Overview
The GitLab integration links a Kaneo project to a project on GitLab.com or your own instance. Tasks sync with issues, and webhooks keep Kaneo updated when issues, merge requests, or pushes change. You need:- GitLab URL:
https://gitlab.com, or e.g.https://gitlab.example.com. - Access token with the
apiscope and at least the Developer role on the target project. - Project path: the full path including any groups, same as in the GitLab UI.
Access token
- In GitLab, open Settings → Access tokens → Add new token (personal, project, and group tokens all work).
- Enable the api scope and pick a role of Developer or higher.
- Copy the token and store it securely; paste it into Kaneo’s GitLab integration settings and leave Token type on Personal, project or group access token.
Authorization instead of PRIVATE-TOKEN. GitLab expires OAuth2 tokens two hours after they are created, so an access token is the better fit for a long-lived link.
Webhook in GitLab
Kaneo verifies incoming webhooks with a secret token stored per integration, which GitLab sends back in a header rather than signing the payload, so serve Kaneo over HTTPS.Where to create the webhook in GitLab
- Log in to GitLab and open the same project you linked in Kaneo (
group/project). - Open the project Settings.
- In the left sidebar, open Webhooks (under the “Settings” section).
- If you do not see it, you need at least the Maintainer role on that project.
- Click Add new webhook.
https://<your-gitlab-host>/<project path>/-/hooks
Example: https://gitlab.com/acme/my-app/-/hooks
Configure the webhook
- Connect the project in Kaneo Project → Integrations → GitLab and save.
- Copy the Webhook URL and Secret token shown in Kaneo (after saving).
- In GitLab: Settings → Webhooks → Add new webhook.
- Set URL to the Kaneo webhook URL.
- Set Secret token to the exact value from Kaneo.
- Leave Enable SSL verification on, unless your Kaneo host uses a self-signed certificate.
-
Enable triggers:
- Push events
- Issues events
- Comments
- Merge request events
-
Save and use Test → Push events to confirm a
200response from Kaneo.- If Kaneo runs on a private address, an administrator must first enable Admin → Settings → Network → Outbound requests → Allow requests to the local network from webhooks and integrations.
https://your-kaneo-host/api/gitlab-integration/webhook/<integrationId>
GitLab on a private network
By default Kaneo refuses a GitLab URL that resolves to a private or loopback address. If your instance is only reachable inside your network, setKANEO_ALLOW_PRIVATE_WEBHOOK_DESTINATIONS=true on the API. The same variable lifts the check for Gitea and notification destinations, so only enable it on a trusted deployment.
Without this variable the GitLab URL must use https, since the access token is sent with every request.
What is not synced
- Confidential issues. They are skipped on import and ignored when they arrive through the webhook. If an issue is made confidential later, its task keeps the last public content and stops receiving updates.
- Internal notes and comments on confidential issues.