Update application settings
Updates the current application settings for this GitLab instance.
Authorizations
Section titled “ Authorizations ”Request Body
Section titled “ Request Body ”object
Require admin users to re-authenticate for administrative (i.e. potentially dangerous) operations
Deprecated: Use :abuse_notification_email instead. Abuse reports will be sent to this address if it is set. Abuse reports are always available in the admin area.
Abuse reports will be sent to this address if it is set. Abuse reports are always available in the admin area.
Text shown after sign up
We will redirect users to this page after they sign out
Helps prevent bots from creating issues
Generate API key at http://www.akismet.com
Enable proxying of assets
URL of the asset proxy server
Shared secret with the asset proxy server
Deprecated: Use :asset_proxy_allowlist instead. Assets that match these domain(s) will NOT be proxied. Wildcards allowed. Your GitLab installation URL is automatically whitelisted.
Assets that match these domain(s) will NOT be proxied. Wildcards allowed. Your GitLab installation URL is automatically allowed.
Enable authentication data retention cleanup workers to enforce retention policies
Authorization token duration (minutes)
Lifetime of OAuth access tokens in seconds.
Default timeout for decompressing archived files, in seconds. Set to 0 to disable timeouts.
Set the default expiration time for each job’s artifacts
The instance default CI/CD configuration file and path for new projects
Determine if developers can create projects in the group
Determine if developers can push to default branch
Determine if developers can push to default branch
object
An array of access levels allowed to push
object
A valid access level
Allow force push for all users with push access.
An array of access levels allowed to merge
object
A valid access level
Require approval from code owners
Allow developers to initial push
The default group visibility
The default project visibility
The maximum number of personal projects
The default snippet visibility
Dependency management settings
object
Maximum number of dependency management security update scheduler jobs that run concurrently across the Sidekiq fleet
Stop administrators from connecting to non-trusted OAuth applications.
Disable display of RSS/Atom and Calendar feed_tokens
Disable certain OAuth sign-in sources
Enable domain denylist for sign ups
Users with e-mail addresses that match these domain(s) will NOT be able to sign-up. Wildcards allowed. Enter multiple entries on separate lines. Ex: domain.com, *.domain.com
ONLY users with e-mail addresses that match these domain(s) will be able to sign-up. Wildcards allowed. Enter multiple entries on separate lines. Ex: domain.com, *.domain.com
List of trusted domains or IP addresses to which local requests are allowed when local requests for webhooks and integrations are disabled.
Enable Email-based one-time passwords (OTP) as a multi-factor authentication method.
Allow rendering of iframes in Markdown.
Allowed iframe src host[:port] entries. Enter multiple entries separated by commas or on separate lines.
Raw newline- or comma-separated list of allowed iframe src host[:port] entries.
Enable integration with Amazon EKS
Amazon account ID for EKS integration
Access key ID for the EKS integration IAM user
Secret access key for the EKS integration IAM user
Some email servers do not support overriding the email sender name. Enable this option to include the name of the author of the issue, merge request or comment in the email body instead.
Email confirmation setting, possible values: off, soft, and hard
Allow only the selected protocols to be used for Git access.
Enable Gitpod
The configured Gitpod instance URL
Default Gitaly timeout, in seconds. Set to 0 to disable timeouts.
Gitaly fast operation timeout, in seconds. Set to 0 to disable timeouts.
Medium Gitaly timeout, in seconds. Set to 0 to disable timeouts.
Enable Grafana
Grafana URL
Flag indicating if the Gravatar service is enabled
Hide marketing-related entries from help
Alternate support URL for help page and help dropdown
Alternate documentation pages URL
Custom text displayed on the help page
We will redirect non-logged in users to this page
Enable automatic repository housekeeping (git repack, git gc)
Number of Git pushes after which a full ‘git repack’ is run.
Number of Git pushes after which ‘git gc’ is run.
Number of Git pushes after which an incremental ‘git repack’ is run.
Number of Git pushes after which Gitaly is asked to optimize a repository.
