Add models and feature flag for AI Catalog group inheritance

What does this MR do and why?

Part of the AI Catalog group inheritance epic (#22487 (closed)): a group should be able to enable an agent or flow once so every project under it inherits that enablement, instead of enabling it per project.

This MR is the models step only (#627512 (closed)). It adds a kind enum (direct/inheritance) to Ai::Catalog::ItemConsumer, with validations that keep it sane: immutable after create, inheritance only allowed on a top-level group, inheritance records can't reference a private item, and group uniqueness is now scoped by kind so a group can hold one direct record and one inheritance record for the same item. Ai::FlowTrigger gets a group association (a trigger can now belong to a group instead of only a project), with a validation that a group-scoped trigger must belong to a matching inheritance consumer of that same group. Two lookup scopes, inherited_for_project and applicable_to_project, sit behind a new ai_catalog_group_inherited_consumers feature flag (off by default); the union between them uses remove_duplicates: false since a trigger can never have both project_id and group_id set (DB check constraint), so the two branches can't overlap.

References

#627512 (closed)

How to set up and validate locally

UI regression check (confirms existing enablement flow still works, since this MR has no new UI):

  1. Go to Explore > AI Catalog > Agents, open any agent.
  2. Click "Enable", pick a project, keep the default conditions, click "Enable".
  3. Confirm the createAiCatalogItemConsumerBulk mutation returns no errors, and reopening "Enable" shows that project as "Already enabled".

Database Queries

1. FlowTrigger.inherited_for_project

Query plan - https://console.postgres.ai/gitlab/projects/gitlab-production-main/sessions/57782/commands/162421

2. FlowTrigger.applicable_to_project

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Related to #627512 (closed)

Merge request reports

Loading
Loading