Remove the npm install path for the GitLab Duo CLI in flow executor jobs
What does this MR do and why?
Removes the duo_agent_platform_executor_binary feature flag together with the npm
install path it guarded. Flow executor CI jobs now always download the GitLab Duo CLI as a
precompiled binary from the GitLab package registry, which is what production has done
since the flag reached 100% (see the rollout issue below) and what the flag has defaulted to
since !254412 (merged).
The @gitlab/duo-cli npm package is no longer published, so the npm path is dead code on
every instance. It also blocks releases: the verify-start-workflow-service-assets CI job
checked DUO_CLI_VERSION against the npm registry with npm view, and that check fails for
any version we could bump to. The job now verifies the binaries in the package registry at
the URL the service builds, and detect-system-tests-duo installs that same pinned binary
instead of an unpinned npm package.
The documentation already describes the binary download since the MR above, so this MR contains no docs changes.
References
- Rollout issue: #602106 (closed)
- Feature issue: #600436 (closed)
- Introduced by: !239056 (merged)
- Default-enable MR: !254412 (merged)
How to set up and validate locally
-
Run the service specs:
bin/rspec ee/spec/services/ai/duo_workflows/start_workflow_service_spec.rb \ ee/spec/services/ai/duo_workflows/resume_workflow_service_spec.rb -
Run the registry check the CI job performs, for the pinned version and for a version that does not exist. The first command exits 0 and the second exits 22:
curl --fail -sfIL -o /dev/null "https://gitlab.com/api/v4/projects/46519181/packages/generic/duo-cli/9.8.0/duo-linux-x64"; echo $? curl --fail -sfIL -o /dev/null "https://gitlab.com/api/v4/projects/46519181/packages/generic/duo-cli/0.0.0/duo-linux-x64"; echo $?
Follow-ups
- After merge and deployment, clean up the flag on all environments as tracked in the rollout issue:
/chatops gitlab run feature delete duo_agent_platform_executor_binary --dev --pre --staging --staging-ref --production. ee/lib/gitlab/duo/developments/swe_bench_seeder/agent_configs.ymlstill installs the CLI with npm in the seededsetup_script. It is a GDK developer seeder and is left for a separate change.NPM_CONFIG_CACHEstays in the sandbox environment because the Anthropic Sandbox Runtime is still installed with npm in custom images.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.