Skip secrets_stored billing events for unenrolled instances
What does this MR do and why?
A previous MR (!253174 (merged)) stopped daily secrets_stored billing events for GitLab.com root namespaces that opted out of the Secrets Manager. That guard checks SecretsManagement::NamespaceEnrollment.opted_out?, which relies on per-namespace enrollment records that only exist on GitLab.com. On self-managed and GitLab Dedicated, opt-out is instance-level — the secrets_manager_instance_enrolled application setting — so no enrollment rows exist and the guard never fires. When an instance unenrolls, secret writes freeze and per-namespace secret counts stay above zero, so once billing events are enabled for instances, unenrolled instances would emit daily billing events indefinitely. This is the same bug shape the previous MR fixed for GitLab.com, and it was raised during review of that MR.
This MR fixes it preemptively — emission is not enabled for instances today, since it is gated behind the secrets_manager_emit_secret_stored_events feature flag (default off, not intended for instances yet). SecretsStoredEmitter#opted_out? now routes by realm using Gitlab::Saas.feature_available?(:gitlab_com_subscriptions), the same split the domain's Entitlement::Resolver already uses: on SaaS it keeps the existing NamespaceEnrollment.opted_out? check, and on instances (self-managed and Dedicated alike) it skips emission when SecretsManagement::InstanceEnrollment.enrolled? is false.
References
- Related to https://gitlab.com/gitlab-org/gitlab/-/work_items/622364 (confidential issue)
- Follow-up to !253174 (merged)
Screenshots or screen recordings
Not applicable — backend-only change.
How to set up and validate locally
In a rails console (GDK runs as self-managed by default):
-
Enable the feature flag:
Feature.enable(:secrets_manager_emit_secret_stored_events) -
Seed a count row:
group = Group.find_by_full_path('<your-root-group>') SecretsManagement::NamespaceSecretCount.upsert_all([{ namespace_id: group.id, root_namespace_id: group.id, count: 5 }], unique_by: :namespace_id) -
Make sure the instance is not enrolled:
Gitlab::CurrentSettings.update!(secrets_manager_instance_enrolled: false) -
Run the emitter — no billing event is tracked (before this fix, it emitted a
secrets_storedevent with quantity 5):SecretsManagement::BillableEvents::SecretsStoredEmitter.new(group).emit! -
Enroll the instance and re-run to confirm the event is emitted again:
Gitlab::CurrentSettings.update!(secrets_manager_instance_enrolled: true) SecretsManagement::BillableEvents::SecretsStoredEmitter.new(group).emit!
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist.