slug: gitlab-ci provider: GitLab CI/CD generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 34 edges: - tag: feature_flags spec_file: gitlab-ci-feature-flags-api-openapi.yml capability_id: BC-4210.50 capability_id_l1: BC-4210 capability_name: Feature Flag Management confidence: 0.95 evidence: POST /api/v4/projects/{id}/feature_flags "Create a new feature flag"; "List all feature flag user lists for a project"; schema API_Entities_FeatureFlag_Strategy reason: Operations are full CRUD over feature flags plus user lists and strategies used to target features to cohorts — exactly Feature Flag Management (lifecycle and runtime control of flags, decoupling deploy from release). - tag: pipelines spec_file: gitlab-ci-pipelines-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.92 evidence: '''Create a new pipeline''; ''Gets the test report for a given pipeline''; ''Retry builds in the pipeline''' reason: Core CI pipeline build orchestration, jobs and test reports — continuous integration management. - tag: unleash spec_file: gitlab-ci-unleash-api-openapi.yml capability_id: BC-4210.50 capability_id_l1: BC-4210 capability_name: Feature Flag Management confidence: 0.92 evidence: GET /api/v4/feature_flags/unleash/{project_id}/client/features, 'Get a list of features (v2 client support)' reason: Unleash-compatible feature flag client endpoints serving flag definitions and client registration/metrics — runtime feature flag management. - tag: ci_jobs spec_file: gitlab-ci-ci-jobs-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.9 evidence: POST /api/v4/projects/{id}/jobs/{job_id}/retry ... 'Trigger an actionable job (manual, delayed, etc)' with schema API_Entities_Ci_Job, API_Entities_Ci_PipelineBasic reason: Operations list, inspect, cancel, retry and play CI pipeline jobs and fetch build traces — core continuous integration build-pipeline execution. - tag: pipeline_schedules spec_file: gitlab-ci-pipeline-schedules-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.88 evidence: '''Play a scheduled pipeline immediately''; schemas API_Entities_Ci_PipelineSchedule, API_Entities_Ci_Variable' reason: Scheduling and variable configuration of CI pipelines is continuous integration pipeline management. - tag: access_requests spec_file: gitlab-ci-access-requests-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"Requests access for the authenticated user to a group." / "Approves an access request for the given user." / "Denies an access request for the given user."' reason: Request-approve-deny lifecycle for user membership of groups and projects, returning API_Entities_Member and API_Entities_AccessRequester — this is access request and entitlement granting, squarely Identity & Access Management. - tag: branches spec_file: gitlab-ci-branches-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.85 evidence: GET /api/v4/projects/{id}/repository/branches ... PUT /api/v4/projects/{id}/repository/branches/{branch}/protect reason: Operations create, delete, list and protect Git repository branches — source-control practice, which BC-4200.40 Software Construction Management explicitly covers ('source control, code review'). - tag: ci_variables spec_file: gitlab-ci-ci-variables-api-openapi.yml capability_id: BC-4210.60 capability_id_l1: BC-4210 capability_name: Configuration & Secrets Management confidence: 0.85 evidence: GET /api/v4/projects/{id}/variables ... POST /api/v4/admin/ci/variables with schema API_Entities_Ci_Variable reason: CRUD over CI/CD variables (including masked/protected secrets) at project, group and instance scope is exactly Configuration & Secrets Management for pipeline and runtime consumption. - tag: commits spec_file: gitlab-ci-commits-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.85 evidence: '"Create a new commit", "Cherry pick commit into a branch", "Revert a commit in a branch"' reason: Source-control operations on commits plus commit comments map to Software Construction Management, which explicitly covers source control and code review practice. - tag: job_artifacts spec_file: gitlab-ci-job-artifacts-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.85 evidence: '"Download the artifacts archive from a job", "Delete the artifacts files from a job", schema "API_Entities_Ci_JobArtifact"' reason: Operations manage build artefacts produced by CI jobs (download, list, keep, expire, delete), which is squarely artefact production within Continuous Integration Management. - tag: jobs spec_file: gitlab-ci-jobs-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.85 evidence: '"List runner''s jobs", "POST /api/v4/jobs/request", "PATCH /api/v4/jobs/{id}/trace", schema "API_Entities_Ci_JobBasicWithProject"' reason: The runner-facing job execution surface — requesting jobs, updating job state, streaming build traces, uploading artefacts — is CI build pipeline execution, i.e. Continuous Integration Management. - tag: merge_request_approvals spec_file: gitlab-ci-merge-request-approvals-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.85 evidence: '"POST .../merge_requests/{merge_request_iid}/approve", "Remove all merge request approvals", schema "API_Entities_MergeRequestApprovalRule_SourceRule"' reason: Approving/unapproving