HN user

dnsmichi

313 karma

Michael Friedrich is a Staff Developer Advocate at GitLab, focusing on Embedded DevSecOps and responsible AI adoption. “How does a computer work?” led him from Hardware/Software Systems Engineering to DNS, monitoring, and authoring GitLab training. Michael loves to educate and regularly speaks at industry events and meetups. When not traveling, he builds LEGO models and embedded hardware projects.

Posts21
Comments183
View on HN
github.com 2y ago

Bpftime: Userspace eBPF runtime for fast Uprobe and Syscall hook and Plugins

dnsmichi
94pts12
www.jedi.be 4y ago

DevSecOps – Developer Motivation vs. Business Prioritisation

dnsmichi
1pts0
www.polarsignals.com 4y ago

Fantastic Symbols and Where to Find Them – Part 2

dnsmichi
8pts0
medium.com 4y ago

Migrating a Dockerized Gitlab Chat Bot to ARM Graviton2 in an Afternoon

dnsmichi
1pts0
www.jumpingrivers.com 4y ago

Git: Moving from Master to Main

dnsmichi
1pts0
github.com 4y ago

Atlas: Secure communication for a distributed Thanos Deployment for Prometheus

dnsmichi
2pts0
falco.org 4y ago

Falco Plugins Early Access

dnsmichi
2pts0
slack.engineering 4y ago

Infrastructure Observability for Changing the Spend Curve at Slack

dnsmichi
1pts0
www.youtube.com 4y ago

How open source made observability mainstream

dnsmichi
2pts0
docs.docker.com 5y ago

Docker Compose CLI tech preview, no extra Docker-compose binary

dnsmichi
3pts0
twitter.com 5y ago

QuestDB 5.0.6 released with improvements for PostgreSQL wire protocol

dnsmichi
1pts0
blog.argoproj.io 5y ago

Argo Workflows v3.0

dnsmichi
68pts11
www.enricozini.org 5y ago

Gitlab Runners with Systemd Nspawn

dnsmichi
2pts0
everyonecancontribute.com 5y ago

Learning Rust with Gitpod Workshop

dnsmichi
4pts0
blog.shhdharmen.me 5y ago

Open source maintainers' must haves

dnsmichi
1pts0
dev.to 6y ago

Emojis everywhere – supercharged with Alfred workflows

dnsmichi
1pts0
about.gitlab.com 6y ago

Dotfiles – Document and automate your MacBook setup

dnsmichi
2pts0
dnsmichi.at 6y ago

First time all remote: Expect the unexpected

dnsmichi
1pts0
dnsmichi.at 6y ago

First time all remote: My first week at Gitlab

dnsmichi
3pts0
www.netways.de 6y ago

From Monitoring to Observability: Distributed Tracing with Jaeger

dnsmichi
1pts0
www.netways.de 6y ago

Automatic PDF Generation with Google Chrome

dnsmichi
1pts0

GitLab team member here. Tutorials are available in the docs [1] and this extensive blog tutorial [2]. Specific use cases with help from Agentic AI are discussed in this guide/whitepaper: "CI/CD modernization: Break down barriers with agentic AI" [3]

In my experience learning and leveraging AI and LLMs in the past 2 years, GitLab Duo understands CI/CD configuration very well and can help with migration questions, tasks, and plans, or with actions where Duo Agentic Chat even analyzes and edits files in the IDE.

If you are using GitLab Duo Agent Platform (currently in Beta), there is also a specific Flow that helps convert a Jenkins CI into a GitLab CI/CD configuration. [4] This was released in 18.3, a demo video is inside the release post [5] (demo project here [6]). You can also find the Agentic AI use case in my GitLab DACH Roadshow talk slides [7].

[1] https://docs.gitlab.com/ci/migration/jenkins/

[2] https://about.gitlab.com/blog/jenkins-to-gitlab-migration-ma...

[3] https://about.gitlab.com/the-source/ai/cicd-modernization-br...

[4] https://docs.gitlab.com/user/duo_agent_platform/flows/conver...

[5] https://about.gitlab.com/blog/gitlab-18-3-expanding-ai-orche...

[6] https://gitlab.com/gitlab-da/use-cases/ai/gitlab-duo-agent-p...

