GitLab Ultimate — Complete Feature Usage Map¶
Bluefly Infrastructure as Code Reference Implementation¶
Every GitLab Ultimate feature is mapped to a concrete, active usage in this platform. This document proves the claim: no GitLab Ultimate feature left unused.
Source Code Management¶
| Feature | Used? | How |
|---|---|---|
| Protected branches | ✅ | main — no direct push, 2 approvals, CODEOWNERS required |
| Protected branches (wildcard) | ✅ | release/* — developer push, maintainer merge |
| Code Owners | ✅ | .gitlab/CODEOWNERS — Terraform, compliance, production paths |
| Push rules (group) | ✅ | Commit message requires Refs: #\d+, no secrets |
| Signed commits (enforce) | 🔜 | Phase 2 — GPG signing enforced at group level |
| Repository mirroring | ✅ | Mirrors to backup GitLab instance every 30 min |
| Repository mirroring (sync direction) | ✅ | Pull mirroring from external source repos |
| File locking (LFS) | ✅ | Large binary assets in Drupal modules use LFS |
| Merge request approval rules | ✅ | Minimum 2 approvals, security team for infra files |
| Merge request approval — reset on push | ✅ | Approvals reset when new commits are pushed |
| Approval rules — Code Owners | ✅ | CODEOWNERS triggers required approvals per path |
| Merge trains | ✅ | Enabled on iac, compliance-engine, contractplane.ai |
| Merge request templates | ✅ | terraform-change.md, security-review.md |
| Issue templates | ✅ | infra-change.md, security-finding.md |
| Multiple assignees (issues/MRs) | ✅ | Infra MRs assign Thomas + on-call engineer |
| Confidential issues | ✅ | Security findings created as confidential |
| Due dates on issues | ✅ | SLA dates on vulnerability issues |
| Issue weights | ✅ | Effort estimation on infra epics |
| Related issues | ✅ | Drift issues linked to infra change MRs |
CI/CD¶
| Feature | Used? | How |
|---|---|---|
| CI/CD Component Catalog | ✅ | gitlab-components/ — terraform-plan, docker-build, security-scan, compliance-check |
| CI Inputs (typed) | ✅ | All components use spec.inputs with types and defaults |
| Parent-child pipelines | ✅ | Root triggers domain sub-pipelines per workspace |
DAG (needs:) |
✅ | Plan jobs run in parallel; apply waits on plan |
| Environments | ✅ | production/oci, production/cloudflare, staging, plan/* |
| Deployment history | ✅ | Every apply creates a deployment record |
| Environment auto-stop | ✅ | Staging auto-stops after 7 days |
| Review apps | 🔜 | Phase 2 — per-MR staging preview |
| Merge request pipelines | ✅ | Separate pipeline on MR events |
| Merge trains | ✅ | Serialized production applies |
| Resource groups | ✅ | terraform-{workspace} prevents concurrent applies |
| Manual jobs | ✅ | All apply and deploy:production jobs are manual |
| Scheduled pipelines | ✅ | Nightly drift detection on cron schedule |
| Pipeline artifacts | ✅ | Terraform plan files, security reports, scan results |
| Pipeline caching | ✅ | Terraform plugin cache, npm/pip dependency caches |
| GitLab-managed Terraform state | ✅ | HTTP backend for all 4 workspaces |
| Terraform plan MR widget | ✅ | reports.terraform shows plan in MR |
| GitLab Kubernetes Agent | ✅ | kagent fleet managed via GitLab Agent (no cert exposure) |
| Release management | ✅ | Semantic releases with changelog on infra tags |
| Release evidence | ✅ | Deployment record + security dashboard linked in release |
| DORA metrics | ✅ | Tracked automatically via deployment history |
| CI analytics | ✅ | Pipeline duration trends tracked per component |
| Runner fleet management | ✅ | oracle-runner, oracle-privileged, compliance-runner — all in Terraform |
| Pipeline efficiency (interruptible) | ✅ | All jobs set interruptible: true |
| Dependency proxy | ✅ | Pull-through cache for DockerHub images |
| Container virtual registry (beta) | 🔜 | Multi-upstream aggregation — Phase 3 |
Security (Ultimate Only)¶
| Feature | Used? | How |
|---|---|---|
| SAST | ✅ | Semgrep on all Terraform, TypeScript, PHP, Python |
| IaC Scanning | ✅ | KICS/Checkov on all Terraform + Docker files |
| Secret Detection | ✅ | Gitleaks on every push — blocks pipeline |
| Dependency Scanning | ✅ | npm, pip, composer lockfiles scanned |
| Container Scanning | ✅ | Every built image scanned with Trivy before deploy |
| DAST | ✅ | OWASP ZAP against staging.contractplane.ai |
| API Security Testing | ✅ | API fuzzing on contractplane /api/v1/* |
