Spike: Test, validate current workflow for creating/updating/removing policies and propose next steps to improve it to help customers manage policies

Time-window: 5 days

Description

The purpose of this Spike is to thoroughly investigate and validate the current workflow for creating, updating, and removing security policies in GitLab, with a focus on addressing the issues that arise when a security policy project is deleted. Our goal is to identify potential improvements that will enhance the user experience and prevent unintended consequences.

Tasks

  1. Document and test the current workflow for creating, updating, and removing security policies.
  2. Investigate the specific issue where policies cannot be edited or added once the security policy project is deleted.
  3. Analyze the impact of project deletion on linked security policies across groups and projects.
  4. Explore potential solutions, including but not limited to: a. Preventing the deletion of projects linked as Security Policy Projects (SPP). b. Implementing a warning system that lists affected groups/projects before deletion. c. Requiring users to unlink projects before deletion. d. Automatically unlinking projects when deleted (considering compliance implications).
  5. Assess the feasibility of implementing a "lock" feature for security policy projects to prevent accidental deletion.
  6. Investigate how to handle policy management when removing groups that contain security policy projects.
  7. Consider the implications of these changes on API, UI, and group removal processes.
  8. Evaluate the need for a feature flag implementation for any proposed solutions.
  9. Propose a step-by-step plan for implementing the most viable solution(s), considering the current roadmap and priorities.

Expected Outcome

A comprehensive report detailing the current workflow, identified issues, proposed solutions, and a recommended implementation plan to improve the management of security policies in GitLab. This report should balance user flexibility with compliance and security considerations.

Edited by Alan (Maciej) Paruszewski