Prev Next

DevOps / Gitlab Interview questions

How do you configure branch protection rules to enforce a merge-request-only workflow?

To make sure no one can bypass code review by pushing straight to a release branch, protection has to be configured at the branch level, not just relied on as a team convention.

  1. Go to Settings > Repository > Protected branches.
  2. Select the branch (e.g. main) or a wildcard pattern (e.g. release/*).
  3. Set Allowed to push and merge to No one, so direct pushes are impossible for everyone, including Maintainers.
  4. Set Allowed to merge to the roles or specific users permitted to accept merge requests.
  5. Optionally enable Code Owner approval required so ownership rules from the CODEOWNERS file are enforced.
  6. Combine with a merge request approval rule requiring a minimum approval count and a passing pipeline before the merge button unlocks.

With these set, the only way changes reach the protected branch is through a reviewed, approved, pipeline-passing merge request; the CLI simply rejects a direct git push origin main from anyone, regardless of their general repository permissions.

Setting "Allowed to push and merge" to "No one" achieves:
Enforcing Code Owner approval requires:

More Related questions...

What is GitLab? What is Git? What is the difference between Git and GitLab? What is the difference between GitLab and GitHub? What are the main features of GitLab? What is a GitLab repository? What is a GitLab merge request? What are GitLab CI/CD pipelines? What is a.gitlab-ci.yml file? What is a GitLab Runner? What are stages and jobs in a GitLab pipeline? What is a GitLab Issue Board? What are GitLab Epics? What is the difference between a GitLab group and a GitLab project? What is GitLab Container Registry? What is GitLab Pages? What are protected branches in GitLab? What is GitLab Auto DevOps? What is forking in GitLab? What are labels in GitLab? What is the GitLab Wiki? What are the different GitLab subscription tiers? What is GitLab Flow? What is a GitLab milestone? What is a GitLab Snippet? Explain the execution flow of a GitLab CI/CD pipeline from commit to deployment? Why would a DevOps team choose GitLab over GitHub for a single-platform workflow? How does a GitLab merge request differ from a GitHub pull request? What is the difference between GitLab.com (SaaS) and GitLab self-managed? How do you write a multi-stage.gitlab-ci.yml pipeline? When should you use CI/CD variables versus environment-scoped variables in GitLab? How do you troubleshoot a GitLab Runner stuck in "pending"? What is the difference between shell, Docker, and Kubernetes GitLab Runner executors? How does GitLab enforce merge request approvals with Code Owners? Explain the internal working of GitLab merge trains? What is the difference between GitLab CI/CD and Jenkins? How do you implement GitOps with GitLab and Kubernetes agent? Why use GitLab Auto DevOps instead of hand-writing pipelines? What is the difference between "include" and "extends" in GitLab CI/CD YAML? How does GitLab cache artifacts between pipeline jobs? When would you choose GitLab Ultimate over GitLab Premium? How do you configure branch protection rules to enforce a merge-request-only workflow? What is the difference between GitLab CI/CD "rules" and the deprecated "only/except" keywords? Explain the lifecycle of a GitLab issue from creation to closure? How do you optimize GitLab CI/CD pipeline performance for a large monorepo? What is the difference between GitLab Container Registry and Docker Hub? How does GitLab's Auto DevOps decide which CI/CD template to apply to a project? Why should you use GitLab environments to track deployments? What is the difference between a group-level and project-level CI/CD variable in GitLab? How do you troubleshoot merge conflicts flagged in a GitLab merge request?
Show more question and Answers...


Comments & Discussions