Docs
Reference

GitLab Self-Managed CI/CD variables

Sync CI/CD variables with a project on your own GitLab instance.

Sync CI/CD variables with a project on your own GitLab instance.

The connection

WhatThis provider
VendorGitLab
Keygitlab-self-managed-variables
Availabilityavailable. You can connect it today.
Credential penv holdsgitlab-self-managed-token
Values read backyes
Activationimmediate

What it moves

DirectionWhat it does
importReads names and values out of the store into penv.
exportWrites names and values from penv into the store.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
tokenAccess tokensecret, masked here and sealedyesA personal access token on your instance with the api scope.

What the connection asks for

Fixed when you connect, and shared by every mapping on it.

FieldLabelKindRequiredAdvancedWhat it is
instanceUrlInstance URLtextyesnoMust be reachable from the internet for us to read and write there.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
projectIdProjecttextyesnoThe project path from its URL, or the numeric ID under Settings → General.
environmentScopeEnvironment scopetextyesyes* covers every environment. Name one to keep this sync off the others. Starts at *.
maskedHide values in job logsyes or noyesyesOn, GitLab redacts the value if a job prints it. Values with spaces cannot be masked. Starts at false.
protectedProtected branches onlyyes or noyesyesOn, only jobs on protected branches and tags can read it. This sync never turns it off. Starts at false.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
user:readevery directionyesWe cannot confirm which GitLab account this token belongs to.
variables:readimportyesImport cannot read variable values.
variables:writeexportyesExport cannot write anything.