Add frontend handling for Secrets Manager opt-out
What does this MR do and why?
Frontend half of the fix for the Secrets Manager settings toggle having no effect when the secrets_manager_paid_experience feature flag (default off) is enabled. The backend half — tri-state enrollment with a disabled_at column, policy/CI enforcement, and the enrollment resolver returning null for opted-out groups — is in !250989 (merged).
Changes:
- A new
hasSelectedTrialOrPaidAddOnutility feeds into theshowSettingscomputed from !250921 (merged): for the paid experience, the whole Secrets Manager settings section renders only when the enrollment toggle is actionable (a trial or paid add-on has been selected) or the secrets manager is already provisioned for the namespace. Before a trial or paid add-on is selected there is nothing actionable, so the entire section is hidden instead of showing a section with a missing toggle. - Improved loading state: in the paid experience the skeleton loader also waits for the entitlement query, since
showSettingsdepends on it.
References
Related to https://gitlab.com/gitlab-org/gitlab/-/work_items/618054
Stacked on the backend MR !250989 (merged) and targets its branch, but only for review sequencing and so the two halves can be tested together — there is no API dependency, and this frontend works against the current production API as well. It will be retargeted to master once the backend MR merges. The branch also has the latest master merged in, because it builds on the showSettings change from !250921 (merged).
Screenshots or screen recordings
Visible change: the whole Secrets Manager settings section does not appear until a trial or paid add-on is selected. Once it appears, a previously opted-out group shows the enrollment toggle off. Screenshots to be added.
| Before | After |
|---|---|
How to set up and validate locally
- Run GDK with SaaS simulation:
export GITLAB_SIMULATE_SAAS=1 - In rails console:
Feature.enable(:secrets_manager_paid_experience)andFeature.enable(:group_secrets_manager) - Check out this branch (it includes the backend changes)
- Visit the top-level group's settings and confirm the whole Secrets Manager settings section is hidden until the namespace has a trial or paid add-on selected
- With one selected, toggle Secrets Manager off and confirm the toggle shows as off — the backend resolves an opted-out enrollment to
null— then toggle it back on and confirm it is re-enabled
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.