The module lifecycle stageGeneral Availability
The module has requirements for installation

1.13

1.13.4

Gitlab Version: 19.2.4_0

  • Module:
    • fix:
      • Fixed preflight check for postgres extensions
    • docs:
      • Updated alerts table on maintenance page with actual severity level
      • Updated guide for custom certificate setup
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE to 19.2.4
      • Mitigated security issues CVE-2026-19478 and CVE-2026-19650 - a critical code injection issue via a GraphQL directive and a cross-site request forgery issue in the GraphQL multiplex query handler
    • features:
      • Added merge request title validation - project maintainers can define a required title pattern and example, and merge requests with nonmatching titles are blocked from merging

1.13.3

Gitlab Version: 19.2.2_0

  • Module:
    • fixes:
      • Added more sidekiq related panels to Grafana Dashboard
      • Bumped Golang version to 1.25.13
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE to 19.2.2
      • Fixed sign in when LDAP group sync error occurs
      • Fixed approval rules in merge quests from forked repo
      • Fixed approval rules bypass by administrator

1.13.2

Gitlab Version: 19.2.1_2

  • Module:
    • fixes:
      • Added soft pod anti-affinity and topology spread constraints for haproxy and gitaly to improve pod distribution across nodes in HA mode
  • DeckhouseCode:
    • fixes:
      • Fixed branding, description and translation on Help page
      • Fixed writing audit events to current database table

1.13.1

Gitlab Version: 19.2.1_1

  • DeckhouseCode:
    • features:
      • Improved interface localization
      • Improved the relevance of code search and result previews. Files containing verbatim phrases now appear above files containing the same words scattered throughout the text, and pasting a code fragment with quotation marks and punctuation into the search bar no longer returns empty results
    • fixes:
      • Fixed a read timeout for the OpenSearch client. If the cluster accepts a connection but stops responding, search, index admin pages, and background indexing will fail with an error instead of waiting indefinitely; the timeout duration is configurable in fe.search.opensearch
      • Minor interface changes have been made to better comply with the company’s branding guidelines
      • The remaining telemetry channels have been closed - the version check setting is always reported as disabled, it cannot be enabled either in the admin panel or via the API, and the billing event endpoints introduced in 19.2.1 have been reset. The instance does not send anything out
      • The failure reason in the CI job status tooltip has been translated into Russian - the failed job tooltip no longer mixes the two languages
      • On the project import form by URL, the “Mirror repository” checkbox is enabled - the imported repository is immediately configured as a mirror

1.13.0

Gitlab Version: 19.2.1_0

  • Module:
    • fixes:
      • Bumped haproxy version to v3.4.3
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 19.2.1
      • Updated translation on import project page
      • Removed creation limit from service accounts
    • features:
      • Added Scoped labels for issues, merge requests

1.12

1.12.5

Gitlab Version: 19.1.6_0

  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 19.1.6

1.12.4

Gitlab Version: 19.1.4_0

  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 19.1.4

1.12.3

Gitlab Version: 19.1.3_0

  • DeckhousCode:
    • fixes:
      • Updated Gitlab CE version to 19.1.3

1.12.2

Gitlab Version: 19.1.2_1

  • Module:
    • fixes:
      • Fixed mount for registry db credentials
      • Disable db partition sync on webservice and toolbox deployment
      • Optimize rails load for Jobs, including migrations
  • DeckhouseCode:
    • fixes:
      • Fixed server error on global search requests

1.12.1

Gitlab Version: 19.1.2_0

  • Module:
    • docs:
      • Added project import/export docs to FAQ
      • Small fixes in module documentation layout
    • fixes:
      • Edited alerts severity levels
      • Added new alert for unavailable repositories in Gitaly
      • Added SecurityPolicyExceptions for workload
  • DeckhouseCode:
    • features:
      • Added Merge results pipelines
      • Added global search api
      • Added notification about missing license
    • fixes:
      • Updated Gitlab CE version to 19.1.2
      • Fixed bug with approvals sidebar

1.12.0

Gitlab Version: 19.1.1_3

  • Module:
    • features:
      • Added global search feature for CRD CodeInstance
      • Added support for internal mode for opensearch instance
      • Added separate sidekiq deployment for global search feature
      • Added support for MTLS using the Istio module
    • fixes:
      • Bumped Golang version to 1.25.12
      • Bumped haproxy version to v3.4.2
      • Fixed registry migration job healthchecks
      • Added message in status field if preprocessing CodeInstance error occurs
      • Fixed toolbox tmp pvc reconcile
      • Fixed rediss preflight check
    • docs:
      • Removed step duplicate in registry v2 migration guide
  • DeckhouseCode:
    • features:
      • Added External Status Checks for merge requests
      • Added OpenSearch support
      • Added a toggle to disable Code Owners approval checks
      • Added redirect path and user agent to unauthenticated audit event
      • Added maintenance mode
      • Added pull mirroring silent mode
    • fixes:
      • Updated Gitlab CE version to 19.1.1
      • Added auto-assign Code Owners as reviewers
      • Fixed approval rules for MRs created without a rules param
      • Cleaned up Russian translations and fixed maintenance message wording
      • Fixed search on Security Credentials admin pages
      • Updated user select label for multiple selections
      • Fixed selection single id_token for Vault CI secrets
    • chores:
      • Removed include directive support in CODEOWNERS

