[FF] duo_auto_mode -- advertise the Duo auto mode capability to clients
Summary
Roll out the duo_auto_mode feature flag, which gates advertisement of the Duo auto mode capability to clients. When enabled, whether the capability is actually advertised is controlled by the duo_auto_mode_enabled cascading setting (resolved application_settings -> namespace_settings -> project_settings). Default off (wip type, default_enabled: false, group group::developer clients); when off, the capability is never advertised to clients, which is today's behavior. See Auto mode: duo_auto_mode cascading setting, cap... (#618088 - closed) for context. Introduced in Add duo_auto_mode cascading setting implementat... (!255441 - merged).
- DRI: @dbernardi
- Team Slack channel:
#s_ai-clients
What could go wrong?
The flag only controls whether the capability is advertised: no data is written, so there is nothing to migrate or backfill on rollback. If something looks wrong, disable the flag and advertisement reverts immediately to today's behavior, with the duo_auto_mode_enabled cascading setting simply becoming inert again. The main risk is unexpected client-side behavior for surfaces that see the advertised capability for the first time once both the flag and the cascading setting are on. Watch Duo-related error rates and client request metrics on https://dashboards.gitlab.net during each rollout step.
Rollout
Run all production /chatops in #production and cross-post results to #g_developer_clients.
Non-production
/chatops gitlab run feature set duo_auto_mode 50 --actors --dev --pre --staging --staging-ref
/chatops gitlab run feature set duo_auto_mode true --dev --pre --staging --staging-refProduction, percentage rollout (wait at least 15 min between steps, watch dashboards):
/chatops gitlab run feature set duo_auto_mode <percentage> --actorsOr target specific actors instead:
/chatops gitlab run feature set --group=gitlab-org,gitlab-com duo_auto_mode true
/chatops gitlab run feature set --user=dbernardi duo_auto_mode trueBefore global rollout
Confirm the relevant gotchas before going to 100%, see enabling a feature for GitLab.com:
- Docs + version history updated
- Change management issue opened, if required
- External API consumers handled with a fail-open mechanism, if applicable
Cleanup
Remove the flag once deemed stable. Remove the flag and its YAML definition from the codebase, then:
/chatops gitlab run release check <merge-request-url> <milestone>
/chatops gitlab run feature delete duo_auto_mode --dev --pre --staging --staging-ref --productionRollback
/chatops gitlab run feature set duo_auto_mode false # production
/chatops gitlab run feature set duo_auto_mode false --dev --pre --staging --staging-ref # non-production
/chatops gitlab run feature delete duo_auto_mode --dev --pre --staging --staging-ref --production # remove entirely