Scope DWS client governing namespace to the request container
What does this MR do and why?
Scope DWS client governing namespace to the request container
DuoWorkflowService::Client always resolved governing_namespace
with no scope, so gitlab_root_namespace_id in
the Cloud Connector token (and the namespace/organization
headers sent to AI Gateway) fell back to the user's default
Duo namespace instead of the project or
group the workflow actually runs against, misattributing
billing/quota for every Duo Workflow Service call.
Add a container param to Client and read it through
governing_namespace(container).
Related to https://gitlab.com/gitlab-org/gitlab/-/work_items/616057
References
https://gitlab.com/gitlab-org/gitlab/-/work_items/616057+
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.