Loading
Enforce org maintenance mode for Git LFS and Git access
What does this MR do and why?
Blocks Git LFS and Git repository access when an organization is in maintenance ("read-only") mode. A shared before-action in the LFS request concern covers all LFS operations, and the existing Git access check is extended to fetch/clone (not just push). Blocked requests return 503 with a Retry-After: 60 header for time-bounded maintenance reasons, and 403 otherwise. All enforcement stays behind the organization_maintenance_enforcement feature flag.
References
- Work item: #602812 (closed)
- https://handbook.gitlab.com/handbook/engineering/architecture/design-documents/organization/decisions/010_organization_read_only_mode/
How to set up and validate locally
Feature.enable(:organization_maintenance_enforcement)in a Rails console.- On an active non-default org, call
start_maintenance(maintenance_reason: 'migration')thenconfirm_maintenance. - Attempt an LFS batch download,
git lfs pull, orgit cloneon a project in that org: blocked with 503 +Retry-After. - Switch the reason to an indefinite one (e.g.
'legal'): blocked with 403. - Disable the flag: access works normally again.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Abdul Wadood