Compare GitLab Orbit Remote and Local
- Tier: Free, Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
- Status: Beta
The availability of this feature is controlled by a feature flag. For more information, see the history. This feature is available for testing, but not ready for production use.
GitLab Orbit creates a read-only property graph you can query. GitLab Orbit Remote connects to your GitLab instance and GitLab Orbit Local can access your local code and projects.
Together, you can use both tools to understand the relationships between your code and other data in your GitLab instance.
The following sections compare GitLab Orbit Remote and Local so you can learn how they work and determine which one is right for you.
GitLab Orbit Remote
GitLab Orbit Remote runs on GitLab infrastructure. It builds a graph of merged source code together with your software development lifecycle (SDLC) data, including groups, projects, users, merge requests, pipelines, work items, and security findings.
Use GitLab Orbit Remote when you need more context about the code you’re working on.
Developers can use GitLab Orbit Remote for the following tasks:
- Assess a blast radius across projects.
- Check code review history.
- Trace a vulnerability back to the change that introduced it.
For product and engineering managers, security teams, and support, use GitLab Orbit Remote with GitLab Duo Agent Platform.
You can ask a question in plain language in the GitLab UI, and the agent queries the graph and answers. Results are scoped to what your role already permits, so you see the same data you would see elsewhere in GitLab.
GitLab Orbit Local
GitLab Orbit Local runs on your machine and builds a code-only graph from a repository you have checked out. It indexes the branch you are on, which gives AI coding agents real structure to work so they can answer questions about your code.
Use GitLab Orbit Local when:
- The network is unavailable. You still need a network connection to manage the
orbitbinary, the GitLab Orbit skill, and telemetry. - The code must not leave your machine.
Developers use GitLab Orbit Local for the following tasks:
- Get oriented with an unfamiliar repository.
- Find every caller of a function before a rename.
- Map what a change touches.
GitLab Orbit on GitLab Self-Managed
GitLab Orbit on GitLab Self-Managed is GitLab Orbit Remote that you run yourself. GitLab Orbit is available only as a Helm chart. You install GitLab Orbit on a Kubernetes cluster, together with Siphon, the data pipeline that copies your GitLab database into ClickHouse.
Where you install GitLab Orbit depends on how you installed GitLab:
- Linux package: Create a separate Kubernetes cluster for GitLab Orbit, and connect it to the server that runs GitLab. The cluster and your instance must be able to reach each other.
- GitLab Helm chart: Install GitLab Orbit in the same cluster that runs GitLab.
For more information, see GitLab Orbit on GitLab Self-Managed.
Deployment and network
After you install the GitLab Orbit binary, index and query commands are entirely local, and no request leaves your computer to build or read the graph.
On GitLab.com, GitLab Orbit Remote runs in a separate Kubernetes cluster from your GitLab instance. This deployment approach ensures memory usage and compute remain separate.
| Deployment | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Runs on your machine | No | |
| Runs on GitLab infrastructure | No | |
| Graph storage | DuckDB file at ~/.orbit/graph.duckdb | Managed ClickHouse |
| Storage you set up | No | No |
| Network connection required to query | No | |
| GitLab instance required | No |
Authentication and authorization
| Access control | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| GitLab account required | No | |
| Token or sign-in required | No | |
| Results scoped to your role | No | |
| Minimum role to query | None | Reporter |
| Minimum role for security data | None | Security Manager |
| Minimum role to turn on indexing | None | Owner on the top-level group |
GitLab Orbit Local has no authorization layer, and does not require authentication. GitLab Orbit Remote delegates every access decision to GitLab.
Programmatic access to GitLab Orbit Remote uses your existing GitLab authentication.
For more information, see GitLab Orbit Remote security.
Indexed data
GitLab Orbit Local and Remote index different types of data. The following sections list what each feature indexes.
GitLab Orbit Remote and Local do not index:
- Binary files
- Branches other than the checked out branch (GitLab Orbit Local) or the default branch (GitLab Orbit Remote)
Source code
| Code structure | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Files and directories | ||
| Function, class, method, and module definitions | ||
| Import declarations | ||
| Cross-file symbol references |
Groups, projects, and users
| Groups, projects, and users | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Groups | No | |
| Projects | No | |
| Users | No | |
| Notes and comments | No |
Code review
| Code review | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Merge requests | No | |
| Merge request diffs | No | |
| Changed files | No |
CI/CD pipelines
| CI/CD | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Pipelines | No | |
| Stages | No | |
| Jobs | No |
Code planning
| Code planning | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Issues | No | |
| Epics | No | |
| Tasks | No | |
| Incidents | No | |
| Milestones | No | |
| Labels | No |
Security
| Security | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Vulnerabilities | No | |
| Security findings | No | |
| Security scans | No | |
| Scanners | No | |
| CVE identifiers | No | |
| CWE identifiers | No |
Supported languages
GitLab Orbit Remote and Local index code in the same languages.
| Language | Definitions | Cross-file references |
|---|---|---|
| Ruby | ||
| Java | ||
| Kotlin | ||
| Python | ||
| TypeScript | ||
| JavaScript | ||
| Rust | ||
| Go | ||
| C# | ||
| C | ||
| C++ | ||
| PHP | ||
| Bash/Shell | No |
Work scope and freshness
GitLab Orbit Remote and Local see different versions of your code.
GitLab Orbit Local:
- Indexes the working tree as it is on disk
- Includes files you have
not committed, and excludes
.gitignore - Never checks out another branch
- Requires manual re-indexing to refresh the graph
GitLab Orbit Remote:
- Indexes the default branch of every project in the top-level groups where you turned GitLab Orbit on
- Reindexes the graph automatically when the default branch changes
| Scope | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Working tree, including uncommitted files | No | |
| Default branch only | No | |
| Multiple repositories in one graph | ||
| Whole top-level group | No | |
| Branch selection | No | No |
| Updates automatically | No |
Supported tooling
| Access method | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
GitLab Orbit CLI (orbit) | No | |
GitLab CLI (glab orbit local and glab orbit remote) | ||
| MCP | ||
| REST API | No | |
| GitLab Duo Agent Platform | No | |
| GitLab UI | No |
Query interface
| Querying | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Read-only SQL | No | |
| JSON query DSL | No | |
| Natural language through an agent | ||
| Query results scoped by permissions | No |
The GitLab Orbit skill
The GitLab Orbit skill gives AI coding agents structured guidance for graph queries. You use the same skill for GitLab Orbit Remote and Local, but the guidance differs.
For more information, see set up AI coding agents with the GitLab Orbit skill.
| Skill capability | GitLab Orbit Local | GitLab Orbit Remote |
|---|---|---|
| Query language guidance | Read-only SQL | JSON query DSL |
| Paste-ready query recipes | No | |
| Repository map helper | ||
| Reporting and coverage guidance | No | |
| Setup checklist and troubleshooting |