1.11

1.11.2

Gitlab Version: 19.0.3_0

  • Module:
    • fixes:
      • Bumped haproxy version to v3.4.1
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 19.0.3

1.11.1

Gitlab Version: 19.0.2_1

  • Module:
    • fixes:
      • Fixed registry migration job fail on healtcheck
      • Fixed server-side backups
      • Bumped haproxy version to v3.4.0

1.11.0

Gitlab Version: 19.0.2_1

  • Module:
    • fixes:
      • Fixed s3 storage configuration to support aws sdk update
  • DeckhouseCode:
    • fixes:
      • Fixed s3 storage configuration to support aws sdk update
      • Add Prometheus metrics for pull mirroring
      • Granular permisions and fix auditor
      • Guard application setting when table does not exists

1.10

1.10.10

Gitlab Version: 18.11.6_0

  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 18.11.6

1.10.9

Gitlab Version: 18.11.5_1

  • DeckhouseCode:
    • fixes:
      • Guard fe application setting when table does not exists

1.10.8

Gitlab Version: 18.11.5_0

  • Module:
    • fixes:
      • Fixed operator sa token rotation
      • Bumped Golang version to 1.25.11
    • features:
      • Added cluster alert for token rotation errors
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 18.11.5

1.10.7

Gitlab Version: 18.11.4_0

  • Module:
    • fixes:
      • Fixed gitaly statefulset drop hook

1.10.6

Gitlab Version: 18.11.4_0

  • Module:
    • fixes:
      • Fixed gitaly statefulset deploy on k8s 1.34
      • Fixed missing common webservice pod labels
      • Fixed missing PVC storage class name in gitaly stateful set template

1.10.5

Gitlab Version: 18.11.4_0

  • Module:
    • fixes:
      • Fixed ssh session rate panel on monitoring dashboard
      • Fixed backup-before-update job ownerReference
    • features:
      • Added toolbox pod restart on backup-tmp pvc resize
      • Added spec.appConfig.gpgCommitSigning settings to enable web-based commits signing
    • docs:
      • Updated documentation about Redis TLS
      • Updated backup docs related to restore process
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 18.11.4
      • Fixed audit events empty diff message
      • Fixed uninitialized constant on rails components startup

1.10.4

Gitlab Version: 18.11.3_0

  • Module:
    • fixes:
      • Fixed backup before update bug on clean install
      • Fixed s3 preflight false positive error message
      • Backup cronjob now skips pages and registry backup if they are not enabled
    • docs:
      • Added guide for restoring specific repository
      • Added information about gzip compression
      • Added yandex s3 requied permissions for backup tmp bucket
      • Updated backup docs
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 18.11.3

1.10.3

Gitlab Version: 18.11.2_0

  • Module:
    • fixes:
      • Added ttl for jobs and cronjobs
      • Bumped haproxy version to v3.3.10

1.10.2

Gitlab Version: 18.11.2_0

  • Module:
    • fixes:
      • Fixed mount for redis server CA certificate
      • Bumped haproxy version to v3.3.9

1.10.1

Gitlab Version: 18.11.2_0

  • Module:
    • fixes:
      • Fixed panic in module hook ‘010_check_version_before_update’
      • Bumped haproxy version to v3.3.8
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 18.11.2
      • Fixed bug with gitaly signed gpg
      • Fixed bug with hook memoization
      • Disabled Gitlab ping checkbox in UI
      • Updated translations

1.10.0

Gitlab Version: 18.11.1_0

  • Module:
    • features:
      • Added feVersion to CodeInstance status subresource
      • Added spec.appConfig.validate option that validates appconfig fields before applying to cluster
      • Added CronJob for database re-index
      • Added mtls support for redis connections
    • chores:
      • Added deleting pages oauth application if pages disabled
      • Removed module hooks that used for previous release migrations
      • Removed CPU limits from ‘dependencies’ init container
    • fixes:
      • Bumped haproxy version to v3.3.7
      • Webservice now sets 3 puma workers and 8 puma threads for 100 targetUserCount
      • Added D8CodeCoreServiceMetricsAbsent alert to monitoring
      • Fixed s3 preflight check for YC BucketsCountQuotaInCloudExceeded error occurance
      • Removed CPU and memory limits from kube-rbac-proxy sidecar container
      • Fixed module servicemonitor template
      • Added registry DB to backup process
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab CE version to 18.11.1
      • Fixed ‘Create wiki’ button on group wiki page

