Rollout: security_tracked_context_quota_enforcement feature flag
Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.
Rollout tracking for the security_tracked_context_quota_enforcement feature flag, introduced in !239435 (merged).
This flag gates enforcement of the organization-level tracked security context quota (Security::TrackedContextQuotaService). It is deliberately separate from vulnerabilities_across_contexts so quota enforcement can be rolled out, and disabled in an emergency, independently of VAC tracking.
The actor follows the rollout granularity: during the closed beta callers pass the project, so enforcement can be enabled per project. Later we can pass the organization to toggle enforcement per organization.
Rollout steps
- Enable for internal/test projects in the closed beta
- Enable for trusted closed-beta customers
- Monitor quota-exceeded errors and usage counting
- Decide default-on timing for GA
Part of &20475.
Edited by 🤖 GitLab Bot 🤖