Connect GitLab to Label2Prod

Create a GitLab token with the Developer role and api scope, connect your group to Label2Prod, and set it up on GitLab.com Free or self-managed GitLab.

Label2Prod connects to a GitLab group with a token. Every project in the group and its subgroups, except archived ones, becomes available to map to your Jira projects. GitLab.com and self-managed GitLab both work.

Create the token

Which token you create depends on your GitLab.

GitLab.com Premium or Ultimate, or self-managed GitLab: a group access token. You need the Owner role in the group.

  1. Open your top-level group in GitLab.
  2. Go to Settings → Access tokens and add a new token.
  3. Name it Label2Prod, pick an expiry date, choose the role Developer and tick the scope api.
  4. Create the token and copy it. Copy the group’s numeric Group ID from the group’s overview page too.

GitLab.com Free: a service account. Group access tokens need Premium or Ultimate on GitLab.com, but service accounts are available on every tier.

  1. As an Owner of the top-level group, create a service account for Label2Prod.
  2. Add it to the group with the Developer role.
  3. Create a personal access token for the service account with the api scope, and copy it with the Group ID.

A personal access token of a dedicated GitLab user, added to the group as a Developer, works the same way.

Merge requests show the account behind the token as their author, so give it a name your team will recognize.

Connect it in Label2Prod

  1. In Setup, go to Connect your code and choose Connect a GitLab group.
  2. Paste the token and the Group ID.
  3. On self-managed GitLab, open Self-managed GitLab? and enter your GitLab URL, such as https://gitlab.example.com. Your instance must be reachable from the internet over HTTPS, at the root of its address rather than under a sub-path.
  4. Label2Prod checks that the token can read the group and lists the projects it found.

If Label2Prod says GitLab would not let the token read the group, check the Group ID and that the token has the Developer role and the api scope in that group.

Protect your default branch

Label2Prod pushes only to its own branches and never merges. Keep your default branch protected so GitLab enforces this as well: with GitLab’s usual protection, only Maintainers can push or merge there, and a Developer token cannot.

Before the token expires

GitLab tokens expire. Before the date you picked, create a new token the same way and connect the group again with it: Label2Prod replaces the old token and keeps your mappings.