Auto mode: duo_auto_mode cascading setting, capability, and settings UI
Summary
Adds the duo_auto_mode cascading setting and capability so instances, groups, and projects can enable auto mode in the CLI/IDE surfaces, flag-gated behind duo_auto_mode (beta, off by default). Auto mode lets users relax governance Always Ask rules to Always Allow.
What shipped
- Migrations (Add duo_auto_mode_enabled cascading setting dat... (!255428 - merged)):
duo_auto_mode_enabledcascading columns on namespace + project settings (default: false, null: false) +structure.sql. - Implementation (Add duo_auto_mode cascading setting implementat... (!255441 - merged)):
duo_auto_modefeature flag + cascading-setting logic modeled ontool_approval_for_session_enabled(namespacecascading_attr, project override, 3-state availability,CascadeDuoSettingsService), GraphQL group field +projectSettingsUpdatearg + Duo admin REST allow-list, and the auto mode capability advertised viaAi::FlowsMetadataService/compute_server_capabilitiesonly when enabled. Read-cascade, so it uses areset_duo_auto_mode_to_inherit_from_namespaceworkaround inEE::Projects::CreateService(legacy-pattern gap tracked by Refactor duo cascading defaults into a single d... (!255492 - merged)). - UI toggle (Add duo_auto_mode UI toggle to Duo settings (!253317 - merged)): auto mode toggle on Group and Admin Duo settings with cascading-lock parity to
tool_approval_for_session; flag transitionedwiptobeta.
Follow-up (not in these MRs)
- Project-level Settings UI toggle: Add project-level Settings UI toggle for Duo au... (#630007 - closed) (Add duo_auto_mode toggle to project-level Duo s... (!256557 - merged)).
- Rollout: [FF] `duo_auto_mode` -- advertise the Duo auto ... (#629172).
Epic: [Auto Mode] Iteration 0: Client-side enabled au... (&23199 - closed)
Edited by Dylan Bernardi