By default GitLab sends emails in HTML and plain text formats so mail clients can choose what format to use. Disable this option if you only want to send emails in plain text format.
Enabled sources for code import during project creation. OmniAuth must be configured for GitHub, Bitbucket, and GitLab.com
Enable Invisible Captcha spam detection during signup.
Set the maximum file size for each job’s artifacts
Maximum attachment size in MB
Maximum export size in MB
Maximum allowed size in MB for GitHub API responses. 0 for unlimited.
Maximum allowed object count for GitHub API responses. 0 for unlimited. Count is an estimate based on the number of : , { and [ occurrences in the response.
Maximum import size in MB
Maximum remote file size in MB for imports from external object storages
Maximum decompressed size in MB
Maximum size of pages in MB
Maximum number of GitLab Pages custom domains per project
Maximum size in bytes of the Terraform state file. Set this to 0 for unlimited file size.
A method call is only tracked when it takes longer to complete than the given amount of milliseconds.
Flag indicating if password authentication is enabled for the web interface
Flag indicating if password authentication is enabled for the web interface
Flag indicating if password authentication is enabled for the web interface
Flag indicating if password authentication is enabled for Git over HTTP(S)
Deprecated: Use :performance_bar_allowed_group_path instead. Path of the group that is allowed to toggle the performance bar.
Path of the group that is allowed to toggle the performance bar.
Deprecated: Pass performance_bar_allowed_group_path: nil instead. Allow enabling the performance.
Prefix to prepend to all personal access tokens
Flag indicating if Personal / Group / Project access token expiry is required
Enable Kroki
The Kroki server URL
Enable PlantUML
The PlantUML server URL
Enable Diagrams.net
The Diagrams.net server URL
Interval multiplier used by endpoints that perform polling. Set to 0 to disable polling.
Enable project export
Enable Prometheus metrics
Maximum number of changes (branches or tags) in a single push above which webhooks and integrations are not triggered. Setting to 0 does not disable throttling.
Maximum number of changes (branches or tags) in a single push above which a bulk push event is created. Setting to 0 does not disable throttling.
Helps prevent bots from creating accounts
Generate site key at http://www.google.com/recaptcha
Generate private key at http://www.google.com/recaptcha
Helps prevent brute-force attacks
GitLab will periodically run ‘git fsck’ in all project and wiki repositories to look for silent disk corruption issues.
Storage paths for new projects with a weighted value ranging from 0 to 100
object
Require all users to set up Two-factor authentication
Amount of time (in hours) that users are allowed to skip forced configuration of two-factor authentication
Selected levels cannot be used by non-admin users for groups, projects or snippets. If the public level is restricted, user profiles are only visible to logged in users.
Session duration in minutes. GitLab restart is required to apply changes.
Expires sessions based off the creation date rather than last activity
Enable shared runners for new projects
Shared runners text
List of types which are allowed to register a GitLab runner
Flag indicating if sign up is enabled
Enable Sourcegraph
Only allow public projects to communicate with Sourcegraph
The configured Sourcegraph instance URL
Enable Spam Check via external API endpoint
The URL of the external Spam Check service endpoint
Maximum time for web terminal websocket connection (in seconds). Set to 0 for unlimited time.
Every week GitLab will report license usage back to GitLab, Inc.
Local markdown version, increase this value when any cached markdown should be invalidated
Deprecated: Use :allow_local_requests_from_web_hooks_and_services instead. Allow requests to the local network from hooks and services.
Enable Mailgun event receiver
The Mailgun HTTP webhook signing key for receiving events from webhook
Enable Snowplow tracking
The Snowplow collector hostname
The Snowplow cookie domain
The Snowplow site name / application id
Maximum number of issue creation requests allowed per minute per user. Set to 0 for unlimited requests per minute.
Maximum number of requests per minute for each raw path. Set to 0 for unlimited requests per minute.
Maximum number of requests per minute for a raw blob for unauthenticated requests. Set to 0 for unlimited requests per minute.
Maximum wiki page content size in bytes
Maximum work item, merge request, and vulnerability description and comment content size in bytes.