[7] https://docs.google.com/presentation/d/e/2PACX-1vTX-DcBV9Rw6...

Gitlab Duo 2 years ago

Great idea ;-)

But actually, no. I had these helpful tips in mind, and wanted to share them with everyone quickly. There is always an opportunity to learn together, and get inspired from feedback :-)

Gitlab Duo 2 years ago

GitLab team member here. Thanks for your feedback.

GitLab Duo provides AI-assisted features in the DevSecOps lifecycle. GitLab Duo Chat was released as GA last week [0] Code Suggestions are GA, too, and help with code completion and generation [1] The documentation provides more insights on availability and usage [2]

Helpful learning resources:

If you are looking for practical examples and prompt tips for Duo Chat, bookmark this longer tutorial "10 best practices for using AI-powered GitLab Duo Chat" in [3]

We have also updated the documentation to add hands-in GitLab Duo examples for different programming languages and environments, helping with how to integrate AI into your workflows efficiently: [4]

At QCon London 2024 two weeks ago, I spoke about "Efficient DevSecOps workflows with a little help from AI." The slides are publicly available at [5], talk summary in [6]

I also recommend the blog post "How to put generative AI to work in your DevSecOps environment" [7] to tackle important questions such as workflow assessments, AI guardrails and how to measure AI impact in your organization.

Last but not least, I started a learning series called "GitLab Duo Coffee Chat" on YouTube [8], showing AI and GitLab Duo in action. I plan to host more sessions in the coming weeks. [9]

Happy to help with more adoption questions, best practices, and development workflows :-)

[0] https://about.gitlab.com/blog/2024/04/18/gitlab-duo-chat-now...

[1] https://about.gitlab.com/blog/2023/12/22/gitlab-duo-code-sug...

[2] https://docs.gitlab.com/ee/user/ai_features.html

[3] https://about.gitlab.com/blog/2024/04/02/10-best-practices-f...

[4] https://docs.gitlab.com/ee/user/gitlab_duo_examples.html

[5] https://go.gitlab.com/ZDYNXQ

[6] https://qconlondon.com/presentation/apr2024/efficient-devsec...

[7] https://about.gitlab.com/blog/2024/03/07/how-to-put-generati...

[8] https://www.youtube.com/playlist?list=PL05JrBw4t0Kp5uj_JgQiS...

[9] https://gitlab.com/groups/gitlab-com/marketing/developer-rel...

GitLab team member here.

How many distros now have their own GitLab instance?

Open Source project partners are listed in https://about.gitlab.com/solutions/open-source/partners/

More insights into GitLab for Open Source in https://about.gitlab.com/solutions/open-source/ and the Open Source program handbook page in https://handbook.gitlab.com/handbook/marketing/developer-rel... -- created an MR to update the section at the bottom with Hacker News examples. https://gitlab.com/gitlab-com/content-sites/handbook/-/merge...

GitLab is down 3 years ago

GitLab team member here.

Thanks for the feedback, I have forwarded it to our teams investigating the incident.

The search works great. I'm using MkDocs with Material as my personal handbook because of the simplicity -- for example, I usually remember great articles in conversations but always forget their location. Since I started writing my newsletter https://opsindev.news/ including an MkDocs web archive, I can share interesting URLs way faster :) Or let folks discover it by themselves, using the search.

Configuration in https://gitlab.com/dnsmichi/opsindev.news/-/blob/main/mkdocs...

Material for MkDocs also has an insiders build, accessible through sponsorship. https://squidfunk.github.io/mkdocs-material/insiders/ These features add more value to MkDocs -- I initially joined to get GDPR-compliant cookie banners and stayed to support a great project.

GitLab team member here, thanks for sharing.

Still not a big fan of how stiff Yaml pipelines feel in Gitlab CI

Maybe the pipeline editor in "Build > Pipeline editor" can help with live linting, or more advanced features such as parent-child pipelines or merge trains.

If you need tips for optimizing the CI/CD pipeline, suggest following these tips in the docs https://docs.gitlab.com/ee/ci/pipelines/pipeline_efficiency.... or a few more tips in my recent talk "Efficient DevSecOps pipelines in cloud-native world", slides from Chemnitz Linux Days 2023 in https://docs.google.com/presentation/d/1_kyGo_cWi5dKyxi3BfYj...

and that tickets for what seems like a simple feature [1] hang around for years, but it is nice.

