Draft: ci: Use GIT_CONFIG_GLOBAL file for git auth so omnibus subprocesses pick it up

What does this MR do?

Problem

Omnibus-gitlab build jobs intermittently fail with:

fatal: remote error: GitLab is currently unable to handle this request due to load

This happens during git clone https://gitlab.com/gitlab-org/gitlab.git (and similar) inside omnibus build jobs because Gitaly throttles unauthenticated clones aggressively (tracked in #9861 (closed)).

Why !9365 (merged) was insufficient

!9365 (merged) added GIT_CONFIG_COUNT / GIT_CONFIG_KEY_* / GIT_CONFIG_VALUE_* CI variables to inject a credential helper and proactiveAuth = basic into git. This works for git invocations that inherit the CI runner environment, but omnibus' Mixlib::ShellOut is configured with environment: {} (see omnibus util.rb), which wipes the parent environment before spawning git subprocesses. As a result the GIT_CONFIG_* variables never reach the git clones that omnibus performs during a build, so those clones remain unauthenticated and continue to be throttled.

Fix

Replace the env-var approach with a real git config file written to $GIT_CONFIG_GLOBAL (= /tmp/.gitconfig).

  • gitlab-ci-config/variables.yml: Remove the five GIT_CONFIG_* variables and add GIT_CONFIG_GLOBAL: '/tmp/.gitconfig'.
  • .gitlab-ci.yml before_script: Materialise the file before any other step using a single-quoted heredoc so that ${CI_JOB_TOKEN} is written literally into the file and evaluated by the credential-helper shell function at clone time (ensuring each job uses its own per-job token).

omnibus' util.rb always sets HOME=/tmp when HOME is unset, so every git subprocess it spawns will read /tmp/.gitconfig as $HOME/.gitconfig even after Mixlib wipes the environment. This approach is aligned with the parent tracking issue gitlab-org/gitlab#591939 (Centralize setting of proactiveAuth) which calls for using a file-based config rather than env vars.

Validation needed

Because the fix targets omnibus build subprocesses (not the runner's own git), it must be validated on dev.gitlab.org (where actual package builds run) and on the security mirror — the same requirement raised by reviewers of !9365 (merged). This MR is kept as a Draft until that validation is complete.

  • #9861 (closed) — recurring build failures due to unauthenticated git clones being throttled
  • gitlab-org/gitlab#591939 — parent tracking issue: Centralize setting of proactiveAuth
  • !9365 (merged) — prior attempt using GIT_CONFIG_* env vars (insufficient because Mixlib wipes the env)

Checklist

See Definition of done.

For anything in this list which will not be completed, please provide a reason in the MR discussion.

Required

  • MR title and description are up to date, accurate, and descriptive.
  • MR targeting the appropriate branch.
  • Latest Merge Result pipeline is green.
  • When ready for review, MR is labeled workflowready for review per the Distribution MR workflow.
  • The UBT version and corresponding checksum hash have been updated and referenced in the merge request if applicable.
    • UBT EE pipeline (Trigger:ee-package-ubt) is green

For GitLab team members

If you don't have access to this, the reviewer should trigger these jobs for you during the review process.

  • The manual Trigger:ee-package jobs have a green pipeline running against latest commit.
  • If config/software or config/patches directories are changed, make sure the build-package-on-all-os job within the Trigger:ee-package downstream pipeline succeeded.
  • If you are changing anything SSL related, then the Trigger:package:fips manual job within the Trigger:ee-package downstream pipeline must succeed.
  • If CI configuration is changed, the branch must be pushed to dev.gitlab.org to confirm regular branch builds aren't broken.

Expected (please provide an explanation if not completing)

  • Test plan indicating conditions for success has been posted and passes.
  • Documentation created/updated.
  • Tests added.
  • Integration tests added to GitLab QA.
  • Equivalent MR/issue for the GitLab Chart opened.
  • Validate potential values for new configuration settings. Formats such as integer 10, duration 10s, URI scheme[REDACTED]host:port may require quotation or other special handling when rendered in a template and written to a configuration file.

Merge request reports

Loading