Allow URI includes for AsciiDoc wiki pages
Require explicit admin approval for new signups
What’s new variant, possible values: all_tiers, current_tier, and disabled.
Enable FloC (Federated Learning of Cohorts)
Send emails to users upon account deactivation
Enable pipeline suggestion banner
Enable Jenkins migration banner
Show the external redirect page that warns you about user-generated content in GitLab Pages
Maximum number of calls to the /users/:id API per 10 minutes per user. Set to 0 for unlimited requests.
Token expiration interval for shared runners, in seconds
Token expiration interval for group runners, in seconds
Token expiration interval for project runners, in seconds
Maximum number of pipeline creation requests allowed per minute per user and commit. Set to 0 for unlimited requests per minute.
Maximum number of pipeline creation requests allowed per minute per user. Set to 0 for unlimited requests per minute.
Maximum number of CI Lint requests allowed per minute per user. Set to 0 for unlimited requests per minute.
ID of the OAuth application used to authenticate with the GitLab for Jira Cloud app.
Enable public key storage for the GitLab for Jira Cloud app.
URL of the GitLab instance used as a proxy for the GitLab for Jira Cloud app.
Atlassian Forge app ID (ARI) of the GitLab for Jira Cloud app, used to verify inbound Forge Invocation Tokens.
Maximum simultaneous direct transfer batch exports to process.
Maximum number of simultaneous batch export jobs to process.
Enable migrating GitLab groups and projects by direct transfer
Maximum download file size in MB when importing from source GitLab instances by direct transfer
Rate limit for authenticated requests to users autocomplete endpoint
Rate limit for authenticated requests to users autocomplete endpoint
Github Importer maximum number of simultaneous import jobs
Bitbucket Cloud Importer maximum number of simultaneous import jobs
Bitbucket Server Importer maximum number of simultaneous import jobs
Allow registering runners using a registration token
Maximum number of includes per pipeline
Maximum number of caches that can be defined in a single CI/CD job
Turn on incremental logging for job logs.
Set the limit for pipelines and branches that can be triggered when creating a Git push. Set to 0 to disable the limit
Query scan result policy approval groups globally
Enable the GitLab for Slack app
The client ID of the GitLab for Slack app
The client secret of the GitLab for Slack app. Used for authenticating OAuth requests from the app
The signing secret of the GitLab for Slack app. Used for authenticating API requests from the app
The verification token of the GitLab for Slack app. This method of authentication is deprecated by Slack and used only for authenticating slash commands from the app
Maximum duration (in seconds) between refreshes of namespace statistics (Default: 300)
Maximum authenticated requests to /project/:id/jobs per minute
Public security contact information made available at https://gitlab.example.com/.well-known/security.txt
Maximum number of downstream pipelines that can be triggered per minute (for a given project, user, and commit).
Maximum requests a user can make per 8 hours to aiAction endpoint
Maximum requests a user can make per minute to code suggestions endpoint
Definition for resource usage limits enforced in Sidekiq workers
object
Settings for VS Code Extension Marketplace
object
Enables VS Code Extension Marketplace for Web IDE and Workspaces
The preset configuration of URL’s for the VS Code Extension Marketplace
VS Code Extension Marketplace URL’s when preset is ‘custom’
object
Enables enforcing language server restrictions
The minimum language server version to accept requests from
Enable encryption for Terraform state files
Logging field schema version (v0, v1, …). Cannot be downgraded.
Version to dual-emit alongside schema_version. Must be strictly greater than schema_version, or omit/null to disable.
Restrictions on the complexity of uploaded RSA keys. A value of -1 disables all RSA keys.
Restrictions on the complexity of uploaded DSA keys. A value of -1 disables all DSA keys.
Restrictions on the complexity of uploaded ECDSA keys. A value of -1 disables all ECDSA keys.
Restrictions on the complexity of uploaded ED25519 keys. A value of -1 disables all ED25519 keys.
Restrictions on the complexity of uploaded ECDSA_SK keys. A value of -1 disables all ECDSA_SK keys.
