Listing Thumbnail

    Secrets Manager - Self Hosted

     Info
    Sold by: GitLab 
    GitLab Secrets Manager - Self-Hosted, brings native secrets management to GitLab instances running in air-gapped and disconnected environments. Store and use CI/CD credentials inside the same platform that runs your code and pipelines, with no separate secrets tool and no outbound internet connectivity required. Built on OpenBao, it uses your existing GitLab group and project structure for access control, so there is no second permission model to build or keep in sync. Each secret is scoped to the job that needs it by environment, branch, and protection status, which limits the blast radius if a credential is ever exposed. Create, update, and delete events stream to the same audit trail as the rest of your platform, and pipeline secret reads carry the originating pipeline and job IDs. Built for teams in regulated, sovereign, and offline environments that need full control over where their secrets live.

    Overview

    Play video

    GitLab Secrets Manager, Self-Hosted, lets teams store and consume CI/CD credentials natively inside a self-managed GitLab instance, including fully air-gapped deployments with no connection to the public internet.

    Built for public sector, defense, financial services, and other regulated teams that require on-premises or air-gapped operation and full data sovereignty.

    Secrets such as access tokens, database credentials, and private keys live in the same platform that runs your code and pipelines. There is no standalone secrets system to install alongside GitLab, no second access model to reconcile, and no external service dependency. The solution is built on OpenBao, the open-source secrets engine, and runs entirely within your own infrastructure and governance boundary.

    Access control reuses the GitLab group and project structure you already maintain. You set read, create, update, and delete permissions per user, group, or role using the same controls that govern your code. Secrets defined at the group level are inherited by the projects beneath it, so shared credentials are defined once.

    Every secret is scoped to the jobs that need it, based on the target environment, the branch, and whether that branch is protected. A compromised credential is contained to one job rather than every pipeline that could reference it. Create, update, and delete events are written to your existing GitLab audit trail, and pipeline secret reads stream as audit events that include the originating pipeline and job IDs, so responders can trace where a secret was used without correlating logs across systems.

    Highlights

    • Fully air-gapped - Native secrets management inside self-managed GitLab, with no standalone tool and no internet connectivity required.
    • One access model - Reuses your existing GitLab group and project permissions instead of a separate system to build and keep in sync.
    • Unified audit trail - Contained blast radius where each secret is scoped to the job that needs it, and reads and changes land in the same GitLab audit stream with pipeline and job IDs.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. Request a private offer to receive a custom quote. Sign in to view any offers that have been extended to you.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Priority Support is included with all self-managed GitLab offerings. Please contact https://about.gitlab.com/support/  for additional information

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.