Skip to content
Back to skills

Avoid Gitlab Cicd Pitfalls

ASecurity

Avoid common GitLab CI/CD mistakes — rules gotchas, silent failures, and YAML merge traps.

  • 19 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
ai-agentsgodockergitapidevopsci/cd

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add rondoflow/rondoflow --skill avoid-gitlab-cicd-pitfalls --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Avoid Gitlab Cicd Pitfalls?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Avoid Gitlab Cicd Pitfalls
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rondoflow-avoid-gitlab-cicd-pitfalls/badge)](https://www.skillsdirectory.com/skills/rondoflow-avoid-gitlab-cicd-pitfalls)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: avoid-gitlab-cicd-pitfalls
description: "Avoid common GitLab CI/CD mistakes — rules gotchas, silent failures, and YAML merge traps."
category: "DevOps & Infra"
author: community
version: "1.0.0"
icon: server
---

## Rules Gotchas
- `rules:` and `only:/except:` can't mix — use one or the other per job
- First matching rule wins — put specific rules before general ones
- Missing `when:` defaults to `on_success` — `rules: - if: $CI_COMMIT_TAG` runs on tag
- Empty rules array `rules: []` means never run — different from no rules at all
- Add `- when: never` at end to prevent fallthrough — otherwise unmatched conditions may run

## Silent Failures
- Protected variables missing on non-protected branches — job runs but variable is empty
- Runner tag mismatch — job stays pending forever with no error
- `docker:dind` on non-privileged runner — fails with cryptic Docker errors
- Masked variable format invalid — variable exposed in logs anyway

## YAML Merge Traps
- `extends:` doesn't deep merge arrays — scripts, variables arrays get replaced, not appended
- Use `!reference [.job, script]` to reuse — `script: [!reference [.base, script], "my command"]`
- `include:` files can override each other — last one wins for same keys
- Anchors `&`/`*` don't work across files — use `extends:` for cross-file reuse

## Artifacts vs Cache
- Cache not guaranteed between runs — treat as optimization, not requirement
- Artifacts auto-download by stage — add `dependencies: []` to skip if not needed
- `needs:` downloads artifacts by default — `needs: [{job: x, artifacts: false}]` to skip

## Docker-in-Docker
- Shared runners usually don't support privileged — need self-hosted or special config
- `DOCKER_HOST: tcp://docker:2375` required — job uses wrong Docker otherwise
- `DOCKER_TLS_CERTDIR: ""` or configure TLS properly — half-configured TLS breaks builds

## Pipeline Triggers
- `CI_PIPELINE_SOURCE` differs by trigger — `push`, `merge_request_event`, `schedule`, `api`, `trigger`
- MR pipelines need `rules: - if: $CI_MERGE_REQUEST_IID` — not just branch rules
- Detached vs merged result pipelines — detached tests source, merged tests result of merge

Files in this skill

  • SKILL.md2.2 KB
  • manifest.json310 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…