Secure Support Pod

A technical interest Support Pod focused on GitLab Secure stage features.

Secure Pod is a technical interest Support Pod focused on GitLab Secure stage features.

Secure Pod members

Purpose, key results and exit criteria (if any)

Secure Pod is a way for Support Engineers interested in Secure stage features to work on relevant tickets and projects together.

The goals of Secure pod are to:

  • identify underlying patterns and trends across Secure tickets
  • file targeted issues and detailed bug reports to improve our Secure features
  • submit MRs to GitLab documentation for self-service support and ticket deflection
  • assist customers and team members with problems and questions involving Secure stage features

FAQ

How can I get involved in Secure Pod?

  1. Talk with your manager.
  2. Submit a merge request to add 'Support Focus: Secure' to your ZenDesk Groups in the Support Team data.
  3. Let your teammates and groupmates know about your new focus area.
  4. Join #spt_pod_secure Slack channel.
  5. Attend Secure Pod pairing sessions. (Check GitLab Support calendar for meeting times)

How the Secure Pod works

  • In the #spt_pod_secure Slack channel, we pin Slack messages about 🎫 tickets that we are keeping an eye on for colleagues, typically when they are out of the office.
    • During 🍐 pairing sessions, check the pinned messages to see if the tickets there require attention.
    • If you pin a ticket, please remove it when it no longer requires attention from the pod.
  • We apply the scoped pod::secure label to the pairing issues that we create.

Support Pod Resources

  • Weekly session: “Secure Pod Pairing” on the GitLab Support Team Calendar, currently scheduled Thursdays at 3:00 PM UTC.
  • Slack channel: #spt_pod_secure
  • Slack alias: @securepod GitLab.com label: ~“devops::secure”

Secure Pod Troubleshooting Resources

Secure Stage

SAST (Static Application Security Testing)

Secret Detection

Dependency Scanning

DAST (Dynamic Application Security Testing)

IaC (Infrastructure as Code) Scanning

Security Dashboard / Vulnerability Report

Security Scan Policies

Code Quality

Technically owned by Secret Detection, but not related to security vulnerabilities.

Container Scanning

License Scanning

Fuzz testing

Learning Resources