Move Secrets Manager settings to the group Secure tab
What does this MR do and why?
The secrets manager settings are being moved out of the General section, and into the recently created Secure section for better discoverability. This move is happening only for the top-level group where the toggle lives, for now subgroups and projects secrets manager settings will continue to be in the General section. Documentation has been updated as well. As a result of moving the TLG settings, the QA specs needed to be updated as well.
For self-managed, the top level group setting has been moved as well for consistency, but the toggle for self-managed lives on the instance level.
It did not seem necessary to create a new component so the same component is being reused, however in this new settings section it needs to be rendered slightly differently (as a collapsible accordion section) unlike when it was nested deep in the General settings.
This change more or less translates the existing setup to a new location.
Resolves #605581 (closed)
References
Screenshots or screen recordings
The top-level group's Secrets Manager settings move from Settings > General to Settings > Secure. Subgroups and projects are unchanged.
Self-managed top-level group — no toggle, permissions table only:
| Self-managed — Settings > Secure |
|---|
![]() |
How to set up and validate locally
Prerequisites
-
When starting gdk, use
GITLAB_SIMULATE_SAAS=1 gdk startto emulate SaaS. -
Upload a Premium license (or above).
-
Set up the GDK with OpenBao: https://gitlab.com/gitlab-org/gitlab-development-kit/-/blob/main/doc/howto/openbao.md
-
Enable the following feature flags:
secrets_manager,group_secrets_manager,secrets_manager_namespace_enrollment,secrets_manager_paid_experience. -
Local GDK has no CustomersDot, so a paid entitlement never resolves. Add this temporary initializer to force one, then delete it before pushing (do not commit):
# config/initializers/zzz_local_secrets_manager_entitlement_spoof.rb # # TEMP, local-only: forces a paid Secrets Manager entitlement so the settings # render without a live CustomersDot connection. Delete before pushing. if Rails.env.development? Rails.application.config.to_prepare do paid_entitlement = SecretsManagement::Entitlement.new( state: :paid, on_demand_enabled: true, credits_remaining: 1000, credits_total: 1000, beta_program_ended: false, beta_window_eligible: false ) SecretsManagement::Entitlement.define_singleton_method(:for) do |*_args, **_kwargs| paid_entitlement end end end
Validate
- Visit the group's Settings > Secure and confirm Secrets Manager renders in a collapsible block titled "GitLab Secrets Manager" (blue "New" badge, one description, single enable toggle).
- Confirm it no longer appears under Settings > General, while a subgroup and a project still show it under Settings > General.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.




