Spike: Test, validate current workflow for creating/updating/removing policies and propose next steps to improve it to help customers manage policies
Time-window: 5 days
Description
The purpose of this Spike is to thoroughly investigate and validate the current workflow for creating, updating, and removing security policies in GitLab, with a focus on addressing the issues that arise when a security policy project is deleted. Our goal is to identify potential improvements that will enhance the user experience and prevent unintended consequences.
Tasks
- Document and test the current workflow for creating, updating, and removing security policies.
- Investigate the specific issue where policies cannot be edited or added once the security policy project is deleted.
- Analyze the impact of project deletion on linked security policies across groups and projects.
- Explore potential solutions, including but not limited to: a. Preventing the deletion of projects linked as Security Policy Projects (SPP). b. Implementing a warning system that lists affected groups/projects before deletion. c. Requiring users to unlink projects before deletion. d. Automatically unlinking projects when deleted (considering compliance implications).
- Assess the feasibility of implementing a "lock" feature for security policy projects to prevent accidental deletion.
- Investigate how to handle policy management when removing groups that contain security policy projects.
- Consider the implications of these changes on API, UI, and group removal processes.
- Evaluate the need for a feature flag implementation for any proposed solutions.
- Propose a step-by-step plan for implementing the most viable solution(s), considering the current roadmap and priorities.
Expected Outcome
A comprehensive report detailing the current workflow, identified issues, proposed solutions, and a recommended implementation plan to improve the management of security policies in GitLab. This report should balance user flexibility with compliance and security considerations.
Edited by Alan (Maciej) Paruszewski