1.9

1.9.16

Gitlab Version: v18.8.9_1

  • Module:
    • fixes:
      • Fixed validation webhook scaling and scheduling

1.9.15

Gitlab Version: 18.8.9_1

  • Module:
    • fixes:
      • Fixed backups listing for auto-cleanup backup stage

1.9.14

Gitlab Version: 18.8.9_1

  • Module:
    • features:
      • Added scaling.deploymentStrategy property to CodeInstance to control deployments strategies
    • fixes:
      • Bumped Golang version to 1.25.9
    • docs:
      • Updated alerts descriptions. Added mitigation guide for D8CodeDbPartitionMissing alert
  • DeckhouseCode:
    • fixes:
      • Update Gitlab CE to v18.8.9
      • Skipped creation of approval rule during merge request creation, if it is any_approver rule with 0 approvals required
      • Fixed push rule propagation errors
      • Fixed lfs import for pull mirroring
      • Fixed respect force push in pull mirroring
      • Added application setting for pull mirroring timeout

1.9.13

Gitlab Version: 18.8.8_0

  • Module:
    • fixes:
      • Fixed operator migrations check api request

1.9.12

Gitlab Version: 18.8.8_0

  • Module:
    • features:
      • Added secret ref support to spec.storages.postgres.external.serverCA CR property
      • Added secret ref support to spec.features.registry.postgres.external.serverCA CR property
      • Added secret ref support to spec.storages.redis.external.serverCA CR property
      • Deployment strategy edited to Recreate for 10 and 100 targetUserCount
      • Added allowedGroups to spec.omniauth.provider
      • Added groupsAttribute to spec.omniauth.provider
      • Added adminGroups to spec.omniauth.provider
    • fixes:
      • Fixed API calls from operator to webservice
    • chores:
      • Removed HTTP port from webservice service
    • docs:
      • Fixed full component schema on Getting Started page
      • Added rake task for secrets verify in module documentation
      • Added mention to backup docs that rails secrets are not included in backup
      • Updated translation for security recommendations page

1.9.11

Gitlab Version: 18.8.8_0

  • Module:
    • features:
      • Added spec.appConfig.monitoring.ipWhitelist option to CRD
      • Fixed postgres CA validation in preflight checks
  • DeckhouseCode:
    • fixes:
      • Update Gitlab CE to v18.8.8
      • Disabled pull mirroring for archived or pending deletion projects
      • Fixed push rules rollback migrations

1.9.10

Gitlab Version: 18.8.7_0

  • Module:
    • features:
      • Added flag backup.serverSide to disable server-side backup
    • fixes:
      • Fixed monitoring creation for pages/registry
      • Fixed render for sidekiq podmonitor
      • Bumped Golang version to 1.25.8
      • Fixed monitoring whitelist for webservice deployments
    • chores:
      • Removed CPU limits from init containers
    • docs:
      • Updated custom certificate setup guide for web UI
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.8.7
    • chores:
      • Disabled What's new section in UI

1.9.9

Gitlab Version: 18.8.5_2

  • Module:
    • fixes:
      • Fixed operator panic on CR status reconcile
      • Fixed validation for registry postgres ssl mode

1.9.8

Gitlab Version: 18.8.5_2

  • Module:
    • features:
      • Added options backup.keepLast to rotate automatic backups
    • fixes:
      • Bumped haproxy version to v3.3.6
      • Make loadBalancerClass option immutable in CodeInstance CR
      • Remove toolbox pod limits
      • Updated secret masking in operator logs
      • Default IngressClass name now is being taken from global params
      • Toolbox s3cfg use_https value for generic s3 provider
      • Registry postgres ssl mode and serverCA validation
      • Bug with redis auth password secretRef
      • Fixed operator panic when omniauth.autoLinkUser is set
      • S3 preflight checks, added s3 write and head check
      • Fixed emptyDir for toolbox and backup CronJob
      • Fixed module hook that enables monitoring
    • docs:
      • Update info about placement.dedicated behavior

1.9.7

Gitlab Version: 18.8.5_2

  • Module:
    • fixes:
      • Fixed postgres sslmode propagation for container registry
      • Updated helm-lib to 1.68.2
      • Added monitoring rule for code operator
      • Added HA-mode for operator
    • features:
      • Added loadBalancerClass option in CodeInstance CR for Haproxy service
      • Added s3Proxy param for container registry feature in CodeInstance CR
    • docs:
      • Improved documentation for network configuration, backup, recovery, and migration processes
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.8.5
    • fixes:
      • Added correct message for groups mention in ChatOps
      • Updated localization in UI