merge requests and configuring approval rules is code-review governance over source-control changes, which is Software Construction Management (source control, code review). - tag: merge_requests spec_file: gitlab-ci-merge-requests-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.85 evidence: POST /api/v4/projects/{id}/merge_requests 'Create merge request'; schemas API_Entities_MergeRequestReviewer, API_Entities_MergeRequestDiff, API_Entities_MRNote reason: Operations create, update, review and diff merge requests — the code review and source-control collaboration surface of software construction, not a generic 'request' workflow. - tag: releases spec_file: gitlab-ci-releases-api-openapi.yml capability_id: BC-4210.30 capability_id_l1: BC-4210 capability_name: Release Engineering Management confidence: 0.85 evidence: '''Create a release'', ''Get a release by a tag name'', ''Collect release evidence'', ''Create a release link'', schema API_Entities_Release' reason: Full lifecycle of software releases keyed by version tags, with release assets, evidence and milestones — squarely release engineering for a software product. - tag: runners spec_file: gitlab-ci-runners-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.85 evidence: List project's runners / Assign a runner to project / Reset the runner registration token for a project, schema API_Entities_Ci_RunnerDetails reason: Manages CI job execution agents (GitLab runners) and their registration to projects/groups — build pipeline infrastructure, squarely continuous integration management. - tag: ci_lint spec_file: gitlab-ci-ci-lint-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.8 evidence: Validate a CI YAML configuration with a namespace reason: Validation of CI pipeline definition files is part of build-pipeline management and pipeline policy enforcement under Continuous Integration Management. - tag: ci_triggers spec_file: gitlab-ci-ci-triggers-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.8 evidence: POST /api/v4/projects/{id}/(ref/{ref}/)trigger/pipeline with schema API_Entities_Ci_Pipeline, API_Entities_Trigger reason: Creating trigger tokens and firing pipelines is direct control of the CI build pipeline, i.e. Continuous Integration Management. - tag: environments spec_file: gitlab-ci-environments-api-openapi.yml capability_id: BC-4210.20 capability_id_l1: BC-4210 capability_name: Environment Management confidence: 0.8 evidence: '"Create a new environment", "Delete multiple stopped review apps", "Stop stale environments"' reason: Lifecycle management of deployment environments including review apps maps directly to Environment Management within release & deployment; some environments are production, which is the only ambiguity. - tag: hooks spec_file: gitlab-ci-hooks-api-openapi.yml capability_id: BC-4270.80 capability_id_l1: BC-4270 capability_name: Webhook & Event Subscription Management confidence: 0.8 evidence: POST /api/v4/projects/{id}/hooks "Add project hook"; "Get events for a given hook id"; "Resend a webhook event"; "Triggers a hook test" reason: Lifecycle of outbound webhook subscriptions plus event log inspection, test triggering and redelivery — squarely Webhook & Event Subscription Management including delivery reliability. - tag: freeze_periods spec_file: gitlab-ci-freeze-periods-api-openapi.yml capability_id: BC-4210.70 capability_id_l1: BC-4210 capability_name: Production Change Authorisation confidence: 0.78 evidence: POST /api/v4/projects/{id}/freeze_periods "Create a freeze period"; schema API_Entities_FreezePeriod reason: Deploy freeze periods define windows in which deployments are blocked — deployment-window governance under Production Change Authorisation. Not a financial or HR 'freeze'. - tag: repositories spec_file: gitlab-ci-repositories-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.78 evidence: GET /api/v4/projects/{id}/repository/tree, .../repository/blobs/{sha}, .../repository/compare, .../repository/contributors, API_Entities_Commit reason: Operations read Git repository trees, blobs, diffs, contributors and generate changelogs — source-control practice, i.e. software construction management. Not the access-requests topic the title implies. - tag: draft_notes spec_file: gitlab-ci-draft-notes-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.75 evidence: /projects/{id}/merge_requests/{merge_request_iid}/draft_notes ... /publish, schema API_Entities_DraftNote reason: Draft review comments on merge requests, created and then published in bulk — the code review discipline within software construction. - tag: features spec_file: gitlab-ci-features-api-openapi.yml capability_id: BC-4210.50 capability_id_l1: BC-4210 capability_name: Feature Flag Management confidence: 0.75 evidence: GET /api/v4/features "List all features"; POST /api/v4/features/{name} "Set or create a feature"; schema API_Entities_FeatureGate reason: The 'features' surface manages instance-level feature gates/definitions — i.e. runtime feature toggles rather than product features. Fits Feature Flag Management, though at platform-operator scope rather than per-project. - tag: files spec_file: gitlab-ci-files-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.75 