Compare GitLab Orbit Remote and Local

  • Tier: Free, Premium, Ultimate
  • Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
  • Status: Beta

The availability of this feature is controlled by a feature flag. For more information, see the history. This feature is available for testing, but not ready for production use.

GitLab Orbit creates a read-only property graph you can query. GitLab Orbit Remote connects to your GitLab instance and GitLab Orbit Local can access your local code and projects.

Together, you can use both tools to understand the relationships between your code and other data in your GitLab instance.

The following sections compare GitLab Orbit Remote and Local so you can learn how they work and determine which one is right for you.

GitLab Orbit Remote

GitLab Orbit Remote runs on GitLab infrastructure. It builds a graph of merged source code together with your software development lifecycle (SDLC) data, including groups, projects, users, merge requests, pipelines, work items, and security findings.

Use GitLab Orbit Remote when you need more context about the code you’re working on.

Developers can use GitLab Orbit Remote for the following tasks:

  • Assess a blast radius across projects.
  • Check code review history.
  • Trace a vulnerability back to the change that introduced it.

For product and engineering managers, security teams, and support, use GitLab Orbit Remote with GitLab Duo Agent Platform.

You can ask a question in plain language in the GitLab UI, and the agent queries the graph and answers. Results are scoped to what your role already permits, so you see the same data you would see elsewhere in GitLab.

GitLab Orbit Local

GitLab Orbit Local runs on your machine and builds a code-only graph from a repository you have checked out. It indexes the branch you are on, which gives AI coding agents real structure to work so they can answer questions about your code.

Use GitLab Orbit Local when:

  • The network is unavailable. You still need a network connection to manage the orbit binary, the GitLab Orbit skill, and telemetry.
  • The code must not leave your machine.

Developers use GitLab Orbit Local for the following tasks:

  • Get oriented with an unfamiliar repository.
  • Find every caller of a function before a rename.
  • Map what a change touches.

GitLab Orbit on GitLab Self-Managed

GitLab Orbit on GitLab Self-Managed is GitLab Orbit Remote that you run yourself. GitLab Orbit is available only as a Helm chart. You install GitLab Orbit on a Kubernetes cluster, together with Siphon, the data pipeline that copies your GitLab database into ClickHouse.

Where you install GitLab Orbit depends on how you installed GitLab:

  • Linux package: Create a separate Kubernetes cluster for GitLab Orbit, and connect it to the server that runs GitLab. The cluster and your instance must be able to reach each other.
  • GitLab Helm chart: Install GitLab Orbit in the same cluster that runs GitLab.

For more information, see GitLab Orbit on GitLab Self-Managed.

Deployment and network

After you install the GitLab Orbit binary, index and query commands are entirely local, and no request leaves your computer to build or read the graph.

On GitLab.com, GitLab Orbit Remote runs in a separate Kubernetes cluster from your GitLab instance. This deployment approach ensures memory usage and compute remain separate.

DeploymentGitLab Orbit LocalGitLab Orbit Remote
Runs on your machinecheck-smNo
Runs on GitLab infrastructureNocheck-sm
Graph storageDuckDB file at ~/.orbit/graph.duckdbManaged ClickHouse
Storage you set upNoNo
Network connection required to queryNocheck-sm
GitLab instance requiredNocheck-sm

Authentication and authorization

Access controlGitLab Orbit LocalGitLab Orbit Remote
GitLab account requiredNocheck-sm
Token or sign-in requiredNocheck-sm
Results scoped to your roleNocheck-sm
Minimum role to queryNoneReporter
Minimum role for security dataNoneSecurity Manager
Minimum role to turn on indexingNoneOwner on the top-level group

GitLab Orbit Local has no authorization layer, and does not require authentication. GitLab Orbit Remote delegates every access decision to GitLab.

Programmatic access to GitLab Orbit Remote uses your existing GitLab authentication.

For more information, see GitLab Orbit Remote security.

Indexed data

GitLab Orbit Local and Remote index different types of data. The following sections list what each feature indexes.