1.9.6

Gitlab Version: 18.8.4_2

  • Module:
    • fixes:
      • Fixed backup job creation when no schedule in CodeInstance CR
      • Fixed postgres server CA handle in container registry configuration
      • Fixed S3 path style for server side backups

1.9.5

Gitlab Version: 18.8.4_2

  • DeckhouseCode:
    • fixes:
      • Fixed issues on security credentials page

1.9.4

Gitlab Version: 18.8.4_1

  • Module:
    • features:
      • Added support for secret ref in different properties in CodeInstance CRD
    • fixes:
      • Added fix to slow tag listing to container-registry
      • Added validation for Gitaly replicas in HA-mode
      • Fixed webservice ingress annotations
      • Fixed Pages ingress tls secret reconcile bug on pages ingress mode switch
      • Updated CR status when optional component is disabled
      • Fixed cache for module webhook
      • Bumped haproxy version to v3.3.4
      • Bumped Golang version to 1.24.13
    • chore:
      • Moved S3 client for operator to AWS SDK
      • Added .features.toolbox.enabled option to enable/disable toolbox deployment creation
      • Added haproxy scaling for HA mode
      • Updated scaling policy and docs
      • Reduced code-operator resources
      • Registry HPA scale policy modified
    • docs:
      • Updated S3 bucket list in Getting Started page
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.8.4
      • Added support for multiple reviewers and assigners
      • Added audit events for push rules
      • Added a new user type auditor
    • fixes:
      • Added max login attempts and unlock period (in minutes) to the UI
      • Fix unchecking disabled flag in sign-in restriction section
      • Updated localizations in UI
      • Fixed audit events and approval rule creation when creating a merge request
      • Added service rake task for migration

1.9.3

Gitlab Version: 18.8.2_0

  • Module:
    • fixes:
      • Fixed default https.mode for network section.

1.9.2

Gitlab Version: 18.8.2_0

  • Module:
    • fixes:
      • Fixed migration module hook for webservice’s deployment

1.9.1

Gitlab Version: 18.8.2_0

  • Module:
    • fixes:
      • Fixed reconcile for webservice deployment

1.9.0

Gitlab Version: 18.8.2_0

  • Module:
    • features:
      • Added ingressClass field for Pages and Registry in CRD
      • Added alerts when number of partitions is not consistent in database
    • fixes:
      • Operator panic on spec.backup.cronSchedule omit
      • Redeploy pods on each reconcile with HA enabled
      • Migrate webservice resources from Helm
      • Fixed Gitlab Container registry with self-signed certificates
      • Bumped haproxy version to v3.3.2
      • Fixed gitlab-rails openid signing key header
      • Fixed incorrect backup s3 url in gitaly configmap
      • Fixed HPA and PDB resource deletion if HA is disabled
      • Migrations pod priority class name edited to production-high
      • Fixed postgres ssl mode env var for deployments
      • Fixed s3cmd error on S3 self-signed certificate
      • Fixed pages s3 credentials inherit in secrets
      • Updated helm-lib to 1.63.7
      • Fixed GC section render in configmap for Registry V2
    • chore:
      • Removed deprecated MRA resources
      • Moved backup job from Helm
      • Deprecated Helm engine for operator
      • Removed webservice and sidekiq CPU limits to optimize bandwidth
      • Improved performance by adding the RUBY_YJIT_ENABLE,MALLOC_ARENA_MAX variables to the Webservice and Sidekiq
      • Removed separate webservice deployment for internal api callbacks
    • docs:
      • Updated Registry V2 migration guide
      • Added example for Deckhouse authentication in Code
      • Fixed headers in security recommendation page
      • Added step to Omnibus migration guide
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.8.2

1.8

1.8.9

Gitlab Version: 18.5.5_0

  • Module:
    • fixes:
      • Fixed postgres ssl configure script for toolbox deployment

1.8.8

Gitlab Version: 18.5.5_0

  • Module:
    • backport-1-9:
      • Fixed default https.mode for network section

1.8.7

Gitlab Version: 18.5.5_0

  • Module:
    • docs:
      • Fixed changelog in module documentation

1.8.6

Gitlab Version: 18.5.5_0

  • Module:
    • fixes:
      • Fixed secrets mount for Gitlab Exporter
      • Fixed postgres ssl mount in components
      • Fixed reconcilation for backup PVC
      • Bumped Golang version to 1.24.12
    • backport-1-9:
      • Fixed incorrect backup s3 url in gitaly configmap
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.5.5
      • Added CodeOwners area in UI
      • Added Bot Access Tokens section for Security Credentials UI
    • fixes:
      • Update PAT/GAT: new default sort, hide revoked switcher, expiration section enhancements
      • Fixed PAT/GAT tables width
      • Added LDAP group sync filter validation on startup
      • Fixed LDAP name mask to correct only one group
      • Removed Support PIN area from UI
      • Corrected error message for diverged protected branches mirroring
      • Renamed required_approve status to not_approved
      • Added rake task for FE migrations rollback
      • Added default expiration 3 months for SA token in rake task
      • Fixed merge request author and committers approval revocation after corresponding approval rules changes