Thanks for sharing. (FYI for everyone) The linked issue suggests a Docker cache cleanup script, which might be helpful. https://gitlab.com/gitlab-org/gitlab-runner/-/issues/27332#n... -> https://docs.gitlab.com/runner/executors/docker.html#clear-t...

GitLab team member here, thanks for sharing.

It lacks most collaboration options for non-developer users, but we found that they are rarely, if at all, used anyway. Non-developer users can still use an edit button that points to GitLab's web editor and update the docs that way.

Maybe the wiki in GitLab provides a possible path forward. https://docs.gitlab.com/ee/user/project/wiki/

The wiki uses the same Rich Text editor as known from issue/MR comments, aiding visual editing with context actions - for example, Markdown tables, rows, columns, or uploading and resizing images.

Material for MkDocs.

I personally love this project. I'm using it for o11y.love and opsindev.news published via GitLab pages. Editing happens mainly in the browser, using the Web IDE.

Sources in case you are interested:

https://gitlab.com/everyonecancontribute/observability/o11y....

https://gitlab.com/dnsmichi/opsindev.news

PS: Tip for faster editing files using the Web IDE in the browser: Press `.` on a repository view which opens the Web IDE immediately.

Thanks for your feedback. GitLab team member here.

We(as in everyone) are in a serious need of a new git server product. Just do git serving, and do it well. Preferably in a way multiple nodes can be run active-active for scaling and reliability. No need for cicd (Jenkins is fine for that, thank you very much).

You can integrate Jenkins into GitLab. https://docs.gitlab.com/ee/integration/jenkins.html Suggest considering a migration to GitLab CI/CD in your migration planning, following the updated documentation: https://docs.gitlab.com/ee/ci/migration/jenkins.html and more automated imports in https://about.gitlab.com/blog/2023/09/26/atlassian-server-en...

Web hooks sending and receiving. For example launch a merge request webhook(to lambda via aws api gateway, or to Jenkins). Receive a webhook as merge request approval when some Jenkins job finishes.

(FYI) https://docs.gitlab.com/ee/user/project/integrations/webhook... and https://docs.gitlab.com/ee/user/project/integrations/webhook...

You can trigger a pipeline from external webhooks using a trigger token, and execute an action against the GitLab REST API. The example for triggering pipelines in https://docs.gitlab.com/ee/ci/triggers/#trigger-a-pipeline can be expanded into more actions, i.e. using the API to create MR approvals or comments.

For Python, I'd recommend looking into python-gitlab and this tutorial blog post: https://about.gitlab.com/blog/2023/02/01/efficient-devsecops...

if you create cicd jobs/pipelines there is no way to giving someone an ability to run that pipeline without giving that person ability to push to the repository and submit merge requests. Yes, you can then set it so approval is needed before merge, protecting said pipeline, but why? There has been a ticket on gitlabs own issues page about it for years and it is still not resolved.

Please share the URL :)

When creating a new GitLab project, the default branch is protected by default, and only maintainer roles can push to the default branch. https://docs.gitlab.com/ee/user/project/protected_branches.h...

A developer role can create non-protected Git branches, merge requests, and as such trigger a pipeline from a merge request. You've mentioned approval rules as a safeguard already - CODEOWNERS can be an additional way to ensure that review workflows are followed. https://docs.gitlab.com/ee/user/project/codeowners/

You can also use branch protection rules to allow `No one` for push actions, i.e. any branch that matches the pattern, except for `main` or git tag patterns. https://docs.gitlab.com/ee/user/project/protected_branches.h...

Gitlab enterprise has no mode of working that let's you have more than one active server at a time so goodbye horizontal scaling.

Suggest reviewing the reference architectures documentation in https://docs.gitlab.com/ee/administration/reference_architec... to decide whether horizontal scaling is needed for your environment.

For distributed environments, suggest looking into Geo: https://docs.gitlab.com/ee/administration/geo/index.html

You want to scale your cicd worker nodes? They want you to use docker mashine(a deprecated product) instead of writing a Plugin like ec2-fleet for Jenkins.

