Remove the npm install path for the GitLab Duo CLI in flow executor jobs

What does this MR do and why?

Removes the duo_agent_platform_executor_binary feature flag together with the npm install path it guarded. Flow executor CI jobs now always download the GitLab Duo CLI as a precompiled binary from the GitLab package registry, which is what production has done since the flag reached 100% (see the rollout issue below) and what the flag has defaulted to since !254412 (merged).

The @gitlab/duo-cli npm package is no longer published, so the npm path is dead code on every instance. It also blocks releases: the verify-start-workflow-service-assets CI job checked DUO_CLI_VERSION against the npm registry with npm view, and that check fails for any version we could bump to. The job now verifies the binaries in the package registry at the URL the service builds, and detect-system-tests-duo installs that same pinned binary instead of an unpinned npm package.

The documentation already describes the binary download since the MR above, so this MR contains no docs changes.

References

How to set up and validate locally

  1. Run the service specs:

    bin/rspec ee/spec/services/ai/duo_workflows/start_workflow_service_spec.rb \
      ee/spec/services/ai/duo_workflows/resume_workflow_service_spec.rb
  2. Run the registry check the CI job performs, for the pinned version and for a version that does not exist. The first command exits 0 and the second exits 22:

    curl --fail -sfIL -o /dev/null "https://gitlab.com/api/v4/projects/46519181/packages/generic/duo-cli/9.8.0/duo-linux-x64"; echo $?
    curl --fail -sfIL -o /dev/null "https://gitlab.com/api/v4/projects/46519181/packages/generic/duo-cli/0.0.0/duo-linux-x64"; echo $?

Follow-ups

  • After merge and deployment, clean up the flag on all environments as tracked in the rollout issue: /chatops gitlab run feature delete duo_agent_platform_executor_binary --dev --pre --staging --staging-ref --production.
  • ee/lib/gitlab/duo/developments/swe_bench_seeder/agent_configs.yml still installs the CLI with npm in the seeded setup_script. It is a GDK developer seeder and is left for a separate change.
  • NPM_CONFIG_CACHE stays in the sandbox environment because the Anthropic Sandbox Runtime is still installed with npm in custom images.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

🤖 Generated with Claude Code

Edited by Alexander Chueshev

Merge request reports

Loading
Loading