Draft: ci: Use GIT_CONFIG_GLOBAL file for git auth so omnibus subprocesses pick it up
What does this MR do?
Problem
Omnibus-gitlab build jobs intermittently fail with:
fatal: remote error: GitLab is currently unable to handle this request due to loadThis happens during git clone https://gitlab.com/gitlab-org/gitlab.git (and similar) inside omnibus build jobs because Gitaly throttles unauthenticated clones aggressively (tracked in #9861 (closed)).
Why !9365 (merged) was insufficient
!9365 (merged) added GIT_CONFIG_COUNT / GIT_CONFIG_KEY_* / GIT_CONFIG_VALUE_* CI variables to inject a credential helper and proactiveAuth = basic into git. This works for git invocations that inherit the CI runner environment, but omnibus' Mixlib::ShellOut is configured with environment: {} (see omnibus util.rb), which wipes the parent environment before spawning git subprocesses. As a result the GIT_CONFIG_* variables never reach the git clones that omnibus performs during a build, so those clones remain unauthenticated and continue to be throttled.
Fix
Replace the env-var approach with a real git config file written to $GIT_CONFIG_GLOBAL (= /tmp/.gitconfig).
gitlab-ci-config/variables.yml: Remove the fiveGIT_CONFIG_*variables and addGIT_CONFIG_GLOBAL: '/tmp/.gitconfig'..gitlab-ci.ymlbefore_script: Materialise the file before any other step using a single-quoted heredoc so that${CI_JOB_TOKEN}is written literally into the file and evaluated by the credential-helper shell function at clone time (ensuring each job uses its own per-job token).
omnibus' util.rb always sets HOME=/tmp when HOME is unset, so every git subprocess it spawns will read /tmp/.gitconfig as $HOME/.gitconfig even after Mixlib wipes the environment. This approach is aligned with the parent tracking issue gitlab-org/gitlab#591939 (Centralize setting of proactiveAuth) which calls for using a file-based config rather than env vars.
Validation needed
Because the fix targets omnibus build subprocesses (not the runner's own git), it must be validated on dev.gitlab.org (where actual package builds run) and on the security mirror — the same requirement raised by reviewers of !9365 (merged). This MR is kept as a Draft until that validation is complete.
Related issues
- #9861 (closed) — recurring build failures due to unauthenticated git clones being throttled
- gitlab-org/gitlab#591939 — parent tracking issue: Centralize setting of proactiveAuth
- !9365 (merged) — prior attempt using
GIT_CONFIG_*env vars (insufficient because Mixlib wipes the env)
Checklist
See Definition of done.
For anything in this list which will not be completed, please provide a reason in the MR discussion.
Required
- MR title and description are up to date, accurate, and descriptive.
- MR targeting the appropriate branch.
- Latest Merge Result pipeline is green.
- When ready for review, MR is labeled workflowready for review per the Distribution MR workflow.
- The UBT version and corresponding checksum hash have been updated and referenced in the merge request if applicable.
- UBT EE pipeline (
Trigger:ee-package-ubt) is green
- UBT EE pipeline (
For GitLab team members
If you don't have access to this, the reviewer should trigger these jobs for you during the review process.
- The manual
Trigger:ee-packagejobs have a green pipeline running against latest commit.- To debug QA failures, refer to the Investigate QA failures section.
- If
config/softwareorconfig/patchesdirectories are changed, make sure thebuild-package-on-all-osjob within theTrigger:ee-packagedownstream pipeline succeeded. - If you are changing anything SSL related, then the
Trigger:package:fipsmanual job within theTrigger:ee-packagedownstream pipeline must succeed. - If CI configuration is changed, the branch must be pushed to
dev.gitlab.orgto confirm regular branch builds aren't broken.
Expected (please provide an explanation if not completing)
- Test plan indicating conditions for success has been posted and passes.
- Documentation created/updated.
- Tests added.
- Integration tests added to GitLab QA.
- Equivalent MR/issue for the GitLab Chart opened.
- Validate potential values for new configuration settings. Formats such as integer
10, duration10s, URIscheme[REDACTED]host:portmay require quotation or other special handling when rendered in a template and written to a configuration file.