I think this is a real strategic challenge for Gitlab; I think the answer is "the features never stop", and that is OK, as long as you understand their target customer/market.
I first started thinking hard about this when they recently cancelled their bronze tier subscription. Gitlab is clearly ducking out of a brawl with Github for the individual/consumer $5/month tier; that makes sense as there is no way Gitlab can win by taking on the incumbent on their own turf. Instead Gitlab seems to be shifting focus to targeting larger enterprise customers; those who are fine paying $20/mo or ideally $100/mo for a one-stop solution to the full SDLC. (The counterargument here would be that they _are_ still targeting the $5/mo customer, they are just trying to replace a $5/mo Github subscription plus a $10/mo CircleCI sub plus a $10/mo Jira sub etc. -- I'm not sure I see that end of the userbase being as amenable to bundling though).
The largest enterprise customers will keep asking for more boxes to be ticked, because it's usually easier to add features onto your existing solution than to stitch multiple solutions together, and because the more features/config options you have, the more complex configurations/requirements you can satisfy. However that means you get feature bloat, and pricing becomes more challenging; you need to charge more for "all the features" tier, but as you broaden the offering, fewer customers actually want to pay for everything. "What do we keep in the $100/mo tier?" is a challenging question to get right as the feature-set grows.
As you get into enterprise sales, you start to need more customization/unbundling. Before I moved back to Github I paid Gitlab $20/mo per engineer on my team and would never dream of jumping up to $100/mo, but would absolutely have paid more for a la carte access to certain features from the $100/mo ultimate tier. (For example I have no interest in their issue tracker, but I'd love to have been able to use their DevOps / Kubernetes tooling).
I believe this sort of a la carte pricing is less developer-friendly because you tend to need to talk to a sales person vs. just having the developer sign up, but then I don't believe that "developer first" is your sales strategy in enterprise; see Okta vs. Auth0 for a good example:
https://auth0.com/pricing/
https://www.okta.com/pricing/#customer-identity-products
Auth0 keeps it as simple as possible. Even within customer-identity (their competitor to Auth0) Okta has way more configuration for add-ons like MFA, SSO etc.
(I know @sytse / Gitlab folks post on here regularly so I'd love to hear their feedback on whether I'm completely off-base in how I'm thinking about this stuff!)