Restrictions on the complexity of uploaded ED25519_SK keys. A value of -1 disables all ED25519_SK keys.
Enable support for AWS hosted elasticsearch
AWS IAM access key
The AWS region the elasticsearch domain is configured
AWS IAM secret access key
Enable Elasticsearch indexing
Enable Elasticsearch search
Pause Elasticsearch indexing (global control for both Advanced Search and ActiveContext)
Pause advanced search indexing
The url to use for connecting to Elasticsearch. Use a comma-separated list to support clustering (e.g., “http://localhost:9200, http://localhost:9201”)
The username of your Elasticsearch instance.
The password of your Elasticsearch instance.
Limit Elasticsearch to index certain namespaces and projects
Pause ActiveContext indexing
The namespace ids to index with Elasticsearch.
The project ids to index with Elasticsearch.
Enable Secret Detection Token Revocation
The configured Secret Detection Token Revocation instance URL
The configured Secret Detection Revocation Token Types instance URL
Additional text added to the bottom of every email for legal/auditing/compliance reasons
Disable project owners ability to delete project
Disable personal access tokens
Size limit per repository (MB)
ID of project where instance-level file templates are stored.
Flag indicating if users are permitted to update their profile name
Disable Users ability to overwrite approvers in merge requests.
Disable Merge request author ability to approve request.
Disable Merge request committer ability to approve request.
Maven package requests are forwarded to repo.maven.apache.org if not found on GitLab.
NPM package requests are forwarded to npmjs.org if not found on GitLab.
PyPI package requests are forwarded to pypi.org if not found on GitLab.
Virtual Registries API endpoints rate limit.
Allow owners to manage default branch protection in groups
When instance is in maintenance mode, non-admin users can sign in with read-only access and make read-only API requests
Message displayed when instance is in maintenance mode
Maximum duration (in minutes) of a session for Git operations when 2FA is enabled
Maximum number of unique repositories a user can download in the specified time period before they are banned
Reporting time period (in seconds)
List of usernames excluded from Git anti-abuse rate limits
List of user ids who will be emailed when Git abuse rate limit is exceeded
Ban users from the application when they exceed maximum number of unique projects download in the specified time period
Flag indicating if users are permitted to make their profiles private
To enforce token expiration for Service accounts users
Indicates whether GitLab Duo features are enabled for the group
Indicates if the GitLab Duo features enabled setting is enforced for all subgroups
Indicates if direct connection for Code Suggestions is disabled for users
Enable receptive mode for GitLab Agents for Kubernetes
Enable automatic reviews by GitLab Duo on merge requests
Number of days before security scan data is considered stale (7-90)
Indicates whether custom agents are allowed for this instance
Indicates if the custom agents enabled setting is enforced for all groups
Indicates whether custom flows are allowed for this instance
Indicates if the custom flows enabled setting is enforced for all groups
Indicates whether external agents are allowed for this instance
Indicates if the external agents enabled setting is enforced for all groups
Indicates whether GitLab Duo remote flows are enabled for the instance
Indicates if the GitLab Duo remote flows enabled setting is enforced for all subgroups
Default container registry for Duo Agent Platform foundational flow images
OTEL Collector endpoint URL for CI job telemetry
Sampling rate for CI job telemetry (0.0 to 1.0)
AI entity access rules for controlling Duo feature access
object
Object containing through namespace information
object
ID of the through namespace
Name of the through namespace
Full path of the through namespace
List of accessible features
Enable built-in project templates for project creation
Enforce the built-in project templates setting for all groups
The ID of a project to use as the Duo Code Review custom instructions template for this instance
Responses
Section titled “ Responses ”OK
object
Elasticsearch index settings.
object
Name of the Elasticsearch index alias.
Number of shards for the Elasticsearch index.
Number of replicas for the Elasticsearch index.
Example
{ "elasticsearch_index_settings": [ { "alias_name": "gitlab-production", "number_of_shards": 5, "number_of_replicas": 1 } ]}Bad Request
Unauthorized
Forbidden