GitLab Orbit Remote and Local do not index:

  • Binary files
  • Branches other than the checked out branch (GitLab Orbit Local) or the default branch (GitLab Orbit Remote)

Source code

Code structureGitLab Orbit LocalGitLab Orbit Remote
Files and directoriescheck-smcheck-sm
Function, class, method, and module definitionscheck-smcheck-sm
Import declarationscheck-smcheck-sm
Cross-file symbol referencescheck-smcheck-sm

Groups, projects, and users

Groups, projects, and usersGitLab Orbit LocalGitLab Orbit Remote
GroupsNocheck-sm
ProjectsNocheck-sm
UsersNocheck-sm
Notes and commentsNocheck-sm

Code review

Code reviewGitLab Orbit LocalGitLab Orbit Remote
Merge requestsNocheck-sm
Merge request diffsNocheck-sm
Changed filesNocheck-sm

CI/CD pipelines

CI/CDGitLab Orbit LocalGitLab Orbit Remote
PipelinesNocheck-sm
StagesNocheck-sm
JobsNocheck-sm

Code planning

Code planningGitLab Orbit LocalGitLab Orbit Remote
IssuesNocheck-sm
EpicsNocheck-sm
TasksNocheck-sm
IncidentsNocheck-sm
MilestonesNocheck-sm
LabelsNocheck-sm

Security

SecurityGitLab Orbit LocalGitLab Orbit Remote
VulnerabilitiesNocheck-sm
Security findingsNocheck-sm
Security scansNocheck-sm
ScannersNocheck-sm
CVE identifiersNocheck-sm
CWE identifiersNocheck-sm

Supported languages

GitLab Orbit Remote and Local index code in the same languages.

LanguageDefinitionsCross-file references
Rubycheck-smcheck-sm
Javacheck-smcheck-sm
Kotlincheck-smcheck-sm
Pythoncheck-smcheck-sm
TypeScriptcheck-smcheck-sm
JavaScriptcheck-smcheck-sm
Rustcheck-smcheck-sm
Gocheck-smcheck-sm
C#check-smcheck-sm
Ccheck-smcheck-sm
C++check-smcheck-sm
PHPcheck-smcheck-sm
Bash/Shellcheck-smNo

Work scope and freshness

GitLab Orbit Remote and Local see different versions of your code.

GitLab Orbit Local:

  • Indexes the working tree as it is on disk
  • Includes files you have not committed, and excludes .gitignore
  • Never checks out another branch
  • Requires manual re-indexing to refresh the graph

GitLab Orbit Remote:

  • Indexes the default branch of every project in the top-level groups where you turned GitLab Orbit on
  • Reindexes the graph automatically when the default branch changes
ScopeGitLab Orbit LocalGitLab Orbit Remote
Working tree, including uncommitted filescheck-smNo
Default branch onlyNocheck-sm
Multiple repositories in one graphcheck-smcheck-sm
Whole top-level groupNocheck-sm
Branch selectionNoNo
Updates automaticallyNocheck-sm

Supported tooling

Access methodGitLab Orbit LocalGitLab Orbit Remote
GitLab Orbit CLI (orbit)check-smNo
GitLab CLI (glab orbit local and glab orbit remote)check-smcheck-sm
MCPcheck-smcheck-sm
REST APINocheck-sm
GitLab Duo Agent PlatformNocheck-sm
GitLab UINocheck-sm

Query interface

QueryingGitLab Orbit LocalGitLab Orbit Remote
Read-only SQLcheck-smNo
JSON query DSLNocheck-sm
Natural language through an agentcheck-smcheck-sm
Query results scoped by permissionsNocheck-sm

The GitLab Orbit skill

The GitLab Orbit skill gives AI coding agents structured guidance for graph queries. You use the same skill for GitLab Orbit Remote and Local, but the guidance differs.

For more information, see set up AI coding agents with the GitLab Orbit skill.

Skill capabilityGitLab Orbit LocalGitLab Orbit Remote
Query language guidanceRead-only SQLJSON query DSL
Paste-ready query recipesNocheck-sm
Repository map helpercheck-smcheck-sm
Reporting and coverage guidanceNocheck-sm
Setup checklist and troubleshootingcheck-smcheck-sm