Change management controls in ISO 27001, NIS2, and SOC 2 all ask the same question: can unreviewed code reach production? If your code lives in GitLab, this integration answers it continuously: protected branches, approval rules, and secret detection verify on schedule, and drift opens a finding the day it happens. GitHub users: see the GitHub integration instead.
Prerequisites
- An OptiTech workspace with the Admin role.
- Owner on the GitLab group you're connecting (gitlab.com or self-managed).
Connect the integration
- In your GitLab group, create a group access token with
read_apiscope and the Reporter role. For self-managed instances, note your instance URL. - In the OptiTech Console, go to Integrations > GitLab, and enter the token and instance URL.
- Select which projects are in scope: all projects in the group (new ones inherit automatically) or a chosen subset.
- Run the first sync and confirm the project list matches your expectation.
Rotate the token on your standard credential schedule; OptiTech reminds you before it expires.
Checks the integration activates
- Protected branches: default and release branches verified protected, with force-push disabled.
- Approval rules: merge requests require the configured approvals, and authors can't approve their own changes, the segregation-of-duties evidence SOX ITGC and ISO 27001 both want.
- Secret detection: verified enabled in the pipeline configuration for in-scope projects.
- Member access: group and project members with elevated roles enumerated for access reviews, and offboarding checks confirm departed employees lose GitLab access too.
- Repository inventory: projects sync into the asset inventory, so new repos enter scope on creation.
Compliance checks in GitLab CI
Beyond monitoring settings, you can gate changes: run OptiTech's CLI in a GitLab CI job to check infrastructure changes against your controls before merge, the same compliance-as-code pattern as GitHub Actions. Add the job to your pipeline template so every project inherits it.
Verify the connection
- Confirm Status: Connected and a project count that matches your group.
- Filter Controls by Source: GitLab and review the results.
- Temporarily unprotect a branch in a test project and confirm the finding opens on the next sync, then re-protect it.
Troubleshooting
- Projects missing: the token's role is below Reporter, or the projects sit outside the connected group; subgroups are included, sibling groups are not.
- 401 errors after working: the token expired or was revoked; create a new one and update the integration.
- Self-managed instance unreachable: OptiTech's collectors need HTTPS access to your instance; allowlist the published egress IPs.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.