Yes. GitLab Self-Managed can use repository-specific instructions to tailor GitLab Duo code review, including rules targeted at file patterns and configured at project, group, or instance scope. The important limit: these instructions guide the AI reviewer; they do not enforce policy or guarantee that every rule will be followed. Keep mandatory security and compliance requirements in deterministic checks and governance controls.
What custom review instructions do—and do not do
GitLab Duo’s custom review instructions supplement the standard review criteria rather than replacing them. They let a team describe how it wants code reviewed, including standards that vary by file type. GitLab’s documentation puts the boundary plainly: “Custom review instructions are guidance for the AI reviewer, not enforced policies.” GitLab’s custom-instructions documentation
As an Amazon Associate I earn from qualifying purchases.
Use them to prompt useful feedback about conventions, maintainability, or areas reviewers should examine. Do not rely on an AI comment as the control that blocks a vulnerable change, proves compliance, or guarantees a required review. For requirements that must be applied consistently, use suitable deterministic checks and governance mechanisms.
Free tools Windows power users keep installed
One-click scans. No signup required.
Choose the GitLab Duo review mode first
GitLab documents two related but distinct review features. Their prerequisites and execution differ, so confirm which one the instance and group are configured to use before setting expectations or troubleshooting. Tier, add-on, and availability details can change by GitLab version; check the documentation for the deployed release and the organization’s settings.
#1 Best Overall
| Mode | What it is | Requirements and context |
|---|---|---|
| Code Review Flow | Agentic review, part of GitLab Duo Agent Platform; supports custom review instructions. | The documented page lists Self-Managed and Premium and Ultimate. It runs as a CI/CD job, so the project needs an eligible runner or GitLab-hosted runners, and the group must allow foundational flows and Code Review. The flow does not reference AGENTS.md or SKILL.md files. See GitLab’s Code Review Flow documentation. |
| GitLab Duo Code Review | Non-agentic review. A user can request a review by assigning @GitLabDuo or using the documented quick action. |
The documented page lists Premium and Ultimate and the GitLab Duo Enterprise add-on, with Self-Managed availability. The selected mode and access depend on add-on and group settings. See GitLab’s GitLab Duo Code Review documentation. |
Do not infer entitlement from “Self-Managed” alone. Verify the GitLab release, seats or add-ons, group settings, and selected review mode for the target instance.
Configure repository-specific instructions
GitLab’s documented repository configuration uses .gitlab/duo/mr-review-instructions.yaml in the repository’s .gitlab/duo directory. Instruction groups have a name and instruction text, and can optionally use file filters. GitLab’s examples separate guidance for languages such as Ruby and Go, test files, and general files; multiple groups can apply to the same file.
- Create the instruction file: add
mr-review-instructions.yamlunder.gitlab/duo/in the repository. - Write focused groups: give each group a meaningful name and concrete review guidance. Add file filters when the guidance applies only to recognizable paths or file types.
- Check the patterns: test glob patterns against repository paths so the intended files match. GitLab recommends validating patterns rather than assuming a filter catches the right files.
- Control ownership: make responsibility for changes visible. GitLab documents protecting the instruction file with a Code Owners entry.
- Review sample merge requests: inspect whether expected files receive relevant feedback and adjust instructions or patterns where needed.
Instructions can also be configured at group or instance scope using a project selected as a template. See GitLab’s instructions for configuring review guidance for the syntax and current setup details.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Plan Self-Managed connectivity and model configuration
Self-Managed GitLab Duo deployments can use GitLab’s cloud-based AI Gateway as the default, an organization’s AI Gateway and self-hosted models, or a hybrid configuration. The documented prerequisites include activating the instance with an activation code, public-hostname DNS resolution, and outbound connectivity to required GitLab services. GitLab says offline licensing is not supported except for GitLab Duo Self-Hosted. Confirm requirements for the specific GitLab release and model deployment before rollout; see GitLab’s Self-Managed configuration documentation.
Code Review Flow also needs its CI/CD execution requirements: an appropriate runner or GitLab-hosted runners, plus group permission for foundational flows and Code Review. These are separate from repository instructions; a correctly written YAML file does not by itself enable the flow.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Understand what the reviewer can see
Non-agentic GitLab Duo Code Review
For this mode, GitLab says the model receives the merge request title and description, filenames, diffs, file contents before changes, and custom instructions. Large requests can exceed the selected model’s context window. If the initial request fails, GitLab retries without original file contents: prompt size may fall, but the model also has less context and feedback may be less specific. GitLab lists a 120-second AI Gateway timeout for this feature. Details are in the feature documentation.
Code Review Flow
The flow’s pre-scan gathers up to approximately 1 MiB and truncates to approximately 800 KiB if that cap is exceeded. Large changes can therefore lose context. GitLab suggests keeping merge requests smaller and excluding irrelevant files to reduce this risk. These are documented context limits, not measures of review accuracy or productivity. See the Code Review Flow documentation.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
A practical rollout checklist
- Identify the review mode and confirm the deployed GitLab version, relevant tier or add-on, and group settings.
- For Code Review Flow, confirm runner availability and that the group permits foundational flows and Code Review.
- For the Self-Managed AI setup, verify activation, DNS resolution, outbound connectivity, and the selected cloud, self-hosted, or hybrid model configuration.
- Write targeted, concrete instructions in
.gitlab/duo/mr-review-instructions.yaml; validate file filters against actual repository paths. - Give the instruction file visible ownership and evaluate sample merge requests for relevance.
- Keep merge requests focused and exclude irrelevant files where appropriate to reduce context loss.
- Keep mandatory controls outside AI instructions: use enforceable checks and governance for security, compliance, and other non-negotiable requirements.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




