Skip to content

Packages and container registry

The package registry of a project or a group: list packages of any format and their files, read and delete them, and publish and download files of the generic package registry, including publishing a file and linking it to a release in one step, or a whole local directory. The container registry: list a project’s or a group’s repositories, read and delete them, and list, read and delete their tags, one at a time or in bulk.

Protection rules restrict who may push or delete packages and container images: package protection rules, container repository protection rules and container image tag protection rules, each listed, created, updated and deleted here.

package.get reads only a package whose status is default or deprecated: GitLab answers 404 for any other, so a package_id that package.list shows in error status, or in hidden, processing or pending_destruction when asked for by status, answers 404 while the package still exists, as a deleted version does. The action then returns a not-found result naming both reasons rather than an error.

package.download writes to the disk of the machine the server runs on, so it is classified as a write, which read-only mode removes and safe mode previews. output_path must resolve under the working directory, the OS temporary directory or a directory named in GITLAB_MCP_ALLOWED_DOWNLOAD_DIRS, and a server reached over HTTP refuses every local path. The file is written beside output_path under a temporary name and renamed over it once complete, so the server needs write permission on that directory, not only on an existing file, and on Unix the new file is readable and writable by its owner alone (mode 0600), whatever the file it replaces allowed.

  • “List the packages of project 42”
  • “Upload the release binary to the generic package registry”
  • “Show the tags of the api image”
  • “Delete the container tags older than the last ten”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as package.delete, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_package with action set to the action’s name, such as delete, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_package_delete, with its parameters as the arguments.

Every tier serves the whole group, on self-managed instances and on GitLab.com alike.

Read-only actions: 12 of 30, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
package.deletegitlab_package_delete
package.downloadgitlab_package_download
package.file_deletegitlab_package_file_delete
package.file_listgitlab_package_file_list
package.getgitlab_package_get
package.group_listgitlab_list_group_packages
package.listgitlab_package_list
package.protection_rule_creategitlab_create_package_protection_rule
package.protection_rule_deletegitlab_delete_package_protection_rule
package.protection_rule_listgitlab_list_package_protection_rules
package.protection_rule_updategitlab_update_package_protection_rule
package.publishgitlab_package_publish
package.publish_and_linkgitlab_package_publish_and_link
package.publish_directorygitlab_package_publish_directory
package.registry_deletegitlab_registry_delete_repository
package.registry_getgitlab_registry_get_repository
package.registry_list_groupgitlab_registry_list_group
package.registry_list_projectgitlab_registry_list_project
package.registry_rule_creategitlab_registry_protection_create
package.registry_rule_deletegitlab_registry_protection_delete
package.registry_rule_listgitlab_registry_protection_list
package.registry_rule_updategitlab_registry_protection_update
package.registry_tag_deletegitlab_registry_delete_tag
package.registry_tag_delete_bulkgitlab_registry_delete_tags_bulk
package.registry_tag_getgitlab_registry_get_tag
package.registry_tag_listgitlab_registry_list_tags
package.registry_tag_rule_creategitlab_registry_tag_protection_create
package.registry_tag_rule_deletegitlab_registry_tag_protection_delete
package.registry_tag_rule_listgitlab_registry_tag_protection_list
package.registry_tag_rule_updategitlab_registry_tag_protection_update

Delete a package permanently. Returns: a success confirmation naming the deleted package and project. See also: package.list, package.file_delete.

  • Meta-tool: gitlab_package, action delete
  • Individual tool: gitlab_package_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
package_idstring/integeryesPackage ID to delete
project_idstring/integeryesProject ID or URL-encoded path

Download a single file from the Generic Package Registry to a local path. Returns: the local output path, byte size, and SHA256 checksum. See also: package.file_list, package.list.