1.8.5

Gitlab Version: 18.5.4_0

  • Module:
    • features:
      • Added embedded MRA. Separate MRA deployment is being deprecated. Scaling to 0 at first
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.5.4
      • Added audit logs retention settings
      • Added audit events triggered when a user’s SSH key is deleted by an administrator
      • Added new audit events - approval_rule_created, approval_rule_updated, approval_rule_deleted, approval_rule_propagated
      • Logged audit events for changes to the retention period
    • fixes:
      • Disabled GitLab Runner version check
      • Fixed link to OAuth application on the audit event page
      • Fixed missing token_id for personal access token audit events
      • Improved human-readable text for nested JSON changes in audit events

1.8.4

Gitlab Version: 18.5.2_0

  • Module:
    • features:
      • Add token expiration hours metrics and alerts
    • fixes:
      • Fixed a bug with incorrect token rotator logs
      • Fixed panic when network.certificates.customCAs items has no keys set
    • docs:
      • Add token expire troubleshooting

1.8.3

Gitlab Version: 18.5.2_0

  • Module:
    • fixes:
      • Fixed tls section in redis config for sidekiq

1.8.2

Gitlab Version: 18.5.2_0

  • Module:
    • fixes:
      • Migrate toolbox, sidekiq resources from Helm
      • Fixed certificate renewals causing new pods creation
      • Fixed redis rediss schema and redis serverCA validations
      • Fixed customCA configmapRef bug
      • Removed default replicas value from gitData section in CRD
      • Fixed .s3cfg file for toolbox
      • Fixed HPA default settings for rails based components
      • Bumped Golang version to 1.24.11
    • docs:
      • Refreshed migration process described in module documentation
      • Fixed descriptions, translations
      • Getting started docs prettified

1.8.1

Gitlab Version: 18.5.2_0

  • Module:
    • fixes:
      • Fixed migrations for gitlab registry V2
    • docs:
      • Fixed module stage display in documentation
      • Improved documentation for Getting Started, Examples, and Scaling sections

1.8.0

Gitlab Version: 18.5.2_0

  • Module:
    • features:
      • Attached OCI artifacts with VEX files for module images
    • fixes:
      • Scaling docs render
      • Updated base image from Debian 12 to 13
      • Fixed validation webhook for Omniauth configuration
      • Fixed pages oauth app register bug
      • Bumped haproxy version to v3.2.9
      • Mitigated CVE-2025-22868 and CVE-2025-22869 in kube-rbac-proxy image
      • Bumped Golang version to 1.24.10
      • Fix incoming email secret reconcile bug
    • docs:
      • Updated module documentation, added calculations for 5000 users
      • Fixed Getting started page in module documentation
    • backport-1-9:
      • Fix gitaly config map incorrect backup s3 url
  • DeckhouseCode:
    • features:
      • Move module to General Availability stage
      • Update Gitlab CE to v18.5.2

1.7

1.7.4

Gitlab Version: 18.3.5_1

  • Module:
    • backport-1-8:
      • Scaling docs render
      • Fixed validation webhook for Omniauth configuration
      • Fix incoming email secret reconcile bug
      • Updated module documentation, added calculations for 5000 users
      • Fixed Getting started page in module documentation

1.7.3

Gitlab Version: 18.3.5_1

  • Module:
    • fixes:
      • Fix bug with predicate for deployment/statefulset
  • DeckhouseCode:
    • fixes:
      • Access Keys Web UI fixes

1.7.2

Gitlab Version: 18.3.5_0

  • Module:
    • fixes:
      • Fix bug with predicate for deployment/statefulset
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.3.5
      • Added “Access Keys” section in administrator mode

1.7.1

Gitlab Version: 18.3.4_3

  • Module:
    • fixes:
      • Fix internal-tls-ca
      • Fix webservice monitoring whitelist
    • docs:
      • Add ownLoadBalancer configuration mention in Getting-Started

1.7.0

Gitlab Version: 18.3.4_3

  • Module:
    • fixes:
      • Bumped Golang version to 1.24.9
      • Bumped base debian image
      • Added validation for hostnames in CRD
      • Fixed reconciliation for internal TLS CA that triggers pod reload
      • Fixed reconciliation for Gitaly S3 backup credentials
      • Fixed components scaling for 3k users
      • Fix Gitlab SA token rotate
      • Fix toolbox s3cmd configmap
      • Fix pages hpa and pdb reconcile
      • Fix sidekiq resources scale
    • features:
      • Added groupSync.prefix.nameMask parameter for LDAP in CRD
      • Manual backups can be done without setting a schedule
    • docs:
      • Added recommendations for security configuration

