Group-Level Protected Environments Do Not Support Invited Groups

Summary

While Project Level Protected Environments allow for assigning an invited group to a Protected Environment - the same does not appear to be the case for Group Level Protected Environments.

Attempts to protect an environment with an invited group using the Group-level Protected Environments API result in the following error being returned from the API:

{"message":["Deploy access levels is too short (minimum is 1 character)"]}

Steps to reproduce

Given: a top level group: top-level-group

  1. Create a Group: shared-groups/operators (group_id: 42)
  2. Share top-level-group with shared-groups/operators
  3. Attempt to use the Group-Level Protected Environments API for production and group_id: 42:
curl --header 'Content-Type: application/json' --request POST \
         --data '{"name": "production", "deploy_access_levels": [{"group_id": 42}]}' \
         --header "PRIVATE-TOKEN: <token>" \
         "https://gitlab.example/com/api/v4/groups/top-level-group/protected_environments"

Result:

{"message":["Deploy access levels is too short (minimum is 1 character)"]}

Project-Level Protected Environments can use invited groups

For Project-level Protected Environments, assigning an invited group is possible (and required as mentioned in the API documentation - it also will not work when a parent group of the project is shared with the with an external operators group).

Given: a top level group and project: top-level-group/test-project

  1. Create a Group: shared-groups/operators (group_id: 42)
  2. Share top-level-group/test-project with shared-groups/operators
  3. Use the Project-Level Protected Environments API for production and group_id: 42:
curl --header 'Content-Type: application/json' --request POST \
         --data '{"name": "production", "deploy_access_levels": [{"group_id": 42}]}' \
         --header "PRIVATE-TOKEN: <token>" \
         "https://gitlab.example/com/api/v4/projects/top-level-group%2Ftest-project/protected_environments"

Result:

{"name":"production","deploy_access_levels":[{"access_level":40,"access_level_description":"protected-access-group","user_id":null,"group_id":32}],"required_approval_count":0}

What is the current bug behavior?

Group-Level Protected Environments cannot be assigned to invited groups.

What is the expected correct behavior?

Group-Level Protected Environments, like Project-Level Protected Environments, should be able to be assigned to invited groups.

Edited by Jason Young