[FF] duo_auto_mode -- advertise the Duo auto mode capability to clients

Summary

Roll out the duo_auto_mode feature flag, which gates advertisement of the Duo auto mode capability to clients. When enabled, whether the capability is actually advertised is controlled by the duo_auto_mode_enabled cascading setting (resolved application_settings -> namespace_settings -> project_settings). Default off (wip type, default_enabled: false, group group::developer clients); when off, the capability is never advertised to clients, which is today's behavior. See Auto mode: duo_auto_mode cascading setting, cap... (#618088 - closed) for context. Introduced in Add duo_auto_mode cascading setting implementat... (!255441 - merged).

  • DRI: @dbernardi
  • Team Slack channel: #s_ai-clients

What could go wrong?

The flag only controls whether the capability is advertised: no data is written, so there is nothing to migrate or backfill on rollback. If something looks wrong, disable the flag and advertisement reverts immediately to today's behavior, with the duo_auto_mode_enabled cascading setting simply becoming inert again. The main risk is unexpected client-side behavior for surfaces that see the advertised capability for the first time once both the flag and the cascading setting are on. Watch Duo-related error rates and client request metrics on https://dashboards.gitlab.net during each rollout step.

Rollout

Run all production /chatops in #production and cross-post results to #g_developer_clients.

Non-production

/chatops gitlab run feature set duo_auto_mode 50 --actors --dev --pre --staging --staging-ref

/chatops gitlab run feature set duo_auto_mode true --dev --pre --staging --staging-ref

Production, percentage rollout (wait at least 15 min between steps, watch dashboards):

/chatops gitlab run feature set duo_auto_mode <percentage> --actors

Or target specific actors instead:

/chatops gitlab run feature set --group=gitlab-org,gitlab-com duo_auto_mode true

/chatops gitlab run feature set --user=dbernardi duo_auto_mode true

Before global rollout

Confirm the relevant gotchas before going to 100%, see enabling a feature for GitLab.com:

Cleanup

Remove the flag once deemed stable. Remove the flag and its YAML definition from the codebase, then:

/chatops gitlab run release check <merge-request-url> <milestone>

/chatops gitlab run feature delete duo_auto_mode --dev --pre --staging --staging-ref --production

Rollback

/chatops gitlab run feature set duo_auto_mode false                                         # production

/chatops gitlab run feature set duo_auto_mode false --dev --pre --staging --staging-ref     # non-production

/chatops gitlab run feature delete duo_auto_mode --dev --pre --staging --staging-ref --production  # remove entirely
Edited by Dylan Bernardi