Hide provisioning toggle when paid experience is enabled

What does this MR do and why?

To start using the secrets manager, a top-level group Owner must:

  • enroll the namespace
  • start a trial

After which, the TLG, subgroups, and projects in this namespace can provision the secrets manager for themselves.

Currently, we show both the enrollment toggle and provisioning toggle for the TLG. We show only the provisioning toggle in subgroups and projects.

Now that we have auto-provisioning and auto-enrollment in the secrets manager page itself, we can remove the provisioning toggle from the settings. This only applies for the paid experience (secrets_manager_paid_experience feature flag ON). We'll leave the UI for the beta experience (secrets_manager_paid_experience OFF) untouched.

The enrollment toggle for top-level groups will still exist so TLG Owners can disable the secrets manager for the namespace.

In the future, we'll provide ways for TLG Owners to disable the secrets manager for and subgroups and projects individually through the upcoming Dashboard feature.

Screenshots or screen recordings

State TLG Subgroup/Project
Beta (paid experience OFF) tlg_beta project_beta
Paid experience ON tlg_paid_experience project_paid_experience

If paid experience is ON and the subgroup or project did not provision the secrets manager yet from the secrets manager page, we hide the settings. The user will only need to go to the settings to manage permissions, and we don't make permissions available until the secrets manager is provisioned.

Screenshot_2026-08-20_at_02.09.53

How to set up and validate locally

Setting up the secrets manager

  1. When starting gdk, use GITLAB_SIMULATE_SAAS=1 gdk start to emulate SaaS.
  2. Upload a Premium license (or above).
  3. Set up the GDK with OpenBao: https://gitlab.com/gitlab-org/gitlab-development-kit/-/blob/main/doc/howto/openbao.md
  4. Enable the following feature flags: secrets_manager, group_secrets_manager, secrets_manager_namespace_enrollment, secrets_manager_paid_experience.

Verifying the feature

The entitlement resolver communicates with the CDot API. We will monkey-patch this and mock the results of the API so we can control the entitlement state locally.

To mock the API, add these files config/secrets_manager_stub.yml and config/initializers/zz_secrets_manager_stub.rb and restart your gdk. This will mock the entitlement state returned by GraphQL (which we normally get from CDot).

secrets_manager_stub.yml

zz_secrets_manager_stub.rb

This automatically sets the entitlement state to trial_eligible and will set it to trial when the trial mutation is triggered.

  1. Visit a TLG's /-/secrets page.
  2. Click on "Start 30-day trial" button and wait for the process to succeed.
  3. Go to the secrets manager settings and verify that only the enrollment toggle shows up for TLG. For subgroups and projects, there is no toggle.
  • Settings for TLG: Settings > General > Permissions and group features
  • Settings for subgroups and projects: Settings > General > Visibility, project features, permissions
  1. Disable the secrets_manager_paid_experience FF.
  2. Verify that the provisioning toggle shows up in the settings.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Mireya Andres

Merge request reports

Loading
Loading