GitLab Secrets Manager on GitLab.com - Limited Availability (LA)
## Executive Summary
GitLab Secrets Manager eliminates secret sprawl by making secure credential management is a native part of the platform. No additional infrastructure to manage for SaaS, no separate access policies to maintain. Secrets live where the work happens, with full audit visibility and controls that meet enterprise compliance requirements out of the box. By offering this, customers can securely store and manage secrets natively within GitLab, reducing reliance on third-party tools and eliminating insecure practices like storing secrets in CI variables.
## Delivery goals
The first release of GitLab Secrets Manager will be on GitLab.com with other distributions followed-up in a phased approach. GitLab Secrets Manager will be production-grade for our customers on GitLab.com. Limited availability is only noted because not all distributions are supported immediately.
Capabilities in this release:
- **Group-level secret storage**
- **Project-level secret storage**
- **Ability to create/edit/delete a secret.**
- **Inject secret into CI Job**
- **Limit secret application to environment or branch.**
- **Send rotation reminders**
- **Provide ability to set permissions including designated roles/groups/specific users at the project level.**
- **Proper backend encryption for secrets at rest.**
- **Segregation for multi-tenant to ensure privacy.**
- **Namespacing secrets available by default for group and project secrets**
- **Support for non-CI/CD use cases with a Read API**
- [**Audit Events**](https://docs.gitlab.com/user/compliance/audit_event_types/#secrets-management)
- [**Packaging and Pricing**](https://gitlab.com/groups/gitlab-org/-/work_items/21254)
To see what's next on the roadmap - see https://gitlab.com/groups/gitlab-org/-/epics/10108+
## Timeline & Milestones
* **Closed Beta Launch: FY26Q4 (Feb-March 2026)**
* **Public Beta Launch: FY27Q2 (May 2026)**
* **GitLab.com Launch: FY27Q3 (August 2026)**
## Target Metrics and Success Criteria
* Business and Product
* Convert 1 beta participant into GA Customer
* 2 design partners to adopt at GA or Post-GA
* Performance and Quality Metrics
* Availability: 99.9%
* Error rate:
* Latency:
## Acceptance Criteria
### Feature completeness
* All delivery goals implemented and tested :hourglass_flowing_sand:
* Packaging restrictions enforced correctly :hourglass_flowing_sand:
* Performance benchmarks established :hourglass_flowing_sand:
### Security and compliance
* Threat model complete :hourglass_flowing_sand:
* Penetration testing passed with no critical findings :white_check_mark:
### Operational readiness
* Monitoring and alerts configured :hourglass_flowing_sand:
* Runbooks for on-call established :hourglass_flowing_sand:
* Support team readiness complete :hourglass_flowing_sand:
## GTM and Packaging
* https://gitlab.com/groups/gitlab-org/-/work_items/21254+
## Rollout strategy
* https://gitlab.com/groups/gitlab-org/-/work_items/20758+
#### Dependencies
- Cross-team dependencies tracked here: https://docs.google.com/document/d/1k6swABYMITI5H8_L8PLNt5psXdPSBA1oDAm1O8XgLSc/edit?tab=t.0#heading=h.z6fiuct8k1jp
#### DRIs
- **PM**: @jrandazzo
- **EM**: @mmishaev @cfleming3
- **UX/PDM**: @sayobittencourt
- **Group(s)**: ~"group::secrets manager application"
- **Engineering Owner**: @mmishaev
epic