Back to Gitlabhq

GitLab Dedicated for Government

doc/subscriptions/gitlab_dedicated_for_government/_index.md

19.1.09.4 KB
Original Source

{{< details >}}

  • Tier: Ultimate
  • Offering: GitLab Dedicated for Government

{{< /details >}}

GitLab Dedicated for Government is a single-tenant SaaS solution designed for government agencies and organizations in regulated industries. GitLab manages all infrastructure, operations, and compliance requirements, so your teams can focus on development.

Your instance has the following capabilities:

  • The complete GitLab Ultimate feature set and DevSecOps platform
  • Isolated infrastructure in a dedicated AWS account deployed on AWS GovCloud in the US-West region
  • High availability and disaster recovery

Compliance certifications

GitLab Dedicated for Government is authorized under the following programs, so your agency can procure and deploy without additional compliance reviews:

FedRAMP Moderate : Meets federal security requirements for cloud services, with Authority to Operate (ATO).

GovRAMP (Package ID: SR25098) : Meets state and local government security requirements for cloud services.

TX-RAMP Level 2 (TX-RAMP ID: TX1549412) : Meets Texas state security requirements for cloud services.

Security architecture

Your instance includes the following security controls:

  • FedRAMP Moderate and GovRAMP compliance with continuous monitoring aligned to federal and state requirements
  • Data sovereignty guaranteed through AWS GovCloud infrastructure in the US-West region
  • Isolated infrastructure in a dedicated AWS account separate from all other tenants
  • Encryption standards that meet FIPS requirements for data at rest and in transit
  • Access controls that follow principle of least privilege with comprehensive audit trails

Data residency and infrastructure isolation

To meet US data residency requirements, your instance is deployed on AWS GovCloud in the US-West region. The GitLab instance runs exclusively on AWS GovCloud. Your own workloads and adjacent systems can run on any platform, including GCP or Azure, and integrate with your instance.

All customer data, including repositories, databases, artifacts, and backups, remains within the AWS GovCloud boundary. Your environment includes all infrastructure necessary to host the GitLab application with complete isolation from GitLab.com.

Data is encrypted at rest and in transit using FIPS-compliant encryption standards.

Access controls

Your environment is protected through multiple layers of security controls:

  • Engineers do not have direct access to your tenant environment and operate with the minimum permissions required for their role.
  • Infrastructure is monitored 24 hours a day, 7 days a week for security threats and anomalies.
  • All access and changes are logged and reviewed by the GitLab Security Incident Response Team.
  • Access requests follow formal security policies and approval workflows aligned with government compliance requirements.

Available features

GitLab Dedicated for Government provides the complete GitLab Ultimate feature set. These features are designed to work within FedRAMP and GovRAMP compliance and government security frameworks.

Availability and scalability

Your instance leverages modified versions of the cloud native hybrid reference architectures with high availability enabled.

When onboarding, GitLab matches you to the closest reference architecture size based on your number of users.

[!note] The published reference architectures serve as a foundation. GitLab Dedicated for Government extends these with additional AWS services for enhanced security and compliance, which means costs differ from standard reference architecture estimates.

Disaster recovery

GitLab backs up all your datastores, including databases and Git repositories. These backups are tested and stored securely in a separate cloud region by default for added redundancy.

Authentication and authorization

You can configure single sign-on (SSO) using:

Your instance acts as the service provider, and you provide the necessary configuration for GitLab to communicate with your Identity Provider (IdP).

You can configure multiple identity providers for your instance.

Email delivery

Email is sent using Amazon Simple Email Service (Amazon SES). The connection to Amazon SES is encrypted.

To send application email using an SMTP server instead of Amazon SES, you can configure your own email service.

Advanced search capabilities are included. You can search across your entire GitLab instance including code, work items, merge requests, and more.

GitLab Duo

GitLab Duo AI features are authorized under FedRAMP and GovRAMP and available to federal, state, local, and education agencies with no additional compliance review. Available features include:

Unavailable features

To maintain FedRAMP and GovRAMP certification and meet government security requirements, some GitLab features are not available in GitLab Dedicated for Government.

Authentication, security, and networking

FeatureAlternative
LDAP or Kerberos authenticationUse SAML or OIDC with your identity provider
FortiAuthenticator or FortiToken 2FAUse identity provider MFA

Communication and collaboration

FeatureAlternative
Reply-by emailUse web interface
Service DeskUse issue tracking
MattermostUse external chat tools

Development and AI features

FeatureAlternative
Some GitLab Duo AI capabilitiesSee supported AI features
Server-side Git hooksUse push rules or webhooks
Features configured outside of the GitLab user interfaceContact support

Application features

GitLab Pages is not available when a custom domain is configured. When you configure a custom domain, the original tenant_name.gitlab-dedicated.com domain is no longer available, which prevents GitLab Pages from functioning.

Operational features

The following operational features are not available:

  • Geo
  • Self-serve purchasing and configuration

Feature flags

Feature flags control which features are available in your instance:

  • Only features with flags enabled by default are available
  • Features with flags disabled by default are not available
  • You cannot modify feature flags

Service operations

GitLab manages all maintenance, monitoring, and support for your instance using government-specific operational processes. These processes prioritize compliance, security, and stability throughout all maintenance and support activities.

Maintenance

Your instance receives maintenance during fixed weekly windows. For details, see GitLab Dedicated maintenance operations.

Releases and versions

Your instance runs one release behind the latest GitLab version. For example, if the latest version is 16.8, your instance runs 16.7.

This approach provides stability while you receive critical security patches through emergency maintenance. Features are rolled out after compliance and change review processes.

Service level agreement

Your instance maintains a service level agreement (SLA) of 99.9% monthly availability. GitLab uses internal service level objectives (SLOs) to support delivery of this SLA commitment.

The following targets apply:

  • Recovery point objective (RPO) target: 4 hours maximum data loss window in a disaster recovery scenario
  • Recovery time objective (RTO) target: Service restoration is prioritized by incident severity and impact

GitLab works to restore service as quickly as possible while ensuring data integrity and security.

Contact sales

Ready to get started? Contact our sales team to discuss your requirements and learn how we can support your organization's compliance and security needs.