> ## Documentation Index
> Fetch the complete documentation index at: https://docs.testdino.com/llms.txt
> Use this file to discover all available pages before exploring further.

# GitLab Self-Managed Integration

> Connect TestDino to a self-managed GitLab instance for merge request comments and MR sync, including the security details.

The GitLab Self-Managed integration connects TestDino to a GitLab instance hosted on internal infrastructure: on-prem, inside a private VPC, or on a corporate domain such as `https://gitlab.mycompany.com`.

After connection, TestDino posts AI test summaries on merge requests in the connected GitLab repository, and keeps MR state in sync with TestDino for Pull Request.

## What the Self-Managed Integration Does

* **Secure OAuth Login**: connects TestDino to the GitLab instance securely, no personal access tokens or shared service accounts.
* **MR Comments**: posts AI test summaries with test status metrics, failure summaries, and a link to the full report.
* **Automatic Token Refresh**: refreshes OAuth tokens in the background so the session stays alive.

## Prerequisites

* **GitLab instance URL**: reachable over HTTPS from TestDino's servers with a valid TLS certificate, for example `https://gitlab.mycompany.com`.
* **Permission to create an Gitlab OAuth Application**: a user-level app on the GitLab account, or a group or instance-level app registered by a GitLab admin.
* **Admin role in TestDino**: only TestDino project admins can connect or disconnect integrations.

<Warning>
  **Warning**

  TestDino connects to your GitLab over the public internet. If your GitLab sits behind a VPN or inside a private network, work with your infra team to expose it or allowlist TestDino's outbound IP range. **Self-signed TLS certificates are not supported today.** Use a public or internal-CA-signed certificate.
</Warning>

## Connect TestDino with Self-Managed GitLab

Connection takes the following steps:

* Register an OAuth Application on the GitLab instance
* Provide GitLab Instance URL and OAuth Credentials to TestDino
* Authorize TestDino via GitLab
* Select the GitLab project to connect with TestDino

### Create a GitLab OAuth Application

In the self-managed GitLab, create a new OAuth application that TestDino uses to sign users in.

1. Go to **User Settings → Applications**, or **Admin Area → Applications** for an instance-wide app.

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-self-oauth-app-create-new.webp" alt="GitLab User Settings Applications page with the Add new application button" />

2. Click **Add new application** and fill in the fields below:

| Field | Value |
| :- | :- |
| Name | `TestDino` |
| Redirect URI | `https://integration.testdino.com/api/v1/integrations/gitlab/oauth/callback` |
| Confidential | Checked |
| Scopes | `api` |

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-self-oauth-creating.webp" alt="GitLab Add new application form with Name, Redirect URI, Confidential checkbox, and Scopes filled in" />

3. Click **Save application**. GitLab shows 2 values: **Application ID** and **Secret**. Keep this page open for the next step.

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-self-oauth-secrets-copy.webp" alt="GitLab OAuth application page highlighting the generated Application ID and Secret to copy" />

<Warning>
  **Warning**

  The Secret is shown only once. If you leave the page without copying it, you must regenerate it from the application page in GitLab.
</Warning>

### Enter GitLab URL and OAuth Credentials

1. In TestDino, open the project, go to **Project Settings → Integrations**, and open the **GitLab** tile.
2. Click **Connect GitLab** and choose **Self-hosted** from the dropdown (the option with the server icon).

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-self-testdino-card-dropdown.webp" alt="TestDino GitLab card showing the Connect to GitLab button with dropdown expanded to show Cloud and Self-Managed options" />

3. A dialog titled **Connect GitLab Self-Hosted** opens. Fill in the 3 values and click **Connect**:

| Field | What to enter |
| :- | :- |
| Instance URL | Base URL of the GitLab instance, for example `https://gitlab.mycompany.com`. No trailing slash, no `/api/v4`. |
| Application ID | The Application ID from Step 1. |
| Application Secret | The Secret from Step 1. |

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-self-testdino-enter-details.webp" alt="Connect GitLab Self-Managed dialog with Instance URL, Application ID, and Application Secret fields filled in" />

TestDino validates the URL and credentials, then redirects you to the GitLab login and authorization page.

### Authorize TestDino in your GitLab

1. Sign in to GitLab if you are not already signed in.

2. GitLab shows an **Authorize TestDino** consent screen listing the requested scopes.

3. Click **Authorize**. You are redirected back to TestDino, and the GitLab card now shows **Connected** instance URL.

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-self-testdino-connected.webp" alt="TestDino GitLab card in connected state showing username and self-managed instance URL" />

### Select the GitLab project to link

1. On the same GitLab card, a **Select GitLab Project** picker appears.
2. Start typing the project name or group. The list loads from your GitLab instance, not from `gitlab.com`.
3. Pick the project this TestDino project should mirror.

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-self-testdino-select-projects.webp" alt="Self-managed GitLab project picker showing projects from the connected instance" />

<Note>
  **Note**

  The picker lists only projects where the connecting user (the GitLab account that authorized TestDino via OAuth) has **Developer** access or above for projects. Lower-access projects for this user are hidden.
</Note>

***

After a successful connection, the integration unlocks MR comments and comment behavior overrides. Configure each below.

## Configure MR Comments

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-pr-comment.webp" alt="GitLab merge request comment showing AI-generated test summary with pass/fail counts and failure analysis" />

When a Playwright run finishes, TestDino posts an AI-generated summary to the merge request inside your self-managed GitLab. Open **Project Settings → Integrations → GitLab → Comment Settings** to control behavior.

### Default comment toggle

A toggle controls the global default:

* **Merge Request Comments**: posts a summary to every MR on a mapped branch

This default applies to all environments unless overridden below.

