GitLab
Integrating GitLab with Escape's ASM provides Code-to-Cloud visibility by matching your Code Resolvers with your Cloud Resources, through API Discovery from Code.
Discovered Resources¶
The GitLab integration automatically discovers and inventories the following resources from your GitLab instance:
- GitLab Repositories: All repositories within the group or project scope
- API Schema Files: OpenAPI specifications, GraphQL schemas, Postman collections, and other API definition files found in repositories
- Extracted APIs: API endpoints and services defined in discovered schema files
The integration scans your repositories for API schema files, extracts API definitions, and automatically classifies them as Assets (APIs) in Escape's ASM. This enables Code-to-Cloud security monitoring by linking discovered APIs to their source repositories and enabling continuous testing as code changes.
Create a GitLab Personal Access Token¶
Use an account with the Developer role on the projects you want to discover.
- Create a new Personal Access Token in your GitLab settings
- Under Scopes, select:
apiread_apiread_repository
- Copy your token immediately - it can't be viewed again after leaving the page
For more details, see the GitLab documentation on Personal Access Tokens.
Self-Hosted GitLab¶
In the integration form, enable This is a self-hosted GitLab instance and set Instance URL to your API base URL, for example https://gitlab.example.com/api/v4.
Internal Networks and Services¶
When integrating with internal networks and services, you may need to:
- Configure a Private Location
- Whitelist FQDNs
For more information, see Private Locations.