Skip to content

Corrective actions for Some users of AI may get 401 unauthorized

Description

This is the follow-up issue for corrective actions required for this incident.

In summary, we recently rotated the JWT signing key for CustomersDot, see https://gitlab.com/gitlab-org/customers-gitlab-com/-/issues/7112+s. While the key rotation was successful, we discovered that the JWKS cache in the AI Gateway needs to be invalidated immediately when such changes go live. This resulted in some users of AI features getting 401 unauthorized errors.

To resolve this, we are taking the following actions:

Once these actions are complete, we expect the 401 errors to cease and AI features to function normally again.

Edited by Aleksei Lipniagov