### Per-environment overrides

The **Environment Overrides** table lists each environment configured in your project (e.g., PROD, DEV, MAIN, QA, STAGE). Each row shows:

| Column | What It Controls |
| :- | :- |
| Environment | The environment name, configured in [Environment Mapping](/guides/environment-mapping) |
| Branch Patterns | Which branches map to this environment (e.g., `main`, `dev`, `staging`) |
| MR | Toggle MR comments on or off for this environment |

Environment-level toggles override the global defaults. For example, you can enable MR comments globally but disable them on the DEV environment. Settings apply immediately with no redeploy and no reconnect.

<img src="https://tdstorageus.blob.core.windows.net/public/docs/integrations/ci-cd/playwright-gitlab-self-hosted/integration-gitlab-settings.webp" alt="GitLab Settings panel showing the MR comment toggle with environment overrides table" />

<Tip>
  **Tip**

  Environment overrides are optional. If the global toggle is on and no overrides are configured, TestDino posts comments on every MR. Use overrides when you want different behavior per environment: for example, post MR summaries on PROD branches, but not on feature branches.
</Tip>

## Security

| Protection | Detail |
| :- | :- |
| Encrypted secret storage | Your OAuth Application Secret is encrypted at rest with AES-256-GCM before storage |
| Short-lived access tokens | Tokens are refreshed automatically. You never share a long-lived personal token with TestDino |
| Clean disconnect | Disconnecting from TestDino wipes the stored OAuth tokens and application credentials |

<Note>
  **Note**

  TestDino stores only the metadata it needs to post comments (project ID, MR IDs, commit SHAs) plus encrypted OAuth tokens. It does not mirror your source code or CI artefacts.
</Note>

## Manage the Connection

### View connection status

**Project Settings → Integrations → GitLab** displays the current connection state, the linked GitLab username, the instance URL, the selected GitLab project, and any recent comment errors.

### Disconnect

Open the GitLab tile and click **Disconnect**. TestDino performs 2 actions:

1. Deletes the stored OAuth tokens and application credentials.
2. Stops posting comments.

You can reconnect any time, to the same or a different instance.

## Troubleshooting

<AccordionGroup>
  <Accordion title="Unable to reach GitLab instance" icon="plug-circle-xmark">
    TestDino cannot resolve or connect to your instance URL.

    * Confirm the URL is correct, uses HTTPS, and is publicly reachable
    * Check with your infra team whether TestDino's outbound traffic needs allowlisting
    * Confirm the TLS certificate is valid and signed by a public or internal CA
  </Accordion>

  <Accordion title="Invalid application credentials" icon="key">
    The Application ID or Secret is wrong, or the app was deleted on your GitLab.

    * Re-create the OAuth Application in GitLab (Step 1) and enter the new ID and Secret in TestDino
    * Make sure **Confidential** was checked when creating the app
  </Accordion>

  <Accordion title="Redirected to GitLab but got a 404 or redirect error" icon="arrow-rotate-left">
    The Redirect URI on the GitLab OAuth app does not match TestDino's callback.

    * In your GitLab Application, set the Redirect URI to exactly `https://integration.testdino.com/api/v1/integrations/gitlab/oauth/callback`
    * No trailing slash, no extra path segments
  </Accordion>

  <Accordion title="Connected, but comments never appear on MRs" icon="comment-slash">
    The MR source branch does not match the branch test runs are reporting on, or comments are disabled.

    * Confirm test runs send the correct branch name in metadata
    * Verify the global comment toggle is enabled in **Project Settings → Integrations → GitLab → Comment Settings**
    * Check the connecting user still has **Developer** access or above on the GitLab project
  </Accordion>

  <Accordion title="Comments stopped appearing after working fine" icon="rotate-right">
    The OAuth app secret was rotated on GitLab, or the connecting user lost repo access.

    * Reconnect via the TestDino UI using the current Application ID and Secret
  </Accordion>

  <Accordion title="Self-signed TLS certificate on your GitLab" icon="shield-halved">
    Self-signed certificates are **not supported today**.

    * Use a valid public or internal-CA-signed certificate
    * Contact TestDino support about your environment if you need a different arrangement
  </Accordion>
</AccordionGroup>

## FAQ

<AccordionGroup>
  <Accordion title="Do all my team members need to do this?" icon="users">
    No. One TestDino admin connects once per TestDino project. Every team member then benefits from comments automatically.
  </Accordion>

  <Accordion title="Does the OAuth Application need to be instance-wide?" icon="building">
    No. A user-owned application works. An instance-wide application is useful only if many TestDino projects across your org connect to the same GitLab and you want centralized management.
  </Accordion>

  <Accordion title="Can one TestDino workspace connect to both Cloud and Self-Managed?" icon="network-wired">
    Yes. Each TestDino project chooses its own GitLab connection independently.
  </Accordion>

  <Accordion title="How do I revoke TestDino's access entirely?" icon="ban">
    From TestDino, click **Disconnect**. From GitLab, go to **User Settings → Applications → Authorized applications** and revoke TestDino there as well.
  </Accordion>
</AccordionGroup>

<CardGroup cols={2}>
  <Card title="GitLab Cloud Integration" icon="gitlab" href="/integrations/playwright-gitlab-ci">
    Connect TestDino to gitlab.com via OAuth for MR comments and sync
  </Card>

  <Card title="Environment Mapping" icon="map" href="/guides/environment-mapping">
    Map branches to environments for targeted comment routing
  </Card>

  <Card title="Pull Requests Dashboard" icon="code-pull-request" href="/platform/pull-requests/summary">
    View all MRs with test run results, trends, and AI insights
  </Card>

  <Card title="Node.js CLI" icon="terminal" href="/cli/testdino-playwright-nodejs">
    Install and configure the TestDino CLI
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.