What moves to the parent, what stays in the child, and why the boundary is itself a compliance control.
GitLab CI/CD parent/child pipelines for HIPAA workloads
A GitLab-specific breakdown of the parent/child architecture. What moves to the parent (gates, evidence, deploy authorization), what stays in the child (build, test, scan, sign), the artifact contract between them, and multi-project pipelines for a polyrepo split across backend, frontend, infra, networking, and security.
Read the post →