Data migration for Seeded external agents to install glab from official GitLab releases

What does this MR do and why?

GitLab has a Seeder class that seeds GitLab-managed external agent data onto an instance.

In !247375 (merged) the seeder was changed to install glab from official GitLab release sources.

This MR updates already seeded data with the same change.

This is a security-fix-in-public MR.

References

https://gitlab.com/gitlab-org/gitlab/-/work_items/595853+

How to set up and validate locally

If you have no previously seeded external agent data

If you haven't previously seeded the external agents, you can seed them according to how they were before the fix in !247375 (merged).

git checkout -b qa/595853-revert-fix
git revert 22c75ba5cdde --no-commit

Seed from the revert branch:

bundle exec rake gitlab:ai_catalog:seed_external_agents

Switch back to this branch to run the migration.

git checkout 595853-data-migration

Verifying the migrated data is correct

Run the migration:

bundle exec rails db:migrate

In rails console, verify each agent's migrated definition matches current seeder output:

seeder = Gitlab::Ai::Catalog::ThirdPartyFlows::Seeder.new

results = seeder.agents.map do |agent_config|
  item = Ai::Catalog::Item.find_by(name: agent_config[:name])
  actual = item.latest_version.definition
  # Same as https://gitlab.com/gitlab-org/gitlab/-/blob/b1d34d61b7fccab1371f1548751a7674e9de8d0f/ee/lib/gitlab/ai/catalog/third_party_flows/seeder.rb#L265-267
  expected = YAML.safe_load(agent_config[:definition], permitted_classes: [], aliases: false).merge('yaml_definition' => agent_config[:definition])
  actual == expected ? "✓ #{agent_config[:name]}" : "✗ #{agent_config[:name]}: MISMATCH"
end

You should see both agent names have a ✓:

["✓ Claude Agent by GitLab", "✓ Codex Agent by GitLab"]

You can enable an external agent in a project https://docs.gitlab.com/user/duo_agent_platform/agents/external/#enable-in-a-project

Trigger it: https://docs.gitlab.com/user/duo_agent_platform/agents/external/#use-an-external-agent

And verify that it does run:

  • Click on the session link in the comment left by the agent
  • In the session view, click the Job ID link to view the job

In the job logs for each agent you should see the glab was installed.

Claude Code:

image

Codex:

image

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Related to #595853

Edited by Luke Duncalfe

Merge request reports

Loading
Loading