GitLab Secrets Manager for CI and Non-CI Workloads
On this page
Quick answer
GitLab Secrets Manager is documented as Limited Availability on GitLab.com and beta on Self-Managed. GitLab.com offers a trial and then consumes GitLab Credits; Self-Managed beta has a separate lifecycle. Verify the exact deployment and billing path.
For CI, scope a secret to the job’s environment, branch, and protection requirements. For non-CI tools such as Kubernetes, Terraform, OpenTofu, or custom consumers, define an explicit workload identity, least-privilege path, rotation owner, audit, and revocation.
Irreversible disable warning
GitLab documents that disabling Secrets Manager for a project permanently deletes project secrets and they cannot be recovered. Treat disable as a destructive operation: inventory dependencies, export or migrate through an approved secure process, obtain owner approval, test recovery, and stop consumers before acting. Apply the corresponding group-level review where relevant.
Test unauthorized read, wrong branch or environment, rotated secret, revoked workload, audit access, trial expiry, Credits interruption, disabled feature, restore plan, and incident response.
Use the 19.3 overview and readiness checklist.
Official sources
Source check: August 23, 2026. Verify lifecycle, billing, scopes, integrations, audit, rotation, deletion, and recovery behavior.