  • Meta-tool: gitlab_package, action download
  • Individual tool: gitlab_package_download
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
file_namestringyesFile name to download. May include / to describe a directory structure (segments must not be empty or . or ..)
output_pathstringyesAbsolute path where the file will be saved on the local filesystem, confined to the current working directory, the OS temp directory, or a directory listed in GITLAB_MCP_ALLOWED_DOWNLOAD_DIRS. Symlinks are resolved and destinations outside those roots are rejected
package_namestringyesPackage name
package_versionstringyesPackage version
project_idstring/integeryesProject ID or URL-encoded path

Delete a single file from a package permanently. Returns: a success confirmation naming the deleted file, package, and project. See also: package.file_list, package.delete.

  • Meta-tool: gitlab_package, action file_delete
  • Individual tool: gitlab_package_file_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
package_file_idstring/integeryesPackage file ID to delete
package_idstring/integeryesPackage ID
project_idstring/integeryesProject ID or URL-encoded path

List the files within a single package. Returns: package files with name, size, checksums, creation time, the pipelines that built each, and pagination metadata. See also: package.download, package.file_delete, package.list.

  • Meta-tool: gitlab_package, action file_list
  • Individual tool: gitlab_package_file_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
package_idstring/integeryesPackage ID
project_idstring/integeryesProject ID or URL-encoded path
order_bystring (id, file_name, created_at)noOrder package files by: id (default), file_name, or created_at
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction: asc or desc

Get one package of a project with its other versions. Returns: the package’s type, status, creator, pipeline metadata, tags, _links, and its other versions with their tags and the pipeline that built each. See also: package.list, package.file_list, package.delete.

  • Meta-tool: gitlab_package, action get
  • Individual tool: gitlab_package_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
package_idstring/integeryesPackage ID, as package.list or package.group_list returns it
project_idstring/integeryesProject ID or URL-encoded path

List packages across a group and its descendant projects with optional filters and ordering. Returns: matching packages with type, status, owning project id/path, pipeline metadata, tags, _links, and pagination metadata. See also: package.list, package.get, package.file_list, package.delete.

  • Meta-tool: gitlab_package, action group_list
  • Individual tool: gitlab_list_group_packages
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
exclude_subgroupsbooleannoExclude packages from subgroups (only return packages from the group’s direct projects)
include_versionlessbooleannoInclude versionless packages
order_bystring (created_at, name, version, type, project_path)noOrder by group package registry field: created_at, name, version, type, or project_path.
package_namestringnoFilter by package name
package_typestring (composer, conan, generic, golang, helm, maven, npm, nuget, pypi, terraform_module)noFilter by package type: composer, conan, generic, golang, helm, maven, npm, nuget, pypi, or terraform_module.
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction: asc or desc
statusstring (default, hidden, processing, error, pending_destruction, deprecated)noFilter by status: default, hidden, processing, error, pending_destruction, or deprecated.

List packages in a project with optional filters and ordering. Returns: matching packages with type, status, pipeline metadata, tags, _links, and pagination metadata. See also: package.get, package.file_list, package.publish, package.delete.

  • Meta-tool: gitlab_package, action list
  • Individual tool: gitlab_package_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
include_versionlessbooleannoInclude versionless packages
order_bystring (created_at, name, version, type)noOrder by package registry field: created_at, name, version, or type.
package_namestringnoFilter by package name
package_typestring (composer, conan, generic, golang, helm, maven, npm, nuget, pypi, terraform_module)noFilter by package type: composer, conan, generic, golang, helm, maven, npm, nuget, pypi, or terraform_module.
package_versionstringnoFilter by package version
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction: asc or desc
statusstring (default, hidden, processing, error, pending_destruction, deprecated)noFilter by status: default, hidden, processing, error, pending_destruction, or deprecated.

Create a package protection rule for a project. Returns: the new rule’s id, project id, package name pattern, package type, and minimum push/delete access levels. See also: package.protection_rule_list, package.protection_rule_update, package.protection_rule_delete.

  • Meta-tool: gitlab_package, action protection_rule_create
  • Individual tool: gitlab_create_package_protection_rule
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
package_name_patternstringyesPackage name pattern with optional wildcards (e.g. @my-scope/my-pkg*)
package_typestringyesPackage type protected by the rule, spelled as GitLab names the registry format, for example npm. GitLab documents no closed list
project_idstring/integeryesProject ID or URL-encoded path
minimum_access_level_for_deletestringnoMinimum access level for delete (maintainer, owner, admin)
minimum_access_level_for_pushstringnoMinimum access level for push (maintainer, owner, admin)

Delete a package protection rule from a project by its id (cannot be undone). Returns: a success confirmation. See also: package.protection_rule_list, package.protection_rule_create.

  • Meta-tool: gitlab_package, action protection_rule_delete
  • Individual tool: gitlab_delete_package_protection_rule
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
rule_idintegeryesPackage protection rule ID

List package protection rules for a project. Returns: each rule’s id, project id, package name pattern, package type, and minimum push/delete access levels, with pagination metadata. For container image protection use package.registry_rule_list. See also: package.protection_rule_create, package.protection_rule_update.

  • Meta-tool: gitlab_package, action protection_rule_list
  • Individual tool: gitlab_list_package_protection_rules
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
order_bystringnoColumn to order results by (keyset pagination)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction (asc, desc)

Update an existing package protection rule by its id. Returns: the updated rule’s id, project id, package name pattern, package type, and minimum push/delete access levels. See also: package.protection_rule_list, package.protection_rule_create, package.protection_rule_delete.

  • Meta-tool: gitlab_package, action protection_rule_update
  • Individual tool: gitlab_update_package_protection_rule
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
rule_idintegeryesPackage protection rule ID
minimum_access_level_for_deletestringnoMinimum access level for delete (maintainer, owner, admin)
minimum_access_level_for_pushstringnoMinimum access level for push (maintainer, owner, admin)
package_name_patternstringnoPackage name pattern with optional wildcards
package_typestringnoPackage type protected by the rule, spelled as GitLab names the registry format, for example npm. GitLab documents no closed list

Publish a single file to the Generic Package Registry. Returns: the published file’s id, package id, name, size, checksums (md5/sha1/sha256), and download URL. See also: package.publish_and_link, package.publish_directory, package.list.

  • Meta-tool: gitlab_package, action publish
  • Individual tool: gitlab_package_publish
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
file_namestringyesName of the file within the package. May include / to describe a directory structure (segments must not be empty or . or ..)
package_namestringyesPackage name (alphanumeric, dots, dashes, underscores)
package_versionstringyesPackage version (e.g. 1.0.0)
project_idstring/integeryesProject ID or URL-encoded path
content_base64stringnoBase64-encoded file content. Only one should be provided.
file_pathstringnoAbsolute path to a local file. Alternative to content_base64. Only one of file_path or content_base64 should be provided.
selectstring (package_file)noResponse detail selector. Use package_file to receive the published file metadata (id, size, checksums).
statusstring (default, hidden)noPackage visibility on publish: default (publicly visible) or hidden.

Publish a file to the Generic Package Registry and link it to a release in one call. Returns: the published file metadata and the created release asset link. See also: package.publish, package.publish_directory, release.get.

  • Meta-tool: gitlab_package, action publish_and_link
  • Individual tool: gitlab_package_publish_and_link
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
file_namestringyesName of the file within the package
package_namestringyesPackage name (alphanumeric, dots, dashes, underscores)
package_versionstringyesPackage version (e.g. 1.0.0)
project_idstring/integeryesProject ID or URL-encoded path
tag_namestringyesTag name of the release to link the package file to
content_base64stringnoBase64-encoded file content. Alternative to file_path.
file_pathstringnoAbsolute path to a local file. Alternative to content_base64.
link_namestringnoDisplay name of the release link. Defaults to file_name if omitted. MUST be the exact filename. Never add descriptive suffixes.
link_typestring (package, runbook, image, other)noType of the release link: package, runbook, image, or other. Defaults to package.
statusstring (default, hidden)noPackage status: default or hidden

Publish every regular file from a local directory to the Generic Package Registry. Returns: total files, total bytes, per-file results, and any per-file errors. See also: package.publish, package.publish_and_link, package.list.

  • Meta-tool: gitlab_package, action publish_directory
  • Individual tool: gitlab_package_publish_directory
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
directory_pathstringyesAbsolute path to a local directory whose files will be published
package_namestringyesPackage name (alphanumeric, dots, dashes, underscores)
package_versionstringyesPackage version (e.g. 1.0.0)
project_idstring/integeryesProject ID or URL-encoded path
include_patternstringnoSingle glob pattern to filter files within the directory (e.g. *.txt or *.tar.gz). If omitted, all regular files are included. Do not pass comma-separated filenames.
statusstring (default, hidden)noPackage status: default or hidden

Delete one container registry repository (cannot be undone). Returns: a success confirmation. See also: package.registry_list_project, package.registry_get, package.registry_tag_delete.

  • Meta-tool: gitlab_package, action registry_delete
  • Individual tool: gitlab_registry_delete_repository
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
repository_idintegeryesRegistry repository ID

Get details of one container registry repository by its id. Returns: the repository’s name, path, location, status, tag count, and optional tags. See also: package.registry_list_project, package.registry_tag_list, package.registry_delete.

  • Meta-tool: gitlab_package, action registry_get
  • Individual tool: gitlab_registry_get_repository
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
repository_idintegeryesRegistry repository ID
tagsbooleannoInclude tags in response
tags_countbooleannoInclude tags count in response

List container registry image repositories across a group. Returns: each repository’s id, name, path, location, status, tag count, and pagination metadata. See also: package.registry_list_project, package.registry_get.

  • Meta-tool: gitlab_package, action registry_list_group
  • Individual tool: gitlab_registry_list_group
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or path
order_bystringnoColumn to order results by (keyset pagination)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction (asc, desc)

List container registry image repositories in a project. Returns: each repository’s id, name, path, location, status, tag count, optional tags, and pagination metadata. See also: package.registry_get, package.registry_tag_list, package.registry_list_group.

  • Meta-tool: gitlab_package, action registry_list_project
  • Individual tool: gitlab_registry_list_project
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
order_bystringnoColumn to order results by (keyset pagination)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction (asc, desc)
tagsbooleannoInclude tags in response
tags_countbooleannoInclude tags count in response

Create a container registry protection rule for a project.

  • Meta-tool: gitlab_package, action registry_rule_create
  • Individual tool: gitlab_registry_protection_create
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
repository_path_patternstringyesRepository path pattern (e.g. my-project/my-image*)
minimum_access_level_for_deletestringnoMinimum access level for delete (maintainer, owner, admin)
minimum_access_level_for_pushstringnoMinimum access level for push (maintainer, owner, admin)

Delete a container registry repository-path protection rule (cannot be undone). Returns: a success confirmation. See also: package.registry_rule_list, package.registry_rule_create.

  • Meta-tool: gitlab_package, action registry_rule_delete
  • Individual tool: gitlab_registry_protection_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
rule_idintegeryesProtection rule ID

List container registry repository-path protection rules for a project. Returns: each rule’s path pattern and minimum push/delete access levels. For tag-level protection use package.registry_tag_rule_list. See also: package.registry_rule_create, package.registry_tag_rule_list.

  • Meta-tool: gitlab_package, action registry_rule_list
  • Individual tool: gitlab_registry_protection_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path

Update a container registry repository-path protection rule. Returns: the updated rule with its path pattern and minimum push/delete access levels. See also: package.registry_rule_list, package.registry_rule_delete, package.registry_rule_create.

  • Meta-tool: gitlab_package, action registry_rule_update
  • Individual tool: gitlab_registry_protection_update
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
rule_idintegeryesProtection rule ID
minimum_access_level_for_deletestringnoMinimum access level for delete (maintainer, owner, admin)
minimum_access_level_for_pushstringnoMinimum access level for push (maintainer, owner, admin)
repository_path_patternstringnoRepository path pattern

Delete one container registry tag (cannot be undone). Returns: a success confirmation. See also: package.registry_tag_list, package.registry_tag_delete_bulk, package.registry_tag_get.

  • Meta-tool: gitlab_package, action registry_tag_delete
  • Individual tool: gitlab_registry_delete_tag
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
repository_idintegeryesRegistry repository ID
tag_namestringyesTag name to delete

Delete container registry tags in bulk by name patterns and age (cannot be undone). Returns: a success confirmation. Deletion runs asynchronously. See also: package.registry_tag_list, package.registry_tag_delete.

  • Meta-tool: gitlab_package, action registry_tag_delete_bulk
  • Individual tool: gitlab_registry_delete_tags_bulk
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
repository_idintegeryesRegistry repository ID
keep_nintegernoNumber of latest tags to keep
name_regexstringnoDeprecated: regex pattern of tag names to delete. Use name_regex_delete instead
name_regex_deletestringnoRegex pattern of tag names to delete
name_regex_keepstringnoRegex pattern of tag names to keep
older_thanstringnoDelete tags older than this (e.g. 1h, 2d, 1month)

Get metadata of one container registry tag. Returns: the tag’s name, path, location, revision, digest, total size, and creation time. See also: package.registry_tag_list, package.registry_tag_delete.

  • Meta-tool: gitlab_package, action registry_tag_get
  • Individual tool: gitlab_registry_get_tag
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
repository_idintegeryesRegistry repository ID
tag_namestringyesTag name

List tags in one container registry repository.

  • Meta-tool: gitlab_package, action registry_tag_list
  • Individual tool: gitlab_registry_list_tags
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
repository_idintegeryesRegistry repository ID
order_bystringnoColumn to order results by (keyset pagination)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction (asc, desc)

Create a container registry tag protection rule. Returns: the created rule. Omit both minimum access levels to make matching tags immutable. See also: package.registry_tag_rule_list, package.registry_tag_rule_update, package.registry_rule_create.

  • Meta-tool: gitlab_package, action registry_tag_rule_create
  • Individual tool: gitlab_registry_tag_protection_create
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
tag_name_patternstringyesTag name pattern as a RE2 regular expression (e.g. v.+)
minimum_access_level_for_deletestringnoMinimum access level to delete matching tags (maintainer, owner, admin). Omit both push and delete levels to make matching tags immutable
minimum_access_level_for_pushstringnoMinimum access level to push matching tags (maintainer, owner, admin). Omit both push and delete levels to make matching tags immutable

Delete a container registry tag protection rule (cannot be undone). Returns: a success confirmation. See also: package.registry_tag_rule_list, package.registry_tag_rule_create.

  • Meta-tool: gitlab_package, action registry_tag_rule_delete
  • Individual tool: gitlab_registry_tag_protection_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
rule_idintegeryesTag protection rule ID

List container registry tag protection rules for a project. Returns: each rule’s tag name pattern and minimum push/delete access levels (empty = immutable). For repository-path protection use package.registry_rule_list. See also: package.registry_tag_rule_create, package.registry_tag_list.

  • Meta-tool: gitlab_package, action registry_tag_rule_list
  • Individual tool: gitlab_registry_tag_protection_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path

Update a container registry tag protection rule. Returns: the updated rule. See also: package.registry_tag_rule_list, package.registry_tag_rule_delete.

  • Meta-tool: gitlab_package, action registry_tag_rule_update
  • Individual tool: gitlab_registry_tag_protection_update
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
rule_idintegeryesTag protection rule ID
minimum_access_level_for_deletestringnoMinimum access level to delete matching tags (maintainer, owner, admin)
minimum_access_level_for_pushstringnoMinimum access level to push matching tags (maintainer, owner, admin)
tag_name_patternstringnoTag name pattern as a RE2 regular expression