Reference
GitLab CI/CD
Move CI/CD variables to and from one GitLab project.
Move CI/CD variables to and from one GitLab project.
The connection
| What | This provider |
|---|---|
| Vendor | GitLab |
| Key | gitlab-variables |
| Availability | available. You can connect it today. |
| Credential penv holds | gitlab-token |
| Values read back | yes |
| Activation | immediate |
What it moves
| Direction | What it does |
|---|---|
import | Reads names and values out of the store into penv. |
export | Writes names and values from penv into the store. |
When a written value goes live
immediate. The running app sees a new value at once.
What happens to a name that exists
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
How you connect
You paste a credential you already hold. penv seals it and never shows it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
token | Access token | secret, masked here and sealed | yes |
What a mapping asks for
Answered once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
projectId | Project | text | yes | no | The project path from its URL, or the numeric ID under Settings → General. |
environmentScope | Environment scope | text | yes | yes | * covers every environment. Name one to keep this sync off the others. Starts at *. |
masked | Hide values in job logs | yes or no | yes | yes | On, GitLab redacts the value if a job prints it. Values with spaces cannot be masked. Starts at false. |
protected | Protected branches only | yes or no | yes | yes | On, only jobs on protected branches and tags can read it. This sync never turns it off. Starts at false. |
Permissions it needs
penv probes for these when it verifies the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
user:read | every direction | yes | We cannot confirm which GitLab account this token belongs to. |
variables:read | import | yes | Import cannot read variable values. |
variables:write | export | yes | Export cannot write anything. |