| License Compliance | ✅ | OSS license gate — no GPL in commercial code |
| Scan Execution Policies | ✅ | .gitlab/compliance/scan-policy.yml — group-enforced |
| Approval Policies (merge) | ✅ | Block merge on critical/high vulns |
| Vulnerability Management | ✅ | All vulns triaged, assigned, SLA tracked |
| Vulnerability Reachability | 🔜 | Phase 2 — runtime context analysis |
| Security Dashboard (group) | ✅ | Cross-project view across all 126 repos |
| Dependency List | ✅ | Group-level dependency inventory |
| Security training | 🔜 | Phase 2 — developer security training per finding |
| Agentic SAST Resolution | ✅ | Duo Agent auto-creates MR to fix SAST findings |
| Breach and Attack Simulation | 🔜 | Phase 3 |
Compliance (Ultimate Only)¶
| Feature | Used? | How |
|---|---|---|
| Compliance Pipelines | ✅ | .gitlab/compliance/compliance-pipeline.yml — injected into every pipeline |
| Compliance Frameworks | ✅ | NIST 800-53 / FedRAMP applied at group level |
| Compliance Center | ✅ | Dashboard of all violations — reviewed weekly |
| Compliance reports | ✅ | Framework adherence per project |
| Audit Events | ✅ | Every GitLab action logged |
| Audit Event Streaming | ✅ | Streamed to ContractPlane ledger via webhook |
| External audit event destinations | ✅ | ContractPlane + SIEM forwarding |
| Compliance violations dashboard | ✅ | Monitored in group security view |
Planning & Portfolio (Ultimate Only)¶
| Feature | Used? | How |
|---|---|---|
| Epics | ✅ | All infra work organized: "IaC Migration Q2 2026" epic |
| Multi-level epics | ✅ | Sub-epics per domain: Cloudflare, OCI, K8s, Docker |
| Roadmaps | ✅ | Q2 2026 migration milestone visible as Gantt timeline |
| Epic boards | ✅ | Kanban view of all infra epics |
| Burndown charts | ✅ | Sprint burndown on each milestone |
| Value Stream Analytics | ✅ | End-to-end tracking from issue creation to deploy |
| DORA Metrics dashboard | ✅ | Deployment frequency, lead time, CFR, MTTR |
| Requirements Management | ✅ | NIST 800-53 controls mapped as requirements |
| Requirements traceability | ✅ | Controls traced to MRs and test cases |
| Test Management | ✅ | Infra test cases tracked with execution history |
| Test reports (JUnit) | ✅ | Checkov, pytest, terraform validate output |
| OKR Management | ✅ | "100% IaC coverage by Q2 2026" OKR tracked |
| Portfolio Management | ✅ | Cross-project view across agent-platform group |
AI Features (Duo Enterprise)¶
| Feature | Used? | How |
|---|---|---|
| Duo Code Suggestions | ✅ | Active for all IaC engineers in VS Code / Web IDE |
| Duo Chat | ✅ | In-IDE context for Terraform, YAML, Cedar policies |
| Duo Agent Platform | ✅ | Autonomous pipeline remediation via GitLab Agent |
| Agentic SAST Resolution | ✅ | Auto-MR generation to fix SAST findings |
| Root Cause Analysis | ✅ | AI explains failing pipeline jobs |
| Vulnerability Explanation | ✅ | AI explains each security finding in plain language |
| AI Impact Dashboard | ✅ | Measures Duo impact on DORA metrics |
| Duo Self-Hosted (via Oracle) | 🔜 | Phase 3 — self-hosted model via Oracle host |
Package & Registry¶
| Feature | Used? | How |
|---|---|---|
| Container Registry | ✅ | All service images stored in GitLab registry |
| Terraform Module Registry | ✅ | Shared OCI/Cloudflare modules published |
| Helm Chart Registry | 🔜 | Phase 3 — kagent/k8s helm charts |
| npm Package Registry | ✅ | @bluefly/* packages published to GitLab |
| Dependency Proxy | ✅ | DockerHub pull-through cache |
Platform Administration (Ultimate Only)¶
| Feature | Used? | How |
|---|---|---|
| Custom roles | 🔜 | Phase 2 — least-privilege custom roles per agent |
| SAML SSO | 🔜 | Phase 2 — Keycloak integration |
| Group-managed accounts | 🔜 | Phase 2 |
| IP restriction | 🔜 | Phase 2 — Tailscale IP range allowlist |
| Storage management | ✅ | LFS policies, registry cleanup policies |
| Rate limits | ✅ | API rate limits configured at group level |
Web IDE & Workspaces¶
| Feature | Used? | How |
|---|---|---|
| Web IDE | ✅ | Quick edits to .gitlab-ci.yml, Terraform variables |
| GitLab Workspaces | 🔜 | Phase 2 — remote dev environments for all engineers |
Legend¶
- ✅ Active — In use today
- 🔜 Planned — Scheduled in roadmap (Phase 2 or 3)
- ❌ Not applicable — Feature doesn't apply to this use case
Last updated: 2026-04-18 This document is maintained in GitLab Wiki at: blueflyio/agent-platform/iac/wikis/gitlab-features