Enable duo_mcp_tool_governance by default

What does this MR do and why?

Makes GitLab MCP server tool governance available to GitLab Self-Managed and GitLab Dedicated in 19.4, by moving duo_mcp_tool_governance to the beta flag type and enabling it by default.

The feature reached 100% of actors on GitLab.com on 2026-09-08 (rollout logged on https://gitlab.com/gitlab-org/gitlab/-/work_items/607499). That covers GitLab.com only. Self-managed and Dedicated instances have no Flipper record, so they read default_enabled from the flag definition, which is false — a 19.4 install still has the feature off.

gitlab_com_derisk cannot be default-enabled: lib/feature/shared.rb sets can_be_default_enabled: false for that type, and lib/feature/definition.rb raises InvalidFeatureFlagError if you try. The feature flag lifecycle allows either removing the flag or flipping it to enabled by default, the latter only for ops and beta.

Moving to beta rather than removing the flag keeps a kill switch: a self-managed administrator can still run Feature.disable(:duo_mcp_tool_governance). The feature is documented as beta, and the sibling flag on the same documentation page, gitlab_duo_governance_settings, is already type: beta with default_enabled: true.

Feature issue: https://gitlab.com/gitlab-org/gitlab/-/work_items/606073 Rollout issue: https://gitlab.com/gitlab-org/gitlab/-/work_items/607499 Introduced by: !247822 (merged)

What does not change

  • No production code. Feature.enabled?(:duo_mcp_tool_governance, namespace) in ee/lib/ai/tool_rules/governed_mcp_tools.rb stays, and passes no type: keyword, so Feature::Definition#valid_usage! has nothing to check.
  • No specs. In RSpec an unstubbed flag is forced on regardless of default_enabled (spec/support/helpers/stubbed_feature.rb), so the existing stub_feature_flags(duo_mcp_tool_governance: false) blocks behave exactly as before.
  • Nothing on GitLab.com. The flag already has a boolean gate set to true there; default_enabled only applies where no record exists.
  • doc/administration/feature_flags/list.md is generated from the flag definitions at docs build time. Moving the flag to beta is what makes it appear there.

Screenshots or screen recordings

Not applicable, no user-facing UI change in this MR. The governance UI shipped in !247822 (merged).

How to set up and validate locally

The flag definition is validated at boot, so a wrong directory or an illegal default_enabled fails the whole suite rather than one spec.

  1. Confirm the definition loads with the new type:

    Feature::Definition.get(:duo_mcp_tool_governance).to_h
    # => type: "beta", default_enabled: true
  2. Confirm the self-managed path, by clearing the local record so the default_enabled fallback answers:

    Feature.remove(:duo_mcp_tool_governance)
    Feature.enabled?(:duo_mcp_tool_governance, Group.first)
    # => true   (false on master)
  3. Open Settings > GitLab Duo > Governance > Tool management for a top-level group and filter for search. It should show source mcp and action READ.

MR acceptance checklist

This MR meets the definition of done.

Merge request reports

Loading
Loading