Remove the ignored shallow_clone API parameter
What does this MR do and why?
Removes the shallow_clone parameter from the two Duo Agent Platform flow-creation endpoints. The parameter no longer changes anything.
StartWorkflowService only honoured shallow_clone on the legacy shallow-clone path. That path became unreachable on GitLab.com with the rollout of dap_full_clone , so the parameter has been inert there since. Removing the dap_full_clone flag makes it inert on every instance, including GitLab Self-Managed.
Why no deprecation period
Both endpoints that accepted the parameter are marked as experiments:
ee/lib/api/ai/duo_workflows/workflows.rb:895—route_setting :lifecycle, :experimentee/lib/api/ai/duo_workflows/agent_workflows.rb:128—route_setting :lifecycle, :experiment
Per the REST API style guide, API elements marked as experiment or beta "are exempt from the breaking changes policy, and can be changed or removed at any time without prior notice". So no deprecation announcement is required. The commit carries Changelog: removed.
Usage check
The parameter has no consumers in this repository: no frontend code, no services, no callers beyond the API layer itself. External senders (Duo CLI, IDE extensions) can only send it; after this change Grape filters it out as an undeclared parameter rather than rejecting the request.
Translated copies under doc-locale/ are left to the translation pipeline, which regenerates them from the English source.
Merge order
Important
Merge this after !250204 (merged), which removes the dap_full_clone flag.
Merging this first would regress GitLab Self-Managed. dap_full_clone is default_enabled: false, so the legacy path is still live there and still honours the parameter. Removing the parameter while that path exists makes params.fetch(:shallow_clone, true) fall back to true, which silently takes away the caller's ability to request a full-depth clone. Once !250204 (merged) merges, this MR is a pure dead-code removal with no behaviour change on any instance.
Follow-up
Forcing the full clone removed the only API-level way to ask for a cheaper clone. If the clone cost on large repositories becomes a problem, a replacement option should be designed deliberately rather than by reviving this boolean, whose name no longer matches the implementation. Related: #582380
References
- Flag removal MR: !250204 (merged)
dap_full_clonerollout issue: #602990 (closed)
How to set up and validate locally
The meaningful local test is that the parameter is now ignored rather than rejected, so a request that still sends it succeeds with a 201:
curl --request POST \
--header "PRIVATE-TOKEN: <your-gdk-pat>" \
--header "Content-Type: application/json" \
--data '{"project_id": "<id-or-path>", "goal": "test", "start_workflow": false, "shallow_clone": false}' \
"http://gdk.test:3000/api/v4/ai/duo_workflows/workflows"MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.