.line /tmp/gl-setup.rb

Verify:

Terminal window
sudo gitlab-rails runner -e production \
'puts ApplicationSetting.current.auto_devops_enabled;
puts PersonalAccessToken.find_by(name: "opstella-platform")&.expires_at'

Finished?

Use the below navigation to proceed