Enforce org maintenance mode for Git LFS and Git access

What does this MR do and why?

Blocks Git LFS and Git repository access when an organization is in maintenance ("read-only") mode. A shared before-action in the LFS request concern covers all LFS operations, and the existing Git access check is extended to fetch/clone (not just push). Blocked requests return 503 with a Retry-After: 60 header for time-bounded maintenance reasons, and 403 otherwise. All enforcement stays behind the organization_maintenance_enforcement feature flag.

References

How to set up and validate locally

  1. Feature.enable(:organization_maintenance_enforcement) in a Rails console.
  2. On an active non-default org, call start_maintenance(maintenance_reason: 'migration') then confirm_maintenance.
  3. Attempt an LFS batch download, git lfs pull, or git clone on a project in that org: blocked with 503 + Retry-After.
  4. Switch the reason to an indefinite one (e.g. 'legal'): blocked with 403.
  5. Disable the flag: access works normally again.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Abdul Wadood

Merge request reports

Loading
Loading