Architecture and migration
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.

WZ-IT plans, installs and operates GitLab as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.
The following are trademarks of their respective owners: GitLab (GitLab Inc.). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

GitLab combines source-code management, issues, CI/CD and further DevOps capabilities in one platform. Security, planning, governance and compliance features differ substantially between Free, Premium and Ultimate.
As an independent service provider, we support you in installing, configuring, and optimizing this powerful DevOps platform. We help you optimally integrate GitLab into your existing development processes and leverage the benefits of a unified platform for your company.
We install, host and operate GitLab for your company - either on our secure, privacy-focused infrastructure in Germany or other locations, as well as on-premise in your own environment.
We provide 24/7 monitoring, backups and maintenance for your GitLab instance. Human response times and support coverage follow the selected service level. Note: we host the GitLab Community Edition (MIT license) freely. GitLab Premium and Ultimate features (e.g. advanced security scans like DAST/container scanning, epics, roadmaps, compliance frameworks, audit logs) require a per-user subscription from GitLab Inc. - we support selection and coordination of the appropriate licence; the licence agreement is concluded with the respective vendor.
Comprehensive source code management with branches, merge requests, code reviews, and detailed permissions for teams of any size.
Automated build, test, and deployment processes with configurable pipelines, parallel jobs, and extensive runners.
Coverage of the entire DevOps lifecycle from planning through development, verification, and deployment to monitoring and feedback.
Security analysis can be integrated into CI/CD. Availability and scope of SAST, DAST, dependency, container and licence scanning depend on the GitLab plan.
Issue tracking, milestones and boards are integrated; epics, roadmaps and advanced planning depend on the selected GitLab plan.
Integrated container registry for Docker images and native Kubernetes integration for modern, container-based applications.
Audit events, compliance reports, access controls and approval workflows are plan-dependent and verified for the required scope.
Enhanced collaboration through wiki, snippets, design management, web IDE, and detailed code reviews with merge requests.
Seamless integration with numerous third-party tools via API, webhooks, and pre-built connectors for a flexible DevOps toolchain.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
Advanced architecture after technical and licence assessment
Centralized repository management with code reviews, merge requests and branch protection
Complete CI/CD pipelines for automated builds, tests and deployments
SAST, DAST, container scanning, dependency scanning and compliance management
Comprehensive metrics and insights for your DevOps processes and team performance
Private Docker registry with vulnerability scanning and lifecycle management
Integrated issue tracking, boards, milestones and project planning
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Directly or through an upstream identity layer
Depends on application, edition and identity provider
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
GitLab is more than a Git repository - it's a complete DevSecOps platform. The powerful GraphQL API and event system make it an ideal candidate for deep integrations.
GitLab offers a powerful GraphQL API that enables precise data queries without over-fetching. Particularly performant for custom dashboards that display the status of hundreds of pipelines, issues, or merge requests in aggregate.
GitLab fires events for almost everything: push, merge request, pipeline failure, issue update. We develop middleware that receives these hooks and controls your processes - automatic ticket creation in Jira, deployment triggering, or compliance notifications.
The strength lies in CI/CD. Instead of UI plugins, we develop custom executor scripts or containers for GitLab Runners. Compliance checks, security scans (SAST, DAST), license audits, or deployment logic are integrated directly into your build pipelines.
How we implement GitLab development in practice.
Standard CI/CD templates don't cover your specific requirements: custom compliance checks, internal security tools, or proprietary deployment targets.
We develop custom CI/CD components and container images for your GitLab Runners. These execute your specific checks (SBOM generation, license compliance, custom SAST) and integrate seamlessly into existing pipelines.
Developers work in GitLab Issues, but project management uses Jira/Asana/Linear. Double data maintenance and sync problems are the result.
Bidirectional synchronization via webhooks and APIs. Status updates, comments, and attachments are automatically mirrored. Merge request links appear in the external tool, issue IDs are referenced in commits.
For audits, information from various GitLab projects must be manually compiled: Who merged what when? Which pipelines failed?
A custom dashboard aggregates data via GraphQL API: merge request approvals, pipeline success rates, deployment history. Export functions for PDF reports and automatic alerts for policy violations included.
We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.
SSO, secure access, internal systems and existing security components are integrated appropriately.
Updates, backups, technical monitoring and response paths follow a transparent operational scope.
APIs, automation and custom extensions can be delivered beyond basic deployment.
The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.
Development and automation platforms need controlled execution, secrets, persistent data and clearly bounded connections to source and target systems.
Teams, repositories, webhooks, schedules and business systems initiate defined processes.
TLS, firewall rules, reverse proxies or private network paths are designed around the platform's exposure.
Local accounts, SSO, directories, service accounts and emergency access are connected through clear roles.
Editor, API, build or workflow runtimes are deployed reproducibly and isolated appropriately.
Metadata, configuration, source state, packages or execution history.
Queues, runners, containers, resource limits and separated execution environments.
Service accounts, secrets and controlled network paths to internal and external systems.
The diagram is a resilient target model. Its implementation depends on edition, data flows, load, availability objectives and existing infrastructure.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.
We also design custom GitLab architectures, integrations and migrations. Contact us for a technical assessment.
One managed standard GitLab application is included in the Starter workload. Every service level also includes flexible expert time for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Briefly describe the current state and objective for GitLab. We assess infrastructure, integration, and ongoing operations.
Whether you run GitLab in-house or need to host confidentiality-professional data §203-ready - we build, operate and maintain GitLab on an encrypted on-site server. Data never leaves the building in cleartext.
See GitLab on-premise
These solutions are often used together with GitLab
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
