with 3.7.0 you should always set GITLAB_SECRET, because it can not be nullable any more.
we are not using tokens at all both servers (gitlab and satis) are in intranet.
may be uncomment in .env:
# GITLAB_SECRET=
and set parameter
env(GITLAB_SECRET): ~
in defaults.yml