Getting started with GitLab

If your code is on GitLab, go to the SonarCloud product page and choose Set up or Login, then select GitLab from the list of DevOps cloud platforms.

Sign in to SonarCloud using your GitLab account.

You will be taken to the GitLab login page. Sign in using your GitLab credentials.

Welcome to SonarCloud

Once you have successfully logged in, you will see the SonarCloud welcome screen. Select Analyze your first projects > Import an organization from GitLab.

Your welcome screen when signing in for the first time.

Set up your organization

Connect your GitLab group with SonarCloud

First, select either

  • Import any GitLab group, if you want to import a GitLab group other than your personal one, or
  • Import my personal GitLab group, if you want to import just your personal group.

If you select the first one you will need your GitLab group key and a personal access token.

If you select the second one you will just need a personal access token.

Group key

For the group key, you can provide either the ID of the group or the key of the group. The group ID can be found under the group name on the group page. The group key is the last element in the path of the group and is found in the URL. For example, gitlab.com/my-group.

Note that the user that is logged into SonarCloud must be an owner of the GitLab group.

Personal access token

To create the token, go to User settings > Personal Access Tokens in GitLab, or while logged in to GitHub, click the Personal Access Token hyperlink in the SonarCloud Create an organization tutorial.

Select API when generating a personal sa

When creating your access token on the GitLab User settings > Personal Access Tokens page, make sure to select api scope. Then click Create personal access token.

When the personal access token is displayed at the top of the page, copy the token and paste it into the field on the SonarCloud setup page.

Create your SonarCloud Organization

SonarCloud is set up to mirror the way that code is organized in GitLab (and other repository providers):

  • Each SonarCloud project corresponds one-to-one with a GitLab project, which resides in its own Git repository.
  • GitLab projects are grouped into GitLab groups.
  • Each SonarCloud organization corresponds one-to-one with a GitLab group.

In this step, you will create a SonarCloud organization that corresponds to your GitLab group.

SonarCloud will suggest a key for your SonarCloud organization. This is a name unique across all organizations within SonarCloud. You can accept the suggestion or change it manually. The interface will prevent you from changing it to an already existing key.

Choose a plan

Next, you will be asked to choose a SonarCloud subscription plan. If all the repositories to be analyzed are public on GitLab, you can select the free plan. When using the free plan, your code and analysis results will be publicly accessible at sonarcloud.io/explore/projects.

If you want to analyze one or more private repositories then you need to select a paid plan. All paid plans offer a 14-day free trial period. Once the 14 days have elapsed, the cost is based on the number of lines of code analyzed.

Once you have chosen a plan and clicked Create Organization, your SonarCloud organization will be created!

Set up your analysis

Import repositories

The next step is to import the projects (that is, individual Git repositories) that you want to analyze from your GitLab group into your newly created SonarCloud organization, creating a corresponding SonarCloud project for each.

SonarCloud will present a list of the repositories in your GitLab group. Select those that you want to import and analyze and click Set Up.

Select the GitLab repositories that you want to analyze with SonarCloud.

The selected projects will be imported.

Configure analysis

With GitLab projects, the actual analysis is performed in your build environment (cloud CI, local machine, etc.). This means you have to configure your build process to perform the analysis on each build and communicate the results up to SonarCloud.

SonarCloud will guide you through a tutorial on how to set up your build environment to perform analysis.

The first step is to select your build environment. SonarCloud will present this page:

Choose your preferred CI tool as the analysis method.

If you have no particular preference and are setting up a new project on GitLab, we recommend using GitLab CI/CD as your CI.

Follow the tutorial to set up your analysis.

See your analysis results

Once it is complete, you can view the results of your first analysis

In addition, please see the page on GitLab CI to integrate SonarCloud into your GitLab pipelines. 

© 2008-2022, SonarCloud by SonarSource SA. All rights reserved.