Overview

Product video
GitLab Secrets Manager, Self-Hosted, lets teams store and consume CI/CD credentials natively inside a self-managed GitLab instance, including fully air-gapped deployments with no connection to the public internet.
Built for public sector, defense, financial services, and other regulated teams that require on-premises or air-gapped operation and full data sovereignty.
Secrets such as access tokens, database credentials, and private keys live in the same platform that runs your code and pipelines. There is no standalone secrets system to install alongside GitLab, no second access model to reconcile, and no external service dependency. The solution is built on OpenBao, the open-source secrets engine, and runs entirely within your own infrastructure and governance boundary.
Access control reuses the GitLab group and project structure you already maintain. You set read, create, update, and delete permissions per user, group, or role using the same controls that govern your code. Secrets defined at the group level are inherited by the projects beneath it, so shared credentials are defined once.
Every secret is scoped to the jobs that need it, based on the target environment, the branch, and whether that branch is protected. A compromised credential is contained to one job rather than every pipeline that could reference it. Create, update, and delete events are written to your existing GitLab audit trail, and pipeline secret reads stream as audit events that include the originating pipeline and job IDs, so responders can trace where a secret was used without correlating logs across systems.
Highlights
- Fully air-gapped - Native secrets management inside self-managed GitLab, with no standalone tool and no internet connectivity required.
- One access model - Reuses your existing GitLab group and project permissions instead of a separate system to build and keep in sync.
- Unified audit trail - Contained blast radius where each secret is scoped to the job that needs it, and reads and changes land in the same GitLab audit stream with pipeline and job IDs.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Financing for AWS Marketplace purchases
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Priority Support is included with all self-managed GitLab offerings. Please contact https://about.gitlab.com/support/ for additional information
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.