Remove QueryLimiting override in dependency-bump resolution PipelineFinishedEvent subscription

DependencyManagement::SecurityUpdate subscribes TriggerResolveDependencyBumpWorkflowWorker to Ci::PipelineFinishedEvent. Its if: condition (dependency_bump_mr_failure?) is evaluated synchronously during publish (e.g. inside POST /api/v4/jobs/request) and does a Ci::Pipeline.find_by_id, pushing that already-saturated endpoint from 100→101 queries over the Gitlab::QueryLimiting cap.

As a temporary measure (introduced in !243891 (merged)) we call Gitlab::QueryLimiting.disable!(..., new_threshold: 105) in the condition.

Why

The original plan here was to reduce the condition to status == 'failed' and move all the ref / feature-flag / author filtering into the async worker. That's rejected now.

status == 'failed' alone is not selective. It means a Sidekiq job gets enqueued for every failