SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
CI/CD New Added 8 September 2026

GitLab CI: jobs config should contain at least one visible job

Every job in the pipeline is hidden or excluded. Names starting with a dot are templates rather than jobs, and rules or workflow conditions that match nothing remove the rest, so the pipeline has nothing left to run and is rejected outright.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# Validate before pushing
glab ci lint
# or POST .gitlab-ci.yml to /api/v4/projects/:id/ci/lint

# Hidden templates need a real job that extends them
.build_template:
  script: [make build]

build:
  extends: .build_template
  rules:
    - if: $CI_PIPELINE_SOURCE == 'merge_request_event'
    - if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH

# See what the rules evaluated to for a given ref
glab ci view

How to diagnose CI/CD errors

CI failures that do not reproduce locally are almost always about environment, permissions or resource limits rather than about your code. CI runners have less memory than a laptop, a deliberately restricted token, a clean cache, and often a different CPU architecture. Treating a CI failure as a code bug before checking those four things wastes an enormous amount of time.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Re-run the job with debug logging enabled (ACTIONS_STEP_DEBUG=true in GitHub Actions, CI_DEBUG_TRACE in GitLab). The default log deliberately hides the most useful lines.
  2. Print the environment early: env | sort, node -v, free -m, df -h. Half of all "works on my machine" CI bugs are visible in that output.
  3. Check token permissions explicitly. GitHub's GITHUB_TOKEN defaults to read-only in many organisations and produces the misleading Resource not accessible by integration error.
  4. Remember that secrets are not available to workflows triggered by pull requests from forks. This is a security feature, not a misconfiguration.
  5. Reproduce locally in the same container image the runner uses, rather than on your host, before changing pipeline configuration.

Tools worth reaching for

  • ACTIONS_STEP_DEBUG
  • act (local Actions runner)
  • docker run <runner image>
  • free -m / df -h in-job

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

docs.gitlab.com

Related CI/CD errors

See all 18 CI/CD errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.