Retention defaults can reduce exposure while making historical evidence harder to recover.
Security teams may favor shorter windows as operators and investigators depend on trace history during incidents.
Who you’d be doing this for
“I don’t want job traces sitting around forever, but I can’t lose the evidence we need on a bad day.”
Worku Tadesse · Security Engineering Manager
Sets evidence-retention expectations for a regulated organization running self-managed delivery infrastructure.
What is at stake
Job traces in regulated instances are kept longer than customers expect, and storage costs climb. You have to weigh tighter defaults against investigations that still need those logs, since this is hard to unwind.
Why it isn’t already fixed
Every obvious fix costs something else. That’s the part you’d have to decide.
- data minimization vs. incident evidence
- uniform defaults vs. customer obligations
- automated classification vs. verified eligibility
- security urgency vs. migration trust
Why Gitlab
For integrated delivery data, retention choices often sit at the boundary between operational evidence and risk reduction.
Written with these in mind
Not your kind of problem? 2 more at Gitlab, or browse every organization.
This is the setup. The work is inside.
Running it puts you in the room: the full situation and its constraints, stakeholders who push back in their own words, and the decisions that are yours to make. What you produce becomes a Day One Plan — work you can show someone instead of describing.