1.6

1.6.5

Gitlab Version: 18.3.4_4

  • Module:
    • backport-1-7:
      • Fix internal-tls-ca
      • Add ownLoadBalancer configuration mention in Getting-Started

1.6.4

Gitlab Version: 18.3.4_4

  • Module:
    • fixes:
      • Fixed reconciliation for Gitaly S3 backup credentials
      • Fix Gitlab SA token rotate
      • Bumped Golang version to 1.24.9
      • Bumped base debian image
      • Added validation for hostnames in CRD
      • Fixed reconciliation for internal TLS CA that triggers pod reload
      • Fix toolbox s3cmd configmap

1.6.3

Gitlab Version: 18.3.4_4

  • Module:
    • fixes:
      • Fixed helm chart render for ldap sync prefix name mask
    • docs:
      • Fix grammar and formalize style in security recommendations

1.6.2

Gitlab Version: 18.3.4_4

  • Module:
    • docs:
      • Added recommendations for security configuration
  • DeckhouseCode:
    • fixes:
      • Updated russian translation

1.6.1

Gitlab Version: 18.3.4_3

  • Module:
    • backport-1-7:
      • Bumped Golang version to 1.24.8
      • Bumped base debian image
      • Added groupSync.prefix.nameMask parameter for LDAP in CRD
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.3.4
    • backport-1-7:
      • Introduced full-text search in Gitlab FE

1.6.0

Gitlab Version: 18.3.2_1

  • Module:
    • features:
      • Introduced Container Registry v2. Added database and gc section to CRD
      • Added deleting secrets, crd, pvc on module disabling
    • fixes:
      • Added init container for container registry when database section is present in CR
      • Migrate praefect resources from Helm
      • Migrate gitaly resources from helm
      • Fixed S3 default encryption options in CRD
      • Change outgoing mail default displayName
      • Fixed LDAP sync: added slugification of reserved extensions instead of discarding them in external user usernames.
      • Deleted module hooks that used for migration from 1.4 to 1.5 releases
      • Fixed Gitaly resources scaling
    • docs:
      • Added components schema and placeholder for hardening guideline
      • Added Gitaly components resources scaling precedence
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.3.2

1.5

1.5.3

Gitlab Version: 18.2.8_0

  • DeckhouseCode:
    • fixes:
      • Update Gitlab CE to v18.2.8

1.5.2

Gitlab Version: 18.2.6_1

  • Module:
    • backport-1-6:
      • Fixed S3 default encryption options in CRD
      • Change outgoing mail default displayName
      • Fixed LDAP sync: added slugification of reserved extensions instead of discarding them in external user usernames.

1.5.1

Gitlab Version: 18.2.6_0

  • Module:
    • fixes:
      • Fixed security issues
    • docs:
      • Add ldap docs

1.5.0

Gitlab Version: 18.2.6_0

  • Module:
    • fixes:
      • Renamed sidekiq deploy, hpa and pdb
      • Fixed logic for CRD resources placement
      • Hardening security context in Gitaly pods. Added list of required capabilities to run
      • Added operator logs warning for postgresql version not fully support
      • Gitaly service type changed from Headless to ClusterIP
      • Praefect service type changed from Headless to ClusterIP
      • Fixed sidekiq startup checks
      • Added startup probe to sidekiq deployment probes
      • Fixed preflight ingress hook for network section in CRD
    • docs:
      • Added notes about supported postgresql version
      • Add ownLoadBalancer network faq for YCloud
      • Updated postgres requirements in Getting Started page
    • chore:
      • Removed migration for service monitors in operator
      • Removed unused variable ‘GITALY_FEATURE_DEFAULT_ON’ from deployments. This feature is default now.
      • Removed deprecated useOwnLoadBalancer from CRD
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.2.6

1.4

1.4.10

Gitlab Version: 18.0.6_5

  • Module:
    • backport-1-6:
      • Fixed S3 default encryption options in CRD
      • Change outgoing mail default displayName
      • Fixed LDAP sync: added slugification of reserved extensions instead of discarding them in external user usernames.

1.4.9

Gitlab Version: 18.0.6_3

  • Module:
    • backport-1-5:
      • Fixed security issues
      • Add ldap docs

1.4.8

Gitlab Version: 18.0.6_3

  • Module:
    • fixes:
      • Fixed backup.cronSchedule field ignoring in cronJob manifest
      • Fixed map read in redis preflight hook

1.4.7

Gitlab Version: 18.0.6_3

  • Module:
    • fixes:
      • Fixed role naming in ldap sync config

1.4.6

Gitlab Version: 18.0.6_3

  • Module:
    • fixes:
      • Added omniauth provider’s idp cert fingerprint sha1 validation
      • Fixed backup-before-update hook error handling
      • Webservice deployment probes timing changed
      • Gitaly statefulset probes timing changed
      • Sidekiq deployment probes timing changed