evidence: GET /api/v4/projects/{id}/repository/files/{file_path}/blame; POST/PUT/DELETE /api/v4/projects/{id}/repository/files/{file_path}; schema API_Entities_BlameRangeCommit reason: Read/write of repository file contents and git blame is source-control practice, which is the substance of Software Construction Management (source control, code review). Not a business object. - tag: usage_data spec_file: gitlab-ci-usage-data-api-openapi.yml capability_id: BC-4280.10 capability_id_l1: BC-4280 capability_name: Product Telemetry Instrumentation confidence: 0.75 evidence: Track usage data event / Track multiple gitlab internal events / Get the latest ServicePing payload reason: Ingests product usage events from client and server runtimes and exposes aggregated usage-ping metrics — product telemetry instrumentation. - tag: submodules spec_file: gitlab-ci-submodules-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.72 evidence: PUT /api/v4/projects/{id}/repository/submodules/{submodule}, API_Entities_CommitDetail reason: Updates a Git submodule reference producing a commit — source-control operation within software construction practice. - tag: access_tokens spec_file: gitlab-ci-access-tokens-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Rotate a personal access token", "Revoke a personal access token", API_Entities_PersonalAccessTokenWithLastUsedIps' reason: Issuance, listing, rotation and revocation of personal and resource access tokens is credential lifecycle management for users of the platform, an IAM concern. Not raised higher because it could also be read as developer credential management for the API ecosystem. - tag: ci_runners spec_file: gitlab-ci-ci-runners-api-openapi.yml capability_id: BC-4210.10 capability_id_l1: BC-4210 capability_name: Continuous Integration Management confidence: 0.7 evidence: Register a new runner ... Verify authentication for a registered runner ... API_Entities_Ci_RunnerRegistrationDetails reason: Runners are the build executors of the CI system; registering and verifying them manages the build-pipeline execution fleet. Some of the surface is credential handling, hence moderate confidence. - tag: deploy_resources spec_file: gitlab-ci-deploy-resources-api-openapi.yml capability_id: BC-4210 capability_id_l1: BC-4210 capability_name: Software Release & Deployment Management confidence: 0.7 evidence: '"Create a project deploy token", "Add deploy key", schemas API_Entities_Deployment, API_Entities_Deployments_Approval' reason: Surface combines deploy credentials (keys/tokens), deployment records and deployment approvals — clearly within software release & deployment management, but split across secrets management, deployment orchestration and change authorisation, so no single L2 is named. - tag: error_tracking spec_file: gitlab-ci-error-tracking-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: '"Get Error Tracking settings", "Enable or disable the Error Tracking project settings", schema API_Entities_ErrorTracking_ClientKey' reason: Error tracking client keys and project settings configure runtime error/exception capture from the running application — observability of production behaviour. - tag: members spec_file: gitlab-ci-members-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: paths "/api/v4/groups/{id}/members/{user_id}" with PUT/DELETE, "/members/{member_id}/approve", "/members/approve_all", schemas "API_Entities_Member", "API_Entities_MemberRole" reason: CRUD over group/project memberships, member roles, overrides and pending-member approval is user access provisioning and role assignment within the platform — Identity & Access Management. Not HR membership despite the noun. - tag: protected_branches spec_file: gitlab-ci-protected-branches-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.7 evidence: GET/POST /api/v4/projects/{id}/protected_branches, schemas API_Entities_ProtectedBranch, API_Entities_ProtectedRefAccess reason: Configures who may push, merge and force-push to branches — source-control and code-review discipline, which is the stated scope of Software Construction Management. Some chance it is better read as change authorisation. - tag: suggestions spec_file: gitlab-ci-suggestions-api-openapi.yml capability_id: BC-4200.40 capability_id_l1: BC-4200 capability_name: Software Construction Management confidence: 0.7 evidence: PUT /api/v4/suggestions/{id}/apply, API_Entities_Suggestion, PUT /api/v4/suggestions/batch_apply reason: Applies reviewer code suggestions from merge request reviews to the codebase — code review discipline under software construction management. - tag: wikis spec_file: gitlab-ci-wikis-api-openapi.yml capability_id: BC-830.30 capability_id_l1: BC-830 capability_name: Knowledge Sharing & Collaboration Management confidence: 0.7 evidence: GET/POST /api/v4/projects/{id}/wikis, "Upload an attachment to the wiki repository", schema API_Entities_WikiPage reason: Operations are full CRUD over wiki pages at group and project level plus attachment upload — a collaborative documentation/knowledge-sharing surface, not CI/CD despite the vendor framing. Mapped to knowledge sharing and collaboration; some ambiguity versus knowledge capture/curation, hence moderate confidence.