Enable duo_mcp_tool_governance by default
What does this MR do and why?
Makes GitLab MCP server tool governance available to GitLab Self-Managed and GitLab Dedicated in 19.4, by moving duo_mcp_tool_governance to the beta flag type and enabling it by default.
The feature reached 100% of actors on GitLab.com on 2026-09-08 (rollout logged on https://gitlab.com/gitlab-org/gitlab/-/work_items/607499). That covers GitLab.com only. Self-managed and Dedicated instances have no Flipper record, so they read default_enabled from the flag definition, which is false — a 19.4 install still has the feature off.
gitlab_com_derisk cannot be default-enabled: lib/feature/shared.rb sets can_be_default_enabled: false for that type, and lib/feature/definition.rb raises InvalidFeatureFlagError if you try. The feature flag lifecycle allows either removing the flag or flipping it to enabled by default, the latter only for ops and beta.
Moving to beta rather than removing the flag keeps a kill switch: a self-managed administrator can still run Feature.disable(:duo_mcp_tool_governance). The feature is documented as beta, and the sibling flag on the same documentation page, gitlab_duo_governance_settings, is already type: beta with default_enabled: true.
Feature issue: https://gitlab.com/gitlab-org/gitlab/-/work_items/606073 Rollout issue: https://gitlab.com/gitlab-org/gitlab/-/work_items/607499 Introduced by: !247822 (merged)
What does not change
- No production code.
Feature.enabled?(:duo_mcp_tool_governance, namespace)inee/lib/ai/tool_rules/governed_mcp_tools.rbstays, and passes notype:keyword, soFeature::Definition#valid_usage!has nothing to check. - No specs. In RSpec an unstubbed flag is forced on regardless of
default_enabled(spec/support/helpers/stubbed_feature.rb), so the existingstub_feature_flags(duo_mcp_tool_governance: false)blocks behave exactly as before. - Nothing on GitLab.com. The flag already has a boolean gate set to
truethere;default_enabledonly applies where no record exists. doc/administration/feature_flags/list.mdis generated from the flag definitions at docs build time. Moving the flag tobetais what makes it appear there.
Screenshots or screen recordings
Not applicable, no user-facing UI change in this MR. The governance UI shipped in !247822 (merged).
How to set up and validate locally
The flag definition is validated at boot, so a wrong directory or an illegal default_enabled fails the whole suite rather than one spec.
-
Confirm the definition loads with the new type:
Feature::Definition.get(:duo_mcp_tool_governance).to_h # => type: "beta", default_enabled: true -
Confirm the self-managed path, by clearing the local record so the
default_enabledfallback answers:Feature.remove(:duo_mcp_tool_governance) Feature.enabled?(:duo_mcp_tool_governance, Group.first) # => true (false on master) -
Open Settings > GitLab Duo > Governance > Tool management for a top-level group and filter for
search. It should show sourcemcpand actionREAD.
MR acceptance checklist
This MR meets the definition of done.