1.4.5

Gitlab Version: 18.0.6_3

1.4.4

Gitlab Version: 18.0.6_2

1.4.3

Gitlab Version: 18.0.6_1

  • Module:
    • fixes:
      • Made network.gitSsh able to omit in CRD
      • Fixed code-operator gitlab api client certificate check
      • Fixed registry with https CustomCertificate mode
      • Fixed Gitaly PVC render
    • docs:
      • Added section about resources placement in Getting Started
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.0.6
      • Added push rules for groups and projects

1.4.2

Gitlab Version: 18.0.3_3

  • Module:
    • fixes:
      • Fixed validation for backup and git storage class in CRD
      • Added validation for SAML provider
      • Added validation for OIDC provider
      • Fixed some variables and error messages in preflights for components
      • Fixed custom certificate preflight check for non-helm components
      • Added mra and gitlab-api-client debug logs

1.4.1

Gitlab Version: 18.0.3_3

  • Module:
    • fixes:
      • Added hostname migration hook
      • Fixed s3 storages for Generic provider

1.4.0

Gitlab Version: 18.0.3_3

  • Module:
    • docs:
      • Added Getting started to module documentation
      • Added changelog to module documentation
      • Added note about Gitaly and Containerd V2
    • features:
      • Added .spec.placement.dedicated to CR to control resource distribution over nodes
    • fixes:
      • Fixed CRD reconciliation when secret or configmap changed
      • Added labels to CRD related resources
      • Dropped .spec.features.pages.s3.external.bucketPrefix in favor of .spec.features.pages.s3.external.bucketName in CRD
      • Dropped Global value support in https sections
      • Added ingress section for registry in CRD
      • Added ingress section for pages in CRD
      • Fixed ingress reconcile when https.mode is CertManager (pages, registry)
      • Set default email for root user on fresh install
      • Add ownLoadBalancer CR validations
      • Moved ServiceMonitor/PodMonitor from operator to module reconciliation to remove DH alerts
      • Fixed storage class propagation in Gitaly
      • Fixed updates on status subresource in CR
      • Fixed traffic policy for service shell
      • Bumped Golang version to 1.24.6
      • Bumped helm-lib to v1.63.0
      • Fixed security context at pod and container scope
      • Added more validation to ldap section
      • Fixed panic on backup s3 preflight
      • Added warning when set non expendable storage class in CRD
      • Fixed secret reconcile for omniauth
      • Fixed ValidatingAdmissionPolicy for backup PVC
      • Fixed ValidatingAdmissionPolicy for gitData PVC
      • Fixed custom certificate search NS
      • Fixed ingress annotations for webservice
    • chore:
      • Removed runner registration token
  • DeckhouseCode:
    • features:
      • Update Gitlab CE to v18.0.3
      • Added activity track to group wiki
      • Added audit event for access level change in group wiki
      • Added full name of project and group to audit event on delete
      • Added API for audit events
    • fixes:
      • Disabled event data transmission

1.3

1.3.24

Gitlab Version: 17.11.7_1

  • Module:
    • docs:
      • Updated LDAP examples in module documentation

1.3.23

Gitlab Version: 17.11.7_1

  • Module:
    • fixes:
      • Fixed s3 section migration configmap

1.3.22

Gitlab Version: 17.11.7_1

  • Module:
    • fixes:
      • Backport fix for backup s3 preflight check
      • Separated Gitaly statefulset and PVC

1.3.21

Gitlab Version: 17.11.7_0

  • Module:
    • fixes:
      • Fixed init container for Gitaly pods
    • docs:
      • Updated module documentation with information about Containerd V2
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab FE version to 17.11.7

1.3.20

Gitlab Version: 17.11.6_1

  • Module:
    • fixes:
      • Fixed storage class propagation in Gitaly

1.3.19

Gitlab Version: 17.11.6_1

  • Module:
    • fixes:
      • Fixed jq filter in module hook

1.3.18

Gitlab Version: 17.11.6_1

  • Module:
    • chore:
      • Removed ‘disabled’ ssl mode from postgres in CRD
    • fixes:
      • Fixed type conversion in migration module hook

1.3.17

Gitlab Version: 17.11.6_1

  • Module:
    • fixes:
      • Updated base image to the newest version to mitigate CVEs
      • Fixed postgres and redis tls secret mount in jobs
      • Fixed redis section in rails based services
    • docs:
      • Added example for Redis TLS in CRD
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab FE version to 17.11.6
      • Changed type for account deckhouse_sa to service account
      • Fixed initial page and added an alert when no admin user exists in the instance.

