Get in Touch

Course Outline

DevSecOps Sovereignty with GitLab for Government

  • Comparative analysis of GitLab Community Edition (CE), Enterprise Edition (EE), and GitLab.com regarding functional capabilities and administrative control.
  • Architectural considerations for Omnibus deployments and Kubernetes Helm chart implementations.
  • Assessment of proprietary SaaS vendor lock-in risks and compliance with data residency mandates.

Deployment and Architectural Configuration

  • Implementation of the Omnibus package on Ubuntu environments using PostgreSQL and Redis services.
  • Deployment of GitLab via Helm charts on Kubernetes clusters with configured persistent storage volumes.
  • Integration of external dependencies including object storage, SMTP services, and LDAP directories.
  • Configuration of Geo replication to support multi-region disaster recovery strategies.

Repository and Project Governance

  • Structuring organizational hierarchies using groups, subgroups, and nested projects.
  • Defining merge request workflows, code review standards, and approval rule enforcement.
  • Leveraging issue boards, epics, and milestones to facilitate Agile planning and execution.
  • Management of documentation via wikis, code snippets, and release cycles.

CI/CD Pipeline Engineering

  • Authoring .gitlab-ci.yml configurations, defining stages, and managing job dependencies.
  • Selection and management of shared, group-specific, and project-specific runners.
  • Utilization of Docker and Kubernetes executors with automated resource scaling.
  • Management of build artifacts, registry publishing, and deployment phase automation.

Security Scanning and Compliance

  • Integration of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and vulnerability scans for dependencies and containers.
  • Detection of hardcoded secrets and enforcement of software license compliance.
  • Centralized vulnerability dashboards and tracking systems for remediation efforts.

Authentication and Authorization Frameworks

  • Configuration of LDAP, SAML, and OpenID Connect for Single Sign-On (SSO) capabilities.
  • Enforcement of two-factor authentication and management of personal access tokens.
  • Implementation of IP allowlisting controls and comprehensive audit event logging.

Registry and Package Administration

  • Administration of the container registry, including authentication, retention policies, and replication.
  • Management of the package registry for ecosystems such as Maven, npm, PyPI, and Conan.
  • Upload and management of generic packages for internal artifact distribution.

Performance Monitoring and Scalability

  • Collection of metrics via GitLab Exporter and visualization through Grafana dashboards.
  • Optimization of database performance and configuration of PgBouncer for connection pooling.
  • Horizontal scaling strategies for web servers, API endpoints, and background process nodes.
  • Establishment of backup protocols using rake tasks, object storage, and restore verification procedures.

Requirements

  • Proficiency in advanced Linux system administration and foundational knowledge of Ruby and Go programming languages.
  • Working knowledge of CI/CD concepts, container orchestration, and Git version control workflows.
  • Operational experience with PostgreSQL and Redis in high-volume or production-scale environments.

Audience Profile

  • Enterprise DevOps teams tasked with migrating from GitLab.com or GitHub Enterprise to self-hosted solutions.
  • Organizations requiring full sovereignty over their DevSecOps toolchain for compliance and security purposes.
  • Entities within regulated industries that mandate on-premise CI/CD and registry services for data protection.
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories