Backport of "Fix self-hosted DWS TLS setting ignored in flow validation and metadata"
What does this MR do and why?
Backport of !245610 (merged) to 19-1-stable-ee.
On self-hosted instances, dws_flow_config_validator were building the DWS gRPC client without passing a feature_setting. Because of that, Client.secure? was falling back to the global config default (true) instead of reading the admin's actual TLS setting from application settings. If the self-hosted DWS endpoint was plaintext, this caused an SSL WRONG_VERSION_NUMBER error.
This fix resolves a feature_setting via FeatureSettingSelectionService and passes it to both Client.url_for and Client.secure?, matching the pattern already used in DuoAgentPlatformProbe and workflows.rb.
- Original MR: !245610 (merged)
- Issue: #605958 (closed)
How to set up and validate locally
Validation steps
1. Flow config validation (dws_flow_config_validator):
- Go to a project with AI Catalog enabled
- Create a new custom flow with a valid definition and make sure it saves successfully
- Now edit the flow and use a missing variable like
{{data}}in the prompt. The DWS validation should catch it and return an error - Similarly create custom agent and verify it saved correctly and when passing invalid prompt system should return error based on the DWS validation.
2. rpecs:
bin/rspec ee/spec/services/ai/catalog/flows/create_service_spec.rbMR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.
- This MR is backporting a bug fix, documentation update, or spec fix, previously merged in the default branch.
- The MR that fixed the bug on the default branch has been deployed to GitLab.com (not applicable for documentation or spec changes).
- The MR title is descriptive (e.g. "Backport of 'title of default branch MR'"). This is important, since the title will be copied to the patch blog post.
- Required labels have been applied to this merge request
- severity label and bug subtype labels (if applicable)
- If this MR fixes a bug that affects customers, the customer label has been applied.
- This MR has been approved by a maintainer (only one approval is required).
- Ensure the
e2e:test-on-omnibus-eejob has succeeded, or if it has failed, investigate the failures. If you determine the failures are unrelated, you may proceed. If you need assistance investigating, request help in the #s_developer_experience Slack channel to confirm the failures are unrelated to the merge request.
Note to the merge request author and maintainer
If you have questions about the patch release process, please:
- Refer to the patch release runbook for engineers and maintainers for guidance.
- Ask questions on the
#releasesSlack channel (internal only). - Once the backport has been merged, the commit changes will be automatically deployed to a release environment that can be used for manual validation. See after merging runbook for details.