Move Secrets Manager settings to the group Secure tab

What does this MR do and why?

The secrets manager settings are being moved out of the General section, and into the recently created Secure section for better discoverability. This move is happening only for the top-level group where the toggle lives, for now subgroups and projects secrets manager settings will continue to be in the General section. Documentation has been updated as well. As a result of moving the TLG settings, the QA specs needed to be updated as well.

For self-managed, the top level group setting has been moved as well for consistency, but the toggle for self-managed lives on the instance level.

It did not seem necessary to create a new component so the same component is being reused, however in this new settings section it needs to be rendered slightly differently (as a collapsible accordion section) unlike when it was nested deep in the General settings.

This change more or less translates the existing setup to a new location.

Resolves #605581 (closed)

References

Screenshots or screen recordings

The top-level group's Secrets Manager settings move from Settings > General to Settings > Secure. Subgroups and projects are unchanged.

Experience Before — Settings > General After — Settings > Secure
Paid (single toggle) secrets_manager_paid_experience enabled 00-tlg-general-before 01-tlg-secure-paid
Beta (enrollment + provisioning toggles) secrets_manager_paid_experience disabled 00b-tlg-general-before-beta 02-tlg-secure-beta

Self-managed top-level group — no toggle, permissions table only:

Self-managed — Settings > Secure
03-selfmanaged-tlg-secure

How to set up and validate locally

Prerequisites

  1. When starting gdk, use GITLAB_SIMULATE_SAAS=1 gdk start to emulate SaaS.

  2. Upload a Premium license (or above).

  3. Set up the GDK with OpenBao: https://gitlab.com/gitlab-org/gitlab-development-kit/-/blob/main/doc/howto/openbao.md

  4. Enable the following feature flags: secrets_manager, group_secrets_manager, secrets_manager_namespace_enrollment, secrets_manager_paid_experience.

  5. Local GDK has no CustomersDot, so a paid entitlement never resolves. Add this temporary initializer to force one, then delete it before pushing (do not commit):

    # config/initializers/zzz_local_secrets_manager_entitlement_spoof.rb
    #
    # TEMP, local-only: forces a paid Secrets Manager entitlement so the settings
    # render without a live CustomersDot connection. Delete before pushing.
    if Rails.env.development?
      Rails.application.config.to_prepare do
        paid_entitlement = SecretsManagement::Entitlement.new(
          state: :paid,
          on_demand_enabled: true,
          credits_remaining: 1000,
          credits_total: 1000,
          beta_program_ended: false,
          beta_window_eligible: false
        )
        SecretsManagement::Entitlement.define_singleton_method(:for) do |*_args, **_kwargs|
          paid_entitlement
        end
      end
    end

Validate

  1. Visit the group's Settings > Secure and confirm Secrets Manager renders in a collapsible block titled "GitLab Secrets Manager" (blue "New" badge, one description, single enable toggle).
  2. Confirm it no longer appears under Settings > General, while a subgroup and a project still show it under Settings > General.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Ahmad Hussein

Merge request reports

Loading
Loading