The current GitLab CI/CD runner architecture involves docker-machine, based on a fork maintained by GitLab. This fork receives security and bug fixes to ensure users and customers can rely on auto-scaling in production. https://gitlab.com/gitlab-org/ci-cd/docker-machine#%EF%B8%8F... Please review the support statement in https://gitlab.com/groups/gitlab-org/-/epics/2502 to learn more for how long the fork remains supported.

The new auto-scaling architecture provides a task scheduler, and so-called fleeting plugins. You can review the architecture blueprint in https://docs.gitlab.com/ee/architecture/blueprints/runner_sc... and follow the documentation in https://docs.gitlab.com/runner/runner_autoscale/

If you prefer a timeline, please follow the Docker Machine Replacement Project Plan in https://gitlab.com/groups/gitlab-org/-/epics/6995 For example, the AWS EC2 Fleeting plugin is available in Beta since GitLab 16.5 and scheduled for 16.7 GA, see the epic https://gitlab.com/groups/gitlab-org/-/epics/8856

When using Kubernetes, you can take advantage of the Kubernetes executor to auto-scale pods. https://docs.gitlab.com/runner/executors/kubernetes.html

To optimize the CI/CD infrastructure next to auto-scaling, these tips might be handy, too: https://docs.gitlab.com/ee/ci/pipelines/pipeline_efficiency....

into saas.

Next to GitLab self-managed and SaaS, you can also use GitLab Dedicated, where you get access your own isolated cloud instance. https://about.gitlab.com/blog/2023/08/03/building-gitlab-wit...

Email and Git = <3 3 years ago

Thanks for sharing. GitLab team member here.

More GitLab push options are documented in https://docs.gitlab.com/ee/user/project/push_options.html

You can also add a parameter to merge the merge request when the pipeline succeeds. This can be handy for quick fixes that do not require reviews, and avoids unnecessary context switches.

# mwps BRANCHNAME

alias mwps='git push -u origin -o merge_request.create -o merge_request.target=main -o merge_request.merge_when_pipeline_succeeds'

Example from https://gitlab.com/sytses/dotfiles/-/blob/master/git/aliases... and https://about.gitlab.com/blog/2021/10/19/top-10-gitlab-hacks...

If you prefer deeper CLI integration, suggest installing the GitLab CLI: https://docs.gitlab.com/ee/editor_extensions/gitlab_cli/

GitLab team member here.

In practice, customers can also make requests via private support tickets.

Yep. Sometimes, it can also be helpful to ask publicly in a forum topic or issue and link that in the support ticket, asking for prioritized support.

I’ve seen GitLab determine priority of an issue based partially on demand from paying customers.

Correct. You might have seen team members commenting with customer requests into issues and epics. While we at GitLab cannot share customer names and other confidential data, the feature request itself is public and increases transparency.

The process is documented in the product handbook: https://about.gitlab.com/handbook/product/product-processes/...

Thanks for your feedback.

Requests are triaged using automation and AI, and responsible teams include the reviews in their planning. [0]

Issues (and related MRs) are targeting milestones. Since we at GitLab work in iterations and smaller changes to release features faster, epics help plan and group the issues. Roadmaps and boards are used by product managers, too. [1] [2] Example roadmap filtered by the CI section [3]

Every stage, group, feature has labels applied, which allows the creation of specific filters. For example, "Category:Code Suggestions" as label filter [4]

Additional helpers are available in the handbook, for example the "Features by group" overview [5] which shows the feature maintainers in the section, stage, group, product and engineering managers, etc.

Customers can open support tickets, too. [6] Opening a public issue is encouraged so other community members can engage and collaborate. Often, a workaround or fast solution is unveiled because of collaboration and transparency.

When in doubt whether it is a bug or feature, or asking for (troubleshooting) help, you are welcome to join our community forum or Discord. [7] I'm mostly active on the forum myself. [8]

[0] https://about.gitlab.com/handbook/engineering/quality/issue-...

[1] https://about.gitlab.com/direction/#how-we-plan-releases

[2] https://about.gitlab.com/handbook/product/product-processes/...