1.3.16

Gitlab Version: 17.11.4_3

  • Module:
    • fixes:
      • Fixed postgres connection check
      • Updated Golang version to 1.24.5 in operator

1.3.15

Gitlab Version: 17.11.4_3

  • DeckhouseCode:
    • features:
      • Added wiki at group level
    • fixes:
      • Updated russian translation
  • Module:
    • fixes:
      • Fix s3 buckets webhook validations
      • Fix ownLoadBalancer services delete on disabling it

1.3.14

Gitlab Version: 17.11.4_2

  • Module:
    • fixes:
      • Fixed definition for network.certificates.customCAs in CRD

1.3.13

Gitlab Version: 17.11.4_2

  • Module:
    • features:
      • Added network.certificates section to CRD to handle custom TLS and CA certificates.
    • fixes:
      • Fixed NodePort range for gitSsh.service in CRD
      • Bumped MRA to v1.1.3
      • Fixed ValidatingAdmissionPolicy rules

1.3.12

Gitlab Version: 17.11.4_2

  • DeckhouseCode:
    • features:
      • Added vault integration to gitlab CI
      • Added webhooks at group level
  • Module:
    • fixes:
      • Bumped base images version to mitigate CVEs
      • Bumped Golang version to 1.24.5
      • Fixed CA certificate field in CRD for postgres
      • Fixed CA certificate field in CRD for redis
      • Fixed registry bucket name in toolbox and backup job
      • Added validation for external omniauth providers in CRD
      • Added validation for registry params
      • Fixed pages s3 configuration and registration job
      • Field s3.external.endpoint and s3.external.region now required for Generic provider
      • Fixed a bug where the gitlab client would not return errors for requests with an invalid status code
      • Fixed backup job reconciliation and added more validation to backup section in CRD
      • Fixed ldap parameters quote
    • docs:
      • Add ownLoadBalancer nginx-ingress mode required

1.3.11

Gitlab Version: 17.11.4_0

  • Module:
    • features:
      • Added spec.ownloadbalancer section
      • Added spec.ownloadbalancer.annotations. Now it’s available to set custom annotations to ownLoadBalancer service
    • chore:
      • Deprecate spec.useOwnLoadBalancer key. Moved to spec.ownloadbalancer.enabled key
      • Deprecate spec.ownLoadBalancerHttpBackends key. Moved to spec.ownloadbalancer.httpBackends key
      • Remove Global from https available modes
    • docs:
      • Edited https modes available, removed Global
    • fixes:
      • Fixed https CustomCertificate mode (.https.mode=CustomCertificate)
      • Fixed https CertManager mode (.https.mode=CertManager)
      • Fixed bug with operator gitlab internal api usage

1.3.10

Gitlab Version: 17.11.4_0

  • Module:
    • fixes:
      • Fixed mail secrets reconcile
      • Updated ports in some ServiceMonitors
      • Fixed bug with s3 external storage configs
      • Fixed sidekiq scaling map execution conditions
      • Fixed webservice scaling map execution conditions
      • Edited gitaly probes from grpc to exec type
      • Added hpa to predicates
      • Fixed rails replicas template with hpa enabled
      • Fixed deployment redeploy bug with targetUserCount more than 10
      • Fixed registry metrics port
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab FE version to 17.11.4

1.3.9

Gitlab Version: 17.11.3_2

  • Module:
    • fixes:
      • Fixed omniauth provider secret missing
      • Fixed outgoing email smtp secret missing
      • Fields *.s3.external.accessKey and *.s3.external.secretKey are now required
      • Fields *.s3.external.region is now required if *.s3.external.provider: Generic
      • Fixed registry configmap syntax error
      • Fixed haproxy configmap syntax error
      • Fixed migration job redis-secret secret lose
      • Fixed pages reconcile logic

1.3.8

Gitlab Version: 17.11.3_2

  • Module:
    • features:
      • Added param network.ownLoadBalancerHttpBackends in CRD to control haproxy routing

1.3.7

Gitlab Version: 17.11.3_2

  • Module:
    • fixes:
      • Fixed handle of deprecated field in module hooks
      • Fixed pages S3 preflight hook
  • DeckhouseCode:
    • fixes:
      • Updated Gitlab FE version
      • Disabled Enabled sign-in and Enabled sign-up in UI
    • features:
      • Added pull mirroring feature

1.3.6

Gitlab Version: 17.11.3_1

  • Module:
    • chore:
      • Removed deprecated fields pages.s3.bucketPrefix and backup.restoreFromBackupMode from CRD

1.3.5

Gitlab Version: 17.11.3_1

  • Module:
    • docs:
      • Fixed menu title in public module documentation
  • DeckhouseCode:
    • fixes:
      • Fixed Gitlab FE bootstrap issue

1.3.4

Gitlab Version: 17.11.3_0

  • Module:
    • features:
      • Added gitData.replicas param to CRD to control Gitaly nodes in high-available mode
    • fixes:
      • Fixed Omniauth provider arguments in CRD
    • docs:
      • Fixed bucket names in public module documentation