I have a GitLab → Vercel project where pushes to main intermittently stop triggering deployments. It's now happened 4 separate times since late July 2026.
When it's broken, GitLab's webhook delivery to the Vercel incoming endpoint returns a 403. GitLab's own "Recent Deliveries" log shows the webhook fires correctly with the right payload and commit SHA — Vercel's endpoint is the one rejecting it:
POST https://api.vercel.com/v1/incoming/gitlab?accountId=[redacted]403 Forbidden
{"error":{"code":"forbidden","message":"unknown incoming IP address"}}
So GitLab is sending fine — Vercel appears to be rejecting the source IP of GitLab.com's webhook. This looks like a Vercel-side IP allowlist / ingress issue for GitLab's current webhook egress IPs, not anything I can configure on my end.
What I've already tried (all ineffective):
- Triggering a Deploy Hook manually — works as a one-off, but it's a manual workaround, not a fix, and it gets invalidated whenever I touch the Git integration.
- Fully disconnecting and reconnecting the GitLab integration at the project level — didn't resolve it, and it invalidated my existing Deploy Hook URL (had to recreate it).
Questions:
- Is this a known issue with Vercel's allowlist not recognizing GitLab.com's current webhook source IPs?
- Is there anything configurable on my side, or does this require Vercel to update the ingress allowlist for my account?
- Has anyone else resolved this permanently (not just via Deploy Hooks)?
Happy to share my team ID, project, and the failing request IDs/timestamps privately with a Vercel staff member. Thanks!