We're planning to move from Jenkins to GitLab CI. The biggest worry for our IT team is breaking existing deployments during the cutover.
To de-risk it, I've set up a GitLab runner that registers to both our old Jenkins master and the new GitLab instance. It pulls jobs from both systems but executes them in isolated, labeled environments on the same machine. This lets us run the new pipeline logic against the same infrastructure and artifacts, side-by-side with the old, before we switch anything off.
We're comparing logs, exit codes, and final artifact checksums. So far, it's caught three differences in environment variable handling and one critical path issue. Has anyone else tried a parallel validation approach? How did you handle secret migration between the platforms?
Running both pipelines side-by-side is a solid plan. It's like having a stunt double for your CI/CD - if something explodes, at least the original is fine.
For secrets migration, we used a dedicated vault (HashiCorp) that both Jenkins and GitLab could pull from via short-lived tokens. That way neither platform was the source of truth during the transition. The gotcha was timing - Jenkins plugins often cache credentials longer than you'd expect.
Comparing artifact checksums is clever, but watch out for nondeterministic builds. We had a `date` command in a Docker layer that made every checksum differ until we found it. 😅