190 lessons published

Stage 05 · Continuous Integration & Delivery

GitLab CI/CD Complete Course

Master GitLab CI/CD from pipeline fundamentals and runners through DAGs, reusable components, security scanning, cloud identity, deployments, governance, optimization, and production operations.

GLCI
38chapters
190lessons
Intermediatestarting level
Hands-onlearning mode
Course state190 published · 0 planned

Course brief

A production-grade GitLab CI/CD curriculum for secure, scalable software delivery.

This course is organized as a progressive operational curriculum from fundamentals through advanced production practice. Lesson files are reserved with stable repository paths so content can be added later without changing URLs or navigation.

By the end

You will be able to

  • Design maintainable pipelines with jobs, rules, DAGs, reusable components, and child pipelines
  • Operate GitLab Runner securely across shell, Docker, Kubernetes, and autoscaled environments
  • Build test, package, release, environment, and deployment workflows with traceable artifacts
  • Integrate security scanning, SBOMs, OIDC, policy controls, and software-supply-chain safeguards
  • Troubleshoot, optimize, govern, and scale CI/CD across large teams and enterprise estates

Complete syllabus

38 chapters in prerequisite order.

The structure goes beyond command references and feature lists. It includes architecture, security, reliability, troubleshooting, automation, governance, performance, and realistic production workflows.

01

Chapter 1

Continuous Integration and Delivery Foundations, GitLab Pipeline Architecture, and Delivery Flow

5 lessons
02

Chapter 2

.gitlab-ci.yml Structure, Pipeline Compilation, Keywords, Defaults, and Configuration Validation

5 lessons
03

Chapter 3

Jobs, Stages, Scripts, Images, Services, before_script, after_script, and Exit Behavior

5 lessons
04

Chapter 4

GitLab Runner Architecture, Registration, Runner Managers, Job Execution, and Lifecycle

5 lessons
05

Chapter 5

Runner Executors: Shell, Docker, Docker Autoscaler, Kubernetes, SSH, and Custom Execution Models

5 lessons
06

Chapter 6

CI/CD Variables, Predefined Variables, File Variables, Masking, Protection, Expansion, and Precedence

5 lessons
07

Chapter 7

Secrets Management, External Secret Providers, Protected Data, Rotation, and Least-Privilege Patterns

5 lessons
08

Chapter 8

workflow:rules, Job rules, if Expressions, changes, exists, Pipeline Sources, and Conditional Execution

5 lessons
09

Chapter 9

Stages, needs DAGs, Dependency Graphs, Early Execution, and Pipeline Critical-Path Design

5 lessons
10

Chapter 10

Artifacts, Reports, Retention, Dependencies, needs:artifacts, and Cross-Job Data Flow

5 lessons
11

Chapter 11

Caches, Cache Keys, Fallback Keys, Distributed Cache, Dependency Reuse, and Cache Correctness

5 lessons
12

Chapter 12

YAML Reuse with include, extends, Anchors, !reference, Hidden Jobs, and Template Architecture

5 lessons
13

Chapter 13

CI/CD Components, Component Catalog, inputs, Versioned Reuse, and Organization-Wide Pipeline Building Blocks

5 lessons
14

Chapter 14

Parent-Child Pipelines, Dynamic Child Pipelines, Generated Configuration, and Monorepo Decomposition

5 lessons
15

Chapter 15

Multi-Project Pipelines, Downstream Triggers, Cross-Project Dependencies, and Platform-Oriented Delivery

5 lessons
16

Chapter 16

Merge Request Pipelines, Merged Results Pipelines, Merge Trains, and Pre-Merge Validation

5 lessons
17

Chapter 17

Parallel Jobs, parallel:matrix, Test Sharding, Fan-Out/Fan-In, and High-Throughput Pipeline Design

5 lessons
18

Chapter 18

Concurrency, resource_group, interruptible Jobs, Retry Policies, Timeouts, and Duplicate-Pipeline Control

5 lessons
19

Chapter 19

Environments, Deployments, Environment Tiers, URLs, Deployment History, and Operational Traceability

5 lessons
20

Chapter 20

Review Apps, Dynamic Environments, Ephemeral Test Stacks, Route Maps, and Environment Cleanup

5 lessons
21

Chapter 21

Protected Environments, Deployment Approvals, Freeze Windows, Manual Gates, and Separation of Duties

5 lessons
22

Chapter 22

Tags, Releases, Release CLI, Changelogs, Evidence, Asset Links, and Release-Orchestration Pipelines

5 lessons
23

Chapter 23

Container Registry, Package Registry, Generic Packages, Dependency Proxy, and Artifact Promotion

5 lessons
24

Chapter 24

Test Reports, Coverage, JUnit, Code Quality, Browser Performance, Accessibility, and Pipeline Feedback

5 lessons
25

Chapter 25

SAST, Dependency Scanning, Secret Detection, Container Scanning, DAST, IaC Scanning, and Security Gates

5 lessons
26

Chapter 26

SBOM Generation, Dependency Lists, Vulnerability Reports, Policy Evaluation, and Supply-Chain Evidence

5 lessons
27

Chapter 27

ID Tokens, OIDC Workload Identity, Cloud Federation, Vault Authentication, and Secretless Deployments

5 lessons
28

Chapter 28

Kubernetes Agent, Cluster Access, GitOps-Oriented Delivery, Kubernetes Deployments, and Environment Integration

5 lessons
29

Chapter 29

Infrastructure-as-Code Pipelines, Terraform/OpenTofu Workflows, Plan Reviews, State Safety, and Drift Controls

5 lessons
30

Chapter 30

Runner Fleets, Autoscaling, Docker Machine Migration, Kubernetes Runners, Ephemeral Workers, and Capacity Planning

5 lessons
31

Chapter 31

Runner Security, Isolation Boundaries, Privileged Containers, Fork Pipelines, Untrusted Code, and Threat Modeling

5 lessons
32

Chapter 32

Pipeline Supply-Chain Security, Dependency Pinning, Image Digests, Signing, Provenance, and Trusted Builders

5 lessons
33

Chapter 33

Pipeline Schedules, Trigger Tokens, Pipeline API, Webhooks, ChatOps, and Event-Driven Automation

5 lessons
34

Chapter 34

CI/CD Analytics, Job Logs, Runner Metrics, Queue Time, Failure Taxonomy, and Observability

5 lessons
35

Chapter 35

Pipeline Performance, Cost Control, Caching Strategy, Queue Reduction, Selective Execution, and Optimization

5 lessons
36

Chapter 36

Compliance Pipelines, Pipeline Execution Policies, Governance, Audit Evidence, and Enterprise Controls

5 lessons
37

Chapter 37

Pipeline Troubleshooting, YAML Debugging, Runner Failures, Network Issues, Flaky Jobs, and Recovery Playbooks

5 lessons
38

Chapter 38

Production Capstone: Build, Secure, Scale, Observe, and Govern a Complete GitLab Delivery Platform

5 lessons

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this address.