Default enable duo_agent_platform_executor_binary
What does this MR do and why?
Releases duo_agent_platform_executor_binary by default, and updates the docs that
still describe the npm install path for the GitLab Duo CLI.
When enabled, duo-cli is downloaded as a precompiled binary from the GitLab package
registry with curl instead of being installed with npm install -g @gitlab/duo-cli,
which removes the Node.js/npm dependency from the flow executor.
The flag
The flag was type: gitlab_com_derisk, which must not be default_enabled: true —
Feature::Definition#validate_default_enabled! raises for that type. So this MR moves the
definition to ee/config/feature_flags/beta/ and sets type: beta, following the same
pattern as duo_developer_model_config and the project-bot-authorizations flag.
No code or spec changes. Ai::DuoWorkflows::StartWorkflowService keeps both install paths,
and every spec around them stubs the flag explicitly in both states, so flipping the default
does not change any spec outcome.
The docs
Rolling this out makes the existing docs wrong in a few places, most importantly the
runner firewall allowlist in Configure GitLab Duo, which told administrators to allow
registry.npmjs.org so the runner could download the CLI. The CLI registry base URL is
hardcoded to https://gitlab.com/api/v4/projects in the service, so that row is now
gitlab.com.
| File | Change |
|---|---|
flows/execution/_index.md |
Executor architecture step 1: binary download instead of the npm package. |
flows/execution/images.md |
Custom-image command requirements (curl instead of npm + Node.js), the Alpine setup_script example, the startup-time tip, and the offline build steps (binary first, npm variant dropped). |
administration/gitlab_duo/configure/_index.md |
Runner firewall allowlist row and the paragraph below it. |
gitlab_duo_self_hosted/offline_deployment.md |
Offline executor image build, plus the verification step. |
development/duo_agent_platform/_index.md |
The CLI is no longer described as a Node executor installed from npmjs.com. |
Note
Node.js and npm are not fully gone from the hardened image: the Anthropic Sandbox Runtime is still installed with npm. The docs say that explicitly rather than claiming Node.js has been removed. There is no tracking issue yet for dropping npm from the hardened image once SRT ships as a binary, so that sentence is deliberately unlinked.
Related
- Rollout issue: #602106 (closed) — global rollout on production is complete
- Feature issue: #600436 (closed)
- Introduced by: !239056 (merged)
- Touches the same runtime inventory table as !254080 (merged), which bumps the SRT row. Whichever merges second needs a trivial rebase.
Follow-ups (not in this MR)
default_enabled: truehas no effect while the production feature gate exists. After merge:/chatops gitlab run feature delete duo_agent_platform_executor_binary- The rollout issue still tracks a separate MR to remove the flag and the
npm_cli_install_commandsfallback entirely.