GitLab Platform Foundations: GitLab.com, Self-Managed, Dedicated, Tiers, and Architecture: Guided Hands-On Workflow and Core Operations
Create a disposable GitLab.com project, connect it to a local Git clone, and verify the same state through the UI, Git, optional glab, and a read-only REST request.
Learning objectives
- Create a disposable GitLab.com Free project in a personal namespace without depending on paid features or a group subscription.
- Map the project path, namespace, visibility, and default branch between the web UI and machine-readable API state.
- Clone, commit, and push a tiny change while predicting which local Git refs and GitLab-hosted views will change.
- Use optional glab inspection safely without exposing authentication tokens.
- Verify causality with commit SHAs and project metadata, then apply safe cleanup rules.
1. Preflight and safety boundary
You need a GitLab.com account and Git installed.
glab is optional. If glab is already
authenticated, use it only for read-only inspection in this chapter.
Do not create a personal access token here; Chapter 02 teaches
credentials deliberately.
-
Use a project name such as
platform-foundations-lab. - Prefer your personal namespace so the lab does not depend on current GitLab.com top-level-group limits or group billing.
- Use public visibility for the mandatory REST exercise, unless you have a reason not to publish even synthetic content. If public projects are disallowed by your account policy, keep it private and use the web/Git path only; the unauthenticated REST step becomes a supplied-response exercise.
- Do not place employer code, credentials, customer information, or production configuration in the lab.
2. Create the disposable project
In the current GitLab UI, use
Create new → New project/repository → Create blank
project. Enter platform-foundations-lab, select your personal
namespace, choose Public for the default lab, and initialize the
repository with a README. Initializing with a README is important
because it creates a repository commit and therefore a default
branch immediately.
Before selecting Create project, predict two state changes:
- A GitLab project resource will be created at a namespace-qualified path.
-
Because README initialization is enabled, the project’s Git
repository will contain at least one commit and a default branch,
normally
mainunless a different default is configured at a higher level.
3. Inspect hosted state before cloning
Do not start by typing Git commands. First record the hosted state GitLab presents. The exact navigation grouping can move between releases; anchor your notes to resources rather than memorizing sidebar coordinates.
| Observation | What it proves | What it does not prove |
|---|---|---|
| Project path | Host + namespace + project identity. | Which local clone you currently have open. |
| Visibility | GitLab access policy for the project. | Whether a particular user has extra membership-based rights. |
| Default branch | Which branch GitLab treats as default. | Which branch your local working tree currently has checked out. |
| README commit SHA | Identity of a repository commit visible to GitLab. | Whether your local clone has fetched that commit yet. |
| Plan/Build/Deploy/Secure/Operate surfaces | Which platform feature areas the UI currently exposes. | That every feature inside them is enabled or included in your tier. |
4. Prove the project with the public REST API
GitLab’s Projects API accepts either a numeric project ID or a
URL-encoded project path. Replace YOUR_NAMESPACE before
running the example. The slash between namespace and project becomes
%2F.
# Bash / Git Bash / macOS / Linux
curl --silent --show-error \
"https://gitlab.com/api/v4/projects/YOUR_NAMESPACE%2Fplatform-foundations-lab"
# Windows PowerShell / PowerShell 7: call curl.exe explicitly for curl flags
curl.exe --silent --show-error `
"https://gitlab.com/api/v4/projects/YOUR_NAMESPACE%2Fplatform-foundations-lab"
Expect a JSON object shaped like this; IDs and URLs will differ:
{
"name": "platform-foundations-lab",
"path_with_namespace": "YOUR_NAMESPACE/platform-foundations-lab",
"default_branch": "main",
"visibility": "public",
"namespace": {
"kind": "user",
"full_path": "YOUR_NAMESPACE"
},
"web_url": "https://gitlab.com/YOUR_NAMESPACE/platform-foundations-lab"
}
This is useful because it turns a visual observation into machine-readable evidence. It still does not prove your local Git state.
5. Clone and compare local Git state
git clone https://gitlab.com/YOUR_NAMESPACE/platform-foundations-lab.git
cd platform-foundations-lab
git remote -v
git branch --show-current
git rev-parse HEAD
git log --oneline --decorate -5
git status --short --branch
Verify that origin points to the project you just
inspected, the current branch matches the GitLab default branch, and
the local HEAD SHA matches the README commit shown by
GitLab. If any identity differs, stop. You may be in the wrong
directory, on the wrong branch, or connected to the wrong remote.
flowchart LR UI[GitLab project\nnamespace + visibility + default branch] --> REM[Remote repository\nrefs/heads/main] REM -->|git clone/fetch| LOC[Local clone\norigin/main + main + HEAD] API[Projects API] --> UI GLAB[glab repo view\noptional] --> UI
The API and glab observe GitLab-hosted project state. Git observes the local clone and remote-tracking refs. Their values should correlate, but they are not the same storage layer.
6. Make one controlled change and predict the result
Create a tiny file containing only synthetic learning notes. Before pushing, write down your prediction: a new commit will exist locally first; GitLab will not see it until the push succeeds.
printf '%s\n' \
'# Platform Foundations Lab' \
'' \
'- Git owns commits and refs.' \
'- GitLab owns project metadata and collaboration state.' \
> platform-map.md
git add platform-map.md
git commit -m "docs: add platform boundary map"
git rev-parse HEAD
git status --short --branch
# Only after recording the local SHA:
git push origin HEAD
PowerShell alternative for file creation:
@(
'# Platform Foundations Lab',
'',
'- Git owns commits and refs.',
'- GitLab owns project metadata and collaboration state.'
) | Set-Content -Encoding utf8 platform-map.md
git add platform-map.md
git commit -m "docs: add platform boundary map"
git rev-parse HEAD
git push origin HEAD
After the push, GitLab’s branch/commit view should show the same SHA. This is causal verification: the Git object was created locally, transferred through Git transport, then became reachable by a branch ref in the hosted repository.
7. Optional glab read-only inspection
If glab is already configured, use its current
context-aware commands. Do not display stored tokens.
glab auth status --hostname gitlab.com
glab repo view -F json
glab auth status determines context from the remote,
GITLAB_HOST, or configuration; specifying
--hostname gitlab.com removes ambiguity. The command
has a --show-token option, but this course
intentionally does not use it because terminal scrollback,
screenshots, logs, and prompt history are all unnecessary exposure
surfaces.
8. Four-surface verification
- Web UI: project path, visibility, default branch, latest commit SHA.
-
Local Git:
git remote -v,git branch --show-current,git rev-parse HEAD. -
REST:
path_with_namespace,default_branch,visibility,namespace.kind. - glab, optional: project view from the same repository context.
If all four identify the same host/project/branch/commit, you have much stronger evidence than “the page looked right.”
9. Challenge — choose the right control surface
Without copying a click path, decide where you would investigate each request:
- “Change the README text.” → repository content / Git change.
- “Make this project private.” → GitLab project setting and permission/tier/policy check.
- “Why does my laptop show an older commit?” → local Git fetch/branch state.
- “Why did no CI job start?” → GitLab pipeline creation/rules first, then runner execution if a job exists.
- “Which group owns this project?” → namespace/project metadata.
10. Cleanup and rollback
The safest default is to keep the project clearly marked disposable until you complete Lesson 5. If you must clean it now, verify that the project contains no valuable data. Archiving or deleting the hosted project is a GitLab platform action and does not merely remove your local clone.
Local rollback is separate: deleting the local directory affects only that clone. If you keep the project, you can re-clone it later.
Knowledge check
You created a commit locally but the GitLab UI still shows the old SHA. What should you check first?
Check whether the commit was pushed to the intended remote and branch. A local commit does not become hosted state until Git transport updates a remote ref successfully.
Why does the REST example encode the slash in namespace/project as %2F?
The Projects API accepts the namespaced path as one path parameter. URL-encoding preserves the slash as data inside that parameter instead of treating it as another URL route separator.
Why is glab optional in this lesson?
Authentication setup and credential design belong to Chapter 02. The core platform-state lesson can be completed with GitLab.com Free, local Git, the web UI, and a public read-only REST request.
A page shows a Security navigation area. Does that prove all security features are available?
No. Navigation visibility is not a feature-entitlement proof. Check the specific feature’s current tier/offering/version documentation and your permissions/policy.
Summary
You created one disposable GitLab project, observed it before mutation, connected it to a local clone, created a commit, pushed it, and verified identity across multiple surfaces. The important habit is not the command sequence; it is predicting which resource changes and independently verifying the result.
Official references
Keep the academy open
Support free, practical DevOps education.
Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this
address.