Default enable duo_agent_platform_executor_binary

What does this MR do and why?

Releases duo_agent_platform_executor_binary by default, and updates the docs that still describe the npm install path for the GitLab Duo CLI.

When enabled, duo-cli is downloaded as a precompiled binary from the GitLab package registry with curl instead of being installed with npm install -g @gitlab/duo-cli, which removes the Node.js/npm dependency from the flow executor.

The flag

The flag was type: gitlab_com_derisk, which must not be default_enabled: true — Feature::Definition#validate_default_enabled! raises for that type. So this MR moves the definition to ee/config/feature_flags/beta/ and sets type: beta, following the same pattern as duo_developer_model_config and the project-bot-authorizations flag.

No code or spec changes. Ai::DuoWorkflows::StartWorkflowService keeps both install paths, and every spec around them stubs the flag explicitly in both states, so flipping the default does not change any spec outcome.

The docs

Rolling this out makes the existing docs wrong in a few places, most importantly the runner firewall allowlist in Configure GitLab Duo, which told administrators to allow registry.npmjs.org so the runner could download the CLI. The CLI registry base URL is hardcoded to https://gitlab.com/api/v4/projects in the service, so that row is now gitlab.com.

File Change
flows/execution/_index.md Executor architecture step 1: binary download instead of the npm package.
flows/execution/images.md Custom-image command requirements (curl instead of npm + Node.js), the Alpine setup_script example, the startup-time tip, and the offline build steps (binary first, npm variant dropped).
administration/gitlab_duo/configure/_index.md Runner firewall allowlist row and the paragraph below it.
gitlab_duo_self_hosted/offline_deployment.md Offline executor image build, plus the verification step.
development/duo_agent_platform/_index.md The CLI is no longer described as a Node executor installed from npmjs.com.

Note

Node.js and npm are not fully gone from the hardened image: the Anthropic Sandbox Runtime is still installed with npm. The docs say that explicitly rather than claiming Node.js has been removed. There is no tracking issue yet for dropping npm from the hardened image once SRT ships as a binary, so that sentence is deliberately unlinked.

Follow-ups (not in this MR)

  1. default_enabled: true has no effect while the production feature gate exists. After merge: /chatops gitlab run feature delete duo_agent_platform_executor_binary
  2. The rollout issue still tracks a separate MR to remove the flag and the npm_cli_install_commands fallback entirely.

🤖 Generated with Claude Code

Edited by Andras Herczeg

Merge request reports

Loading
Loading