Add application settings for the MCP Server rate limit
What does this MR do and why?
Adds the application settings for an MCP Server request rate limit:
throttle_authenticated_mcp_enabledthrottle_authenticated_mcp_requests_per_periodthrottle_authenticated_mcp_period_in_seconds
This follows the shape throttle_authenticated_git_http already uses. A Labkit rate limit rule reads its limit and period from a Gitlab::Throttle options proc over these settings, resolved per check, so an administrator can change the values without a deploy.
Nothing enforces the limit yet:
Registering the throttle requires a matching ThrottleRegistry entry, because a spec asserts the registry covers every throttle in all_throttle_definitions, so registration lands with the rule itself in !257035 (merged), along with the rate_limit_mcp_server feature flag that gates it on GitLab.com. The throttle ships disabled, as every other request throttle does.
References
Part of #629883 (closed), under gitlab-org#22800.
Why these settings and not a bespoke key
A Labkit rule takes its limit and period from Gitlab::RackAttack.all_throttle_definitions, which builds them from Gitlab::Throttle procs over application settings. Using the standard throttle shape rather than a bespoke setting is what makes the value changeable at runtime, and it brings the settings API entries and the admin Network page with it rather than requiring both to be built by hand.
The defaults are inlined rather than defined as constants: 41 of the 50 entries in rate_limits_definition inline theirs, each value is used once, and the Grape description has to repeat the literal anyway.
Screenshots or screen recordings
No UI changes. The admin settings page for these values is #629884.
How to set up and validate locally
-
In
rails console, confirm the defaults are present and disabled:s = ApplicationSetting.current [s.throttle_authenticated_mcp_enabled, s.throttle_authenticated_mcp_requests_per_period, s.throttle_authenticated_mcp_period_in_seconds] # => [false, 600, 60] -
Confirm the options proc reads them:
o = Gitlab::Throttle.mcp_options [o[:limit].call, o[:period].call] # => [600, 60] s.update!(throttle_authenticated_mcp_requests_per_period: 120) Gitlab::Throttle.mcp_options[:limit].call # => 120, no restart -
Confirm the settings API accepts and returns them:
curl --request PUT --header "PRIVATE-TOKEN: <admin token>" \ "http://gdk.test:3000/api/v4/application/settings?throttle_authenticated_mcp_requests_per_period=120" -
Confirm the schema rejects an out-of-range value:
s.update(throttle_authenticated_mcp_period_in_seconds: 0) # => false, schema requires minimum 1
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.