Use different environment variables per deployment in GitLab

Viewed 1031

I'm trying to migrate a BitBucket pipeline to GitLab. In BitBucket we use a different set of environment variables for each deployment (staging/production etc).

I don't know how to specify this in GitLab.

I've set up just group variables and variables specific to the repository but I've not found how to override e.g. DB name for different deployments.

Thank you in advance for your help.

1 Answers

You can define variables and limit their scope

By default, all CI/CD variables are available to any job in a pipeline. Therefore, if a project uses a compromised tool in a test job, it could expose all CI/CD variables that a deployment job used. This is a common scenario in supply chain attacks.

GitLab helps mitigate supply chain attacks by limiting the environment scope of a variable.
GitLab does this by defining which environments and corresponding jobs the variable can be available for.

See "Scoping environments with specs" and "CI/CD variable expression"

deploy:
  script: cap staging deploy
  environment: staging
  only:
    variables:
      - $RELEASE == "staging"
      - $STAGING
Related