Security1 distinct publisher3 min readUpdated
Dedicated customers can now run Duo agents in their own single tenant and region with their own inference models, while Secrets Manager arrives in limited availability as a paid add-on.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
GitLab has told Dedicated customers they can now run the Duo Agent Platform inside the same single-tenant environment and region that already carries their most sensitive delivery workloads, connect their own models for inference, and keep AI-processed data inside their existing security boundary [1]. The announcement, reported by Help Net Security on August 21, 2026, matters less for what the agents write than for where they run and what they can reach [15].
The mechanism is the AI Gateway for the Duo Agent Platform, which now runs inside GitLab Dedicated's single-tenant SaaS infrastructure so that agentic workloads follow the same residency and isolation model as the rest of the software development lifecycle in GitLab [4]. Manav Khurana, GitLab's chief product and marketing officer, framed the release as extending existing control rather than adding capability: "Every capability we shipped this month, from where an agent runs to which secret it can touch, extends that same control into the trusted software delivery workflows enterprises already depend on" [5]. That framing is the useful part. An auditor who has already signed off on a Dedicated tenant has a shorter conversation about an agent in that tenant than about an agent calling out to a shared gateway.
GitLab 19.3 also ships Secrets Manager, the Flow Creator Agent, and bulk SAST false positive detection with agentic SAST vulnerability resolution [2]. On secrets, GitLab says every secret now runs under the same permission model whether it is used inside a pipeline or by infrastructure outside it [3]. Each CI secret is scoped to the environment, branch, and protection status of the job that needs it [7], and the manager supports Kubernetes, Terraform, OpenTofu, and custom tools [8]. Secrets Manager is in limited availability as a paid add-on billed through GitLab Credits for GitLab.com customers, and the announcement puts no other price on it [6].
The backlog work is more conventional. Teams select multiple findings in the Vulnerability Report, GitLab returns a confidence score for each, and confirmed risks come back as a ready-to-merge fix for a developer to review rather than write [9]. GitLab says this covers every SAST vulnerability in the report and that it continues to triage and remediate new critical and high severity findings automatically [10]. Confidence scores are the pressure point: a bulk action is only as good as the review board's willingness to accept a machine's triage on findings it never looked at.
Flow Creator Agent removes the manual schema mapping step, letting a user describe an automation in plain language through Agentic Chat and get back a runnable flow ready to register from the AI Catalog [11]. The control that matters here is downstream of the convenience: every flow runs under a scoped service account with composite identity, and enabling one requires the Maintainer role or higher [12]. Alongside that, GitLab Credits usage caps are now generally available, with a subscription-level ceiling set in the Customers Portal plus default or per-user caps through the GraphQL API [13], and restricted visibility for custom agents and flows per group is generally available in addition to per-project and public options [14].
Two of the pieces here are generally available and the secrets layer is not [16]. Watch whether Secrets Manager exits limited availability with pricing that survives procurement, whether the composite-identity and Maintainer gate on flows holds up when process owners start generating them at volume, and whether the confidence scores behind bulk remediation are exportable as evidence. Competitors selling AI coding features into regulated buyers will now be asked where the inference runs and which secret the agent can touch.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
GitLab Dedicated customers can now run GitLab Duo Agent Platform inside that same single tenant environment and region, connect their own models for inference, and keep AI-processed data inside their existing security boundary.
The AI Gateway for GitLab Duo Agent Platform now runs inside GitLab Dedicated single-tenant SaaS infrastructure, enabling agentic workloads to follow the same residency and isolation model as the rest of the software development lifecycle within GitLab.
GitLab 19.3 ships with support for Secrets Manager, Flow Creator Agent, and Bulk SAST False Positive Detection and Agentic SAST Vulnerability Resolution.
Manav Khurana, chief product and marketing officer at GitLab, said: "Every capability we shipped this month, from where an agent runs to which secret it can touch, extends that same control into the trusted software delivery workflows enterprises already depend on."
GitLab Secrets Manager is in limited availability as a paid add-on billed through GitLab Credits for GitLab.com customers.
Every CI secret is scoped to the environment, branch, and protection status of the job that needs it.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-sourced article, no independent verification
All substantive detail comes from one publisher reproducing GitLab's announcement, including a company executive quote. Availability tiers, scoping rules, and billing mechanics are specific and internally consistent, which supports the descriptive facts, but there is no second publisher, no documentation link, no benchmark, and no third-party test of the fix-generation or flow-generation claims.
Shipping and availability signals only, no usage evidence
Adoption evidence stops at product availability: 19.3 shipped, Credits usage caps and per-group visibility are GA, the Dedicated AI Gateway is described as running in single-tenant infrastructure with no stated tier, and Secrets Manager is gated in limited availability behind a paid add-on. No customer names, deployment counts, credit consumption figures, or usage disclosures appear anywhere in the source, so real-world uptake cannot be scored higher than the shipping signal itself.
Control-and-scale framing outruns the evidence
Framing such as scaling agentic development securely, clearing years of accumulated risk in a single action, and control extending from where an agent runs to which secret it can touch is broader than what the source substantiates. The most load-bearing capability is limited availability, remediation and flow-generation quality is asserted without measurement, and no customer or usage evidence exists. The gap is overstatement of maturity rather than fabrication, since availability tiers and governance mechanics are disclosed plainly.
Vendor announcement with direct monetization stake
The narrative originates with GitLab and is voiced by its chief product and marketing officer, and the coverage largely mirrors the announcement's own section structure. GitLab has a direct revenue interest: Secrets Manager is a paid add-on billed through GitLab Credits, and Credits usage caps are positioned as spend governance for consumption-based agentic AI. No adversarial or independent voice appears in the cluster.
Announcement facts reliable, capability outcomes uncertain
Confidence is moderate: what GitLab announced, and at which availability tier, is stated clearly enough to record with little doubt. Confidence in what the capabilities actually deliver in production is low because the cluster has one publisher, one vendor voice, no measurements, and no deployment evidence.
build
GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim1 distinct publisher
product
Pulumi turns its Terraform-compatibility claim into a diff against tofu1 distinct publisher
build
Edge Kubernetes did not break on clusters. It broke on the assumptions under them.1 distinct publisher
product
The 19% Gap: Why Developer Velocity Self-Reports Cannot Justify an AI Rollout1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026