stage | group | info | type |
---|---|---|---|
Verify |
Pipeline Security |
To determine the technical writer assigned to the Stage/Group associated with this page, see https://about.gitlab.com/handbook/product/ux/technical-writing/#assignments |
reference, api |
- Introduced in GitLab 14.8 with a flag named
ci_secure_files
. Disabled by default.- Generally available in GitLab 15.7. Feature flag
ci_secure_files
removed.
This feature is part of Mobile DevOps developed by GitLab Incubation Engineering. The feature is still in development, but you can:
You can securely store up to 100 files for use in CI/CD pipelines as secure files. These files are stored securely outside of your project's repository and are not version controlled. It is safe to store sensitive information in these files. Secure files support both plain text and binary file types but must be 5 MB or less.
Get list of secure files in a project.
GET /projects/:project_id/secure_files
Supported attributes:
Attribute | Type | Required | Description |
---|---|---|---|
project_id |
integer/string | Yes | The ID or URL-encoded path of the project. |
Example request:
curl --header "PRIVATE-TOKEN: <your_access_token>" "https://gitlab.example.com/api/v4/projects/1/secure_files"
Example response:
[
{
"id": 1,
"name": "myfile.jks",
"checksum": "16630b189ab34b2e3504f4758e1054d2e478deda510b2b08cc0ef38d12e80aac",
"checksum_algorithm": "sha256",
"created_at": "2022-02-22T22:22:22.222Z",
"expires_at": null,
"metadata": null
},
{
"id": 2,
"name": "myfile.cer",
"checksum": "16630b189ab34b2e3504f4758e1054d2e478deda510b2b08cc0ef38d12e80aa2",
"checksum_algorithm": "sha256",
"created_at": "2022-02-22T22:22:22.222Z",
"expires_at": "2023-09-21T14:55:59.000Z",
"metadata": {
"id":"75949910542696343243264405377658443914",
"issuer": {
"C":"US",
"O":"Apple Inc.",
"CN":"Apple Worldwide Developer Relations Certification Authority",
"OU":"G3"
},
"subject": {
"C":"US",
"O":"Organization Name",
"CN":"Apple Distribution: Organization Name (ABC123XYZ)",
"OU":"ABC123XYZ",
"UID":"ABC123XYZ"
},
"expires_at":"2023-09-21T14:55:59.000Z"
}
}
]
Get the details of a specific secure file in a project.
GET /projects/:project_id/secure_files/:id
Supported attributes:
Attribute | Type | Required | Description |
---|---|---|---|
project_id |
integer/string | Yes | The ID or URL-encoded path of the project. |
id |
integer | Yes | The ID of a secure file. |
Example request:
curl --header "PRIVATE-TOKEN: <your_access_token>" "https://gitlab.example.com/api/v4/projects/1/secure_files/1"
Example response:
{
"id": 1,
"name": "myfile.jks",
"checksum": "16630b189ab34b2e3504f4758e1054d2e478deda510b2b08cc0ef38d12e80aac",
"checksum_algorithm": "sha256",
"created_at": "2022-02-22T22:22:22.222Z",
"expires_at": null,
"metadata": null
}
Create a new secure file.
POST /projects/:project_id/secure_files
Supported attributes:
Attribute | Type | Required | Description |
---|---|---|---|
project_id |
integer/string | Yes | The ID or URL-encoded path of the project. |
name |
string | Yes | The name of the file being uploaded. The filename must be unique in the project. |
file |
file | Yes | The file being uploaded (5 MB limit). |
Example request:
curl --request POST --header "PRIVATE-TOKEN: <your_access_token>" \
"https://gitlab.example.com/api/v4/projects/1/secure_files" --form "name=myfile.jks" --form "file=@/path/to/file/myfile.jks"
Example response:
{
"id": 1,
"name": "myfile.jks",
"checksum": "16630b189ab34b2e3504f4758e1054d2e478deda510b2b08cc0ef38d12e80aac",
"checksum_algorithm": "sha256",
"created_at": "2022-02-22T22:22:22.222Z",
"expires_at": null,
"metadata": null
}
Download the contents of a project's secure file.
GET /projects/:project_id/secure_files/:id/download
Supported attributes:
Attribute | Type | Required | Description |
---|---|---|---|
project_id |
integer/string | Yes | The ID or URL-encoded path of the project. |
id |
integer | Yes | The ID of a secure file. |
Example request:
curl --request GET --header "PRIVATE-TOKEN: <your_access_token>" https://gitlab.example.com/api/v4/projects/1/secure_files/1/download --output myfile.jks
Remove a project's secure file.
DELETE /projects/:project_id/secure_files/:id
Supported attributes:
Attribute | Type | Required | Description |
---|---|---|---|
project_id |
integer/string | Yes | The ID or URL-encoded path of the project. |
id |
integer | Yes | The ID of a secure file. |
Example request:
curl --request DELETE --header "PRIVATE-TOKEN: <your_access_token>" "https://gitlab.example.com/api/v4/projects/1/secure_files/1"