Add MCP rate limit settings to the admin Network page

Problem

The MCP rate limit settings have no admin interface. An administrator can only change them through the settings API or a Rails console, which is out of step with every other rate limit in the product.

Proposal

Add an MCP fieldset to Admin → Settings → Network, alongside the existing IP, search and package registry limits: an enable checkbox and the two numeric fields, matching the shape those already use.

Implementation plan

A _mcp_limits.html.haml partial rendered from network.html.haml, following _ip_limits.html.haml for structure.

It needs a js-mcp-limits-settings anchor. Production change requests link the admin page by anchor when they enable a throttle, so without one there is nothing for the change plan to point at.

Depends on the backend settings from the throttle issue, which defines the fields this renders.

Detail

References at commit 43975c6ae.

Why Network rather than beside the existing MCP setting

The instance-level MCP toggle lives in Admin → Settings → General, under "MCP client access". Putting the limit there would keep the MCP settings together, but every other rate limit in the product is on the Network page, and that is where an administrator looks for one. The split between a feature toggle on General and its limits on Network already exists for other features.

What the fieldset needs

The three settings from the throttle issue: throttle_mcp_enabled, throttle_mcp_requests_per_period, throttle_mcp_period_in_seconds. They also need to be in the permitted attributes list, which the throttle issue covers.

Self-managed and Dedicated

This page is how self-managed administrators enable and tune the limit, since it ships disabled. Dedicated customers cannot use it — their rate limits are set by GitLab per reference architecture and are not editable in the Admin area — so Dedicated is handled separately.

Edited by 🤖 GitLab Bot 🤖