Group-Level Protected Environments Do Not Support Invited Groups
Summary
While Project Level Protected Environments allow for assigning an invited group to a Protected Environment - the same does not appear to be the case for Group Level Protected Environments.
Attempts to protect an environment with an invited group using the Group-level Protected Environments API result in the following error being returned from the API:
{"message":["Deploy access levels is too short (minimum is 1 character)"]}Steps to reproduce
Given: a top level group: top-level-group
- Create a Group:
shared-groups/operators(group_id:42) - Share
top-level-groupwithshared-groups/operators - Attempt to use the Group-Level Protected Environments API for
productionandgroup_id: 42:
curl --header 'Content-Type: application/json' --request POST \
--data '{"name": "production", "deploy_access_levels": [{"group_id": 42}]}' \
--header "PRIVATE-TOKEN: <token>" \
"https://gitlab.example/com/api/v4/groups/top-level-group/protected_environments"Result:
{"message":["Deploy access levels is too short (minimum is 1 character)"]}Project-Level Protected Environments can use invited groups
For Project-level Protected Environments, assigning an invited group is possible (and required as mentioned in the API documentation - it also will not work when a parent group of the project is shared with the with an external operators group).
Given: a top level group and project: top-level-group/test-project
- Create a Group:
shared-groups/operators(group_id:42) - Share
top-level-group/test-projectwithshared-groups/operators - Use the Project-Level Protected Environments API for
productionandgroup_id: 42:
curl --header 'Content-Type: application/json' --request POST \
--data '{"name": "production", "deploy_access_levels": [{"group_id": 42}]}' \
--header "PRIVATE-TOKEN: <token>" \
"https://gitlab.example/com/api/v4/projects/top-level-group%2Ftest-project/protected_environments"Result:
{"name":"production","deploy_access_levels":[{"access_level":40,"access_level_description":"protected-access-group","user_id":null,"group_id":32}],"required_approval_count":0}What is the current bug behavior?
Group-Level Protected Environments cannot be assigned to invited groups.
What is the expected correct behavior?
Group-Level Protected Environments, like Project-Level Protected Environments, should be able to be assigned to invited groups.