[3] https://gitlab.com/groups/gitlab-org/-/roadmap?state=opened&...

[4] https://gitlab.com/gitlab-org/gitlab/-/issues/?label_name%5B...

[5] https://about.gitlab.com/handbook/product/categories/feature...

[6] https://about.gitlab.com/support/

[7] https://about.gitlab.com/community/

[8] https://forum.gitlab.com/u/dnsmichi/summary

GitLab team member here. Thanks for your feedback.

Request: The new UI has "Admin" link hidden which is hard to find. I liked the old UI better (explicit is better than implicit).

This was reported in the new navigation feedback issue [0] and is being worked on in [1]. Suggest adding your comment/upvote there too.

Question: Is the open source code the same as the Enterprise versions of the code? (how do you implement feature differences?)

The source code for GitLab is located in a single repository. The change was proposed and introduced in 2019 for efficiency reasons [2] [3] [4]

You can learn more about the stewardship of GitLab, and the promises in [5] - point 11) links to the enterprise code location, and the free open source location.

This workflow also ensures that everyone can contribute to GitLab [6] - free users, and customers [7], using the same code base.

[0] https://gitlab.com/gitlab-org/gitlab/-/issues/409005#what-we...

[1] https://gitlab.com/gitlab-org/gitlab/-/issues/415854

[2] https://about.gitlab.com/blog/2019/02/21/merging-ce-and-ee-c...

[3] https://about.gitlab.com/blog/2019/08/23/a-single-codebase-f...

[4] https://about.gitlab.com/blog/2019/10/02/contributor-after-s...

[5] https://handbook.gitlab.com/handbook/company/stewardship/#pr...

[6] https://about.gitlab.com/community/contribute/

[7] https://docs.gitlab.com/ee/development/contributing/#contrib...

Whatever spark they were feeling in the moment would be sufficiently stomped when they notice the first step in the tutorial is to create a Makefile. Keep in mind they also introduce the concept of variables and if statements. This tutorial's aimed at total beginners!

Thanks for your great feedback. I suggested using a Makefile during blog post review [0], to avoid explaining gcc compiler flags, and have a single command with `make build` available for future, repeated compilation steps. I did not expect this to be an entry barrier, and will reconsider suggesting makefiles in the future. Thanks again.

[0] https://gitlab.com/gitlab-com/www-gitlab-com/-/merge_request...

(GitLab team member here)

Gitlab.com is down 3 years ago

GitLab team member here.

Next to all-in-one packages provided with the Omnibus package on Linux https://docs.gitlab.com/omnibus/ and in containers https://docs.gitlab.com/ee/install/docker.html you can also install GitLab into Kubernetes clusters using the Operator https://docs.gitlab.com/operator/ or Helm Chart. https://docs.gitlab.com/charts/

Most of GitLab.com SaaS is deployed on Kubernetes using the GitLab cloud-native Helm chart (with a few exceptions). More details in https://about.gitlab.com/handbook/engineering/infrastructure...

Gitlab.com is down 3 years ago

GitLab team member here. Thanks for asking.

Incidents can have different types, i.e. when an application bug or performance regression is discovered, this can involve reverting MRs and rolling back releases. The Platform, Delivery group has a top-level responsibility for ensuring continuous delivery of the GitLab application software to GitLab SaaS, https://about.gitlab.com/handbook/engineering/infrastructure...

Other incidents may involve hardware or infrastructure failures, or a combination of both, infrastructure failure that renders GitLab application services unavailable. This requires cross-functional collaboration from infrastructure, product, engineering, etc. teams in the incident.

To get a better understanding here, it is helpful to review the incident management handbook https://about.gitlab.com/handbook/engineering/infrastructure...

Additional helpful information:

- The GitLab.com SaaS production architecture is documented in https://about.gitlab.com/handbook/engineering/infrastructure...

- The Monitoring of GitLab.com handbook provides insights into monitoring workflows, incident management, SLAs, etc. https://about.gitlab.com/handbook/engineering/monitoring/

- Runbooks https://about.gitlab.com/handbook/engineering/infrastructure...

For the current incident discussed in this HN thread, the review issue can be followed in https://gitlab.com/gitlab-com/gl-infra/production/-/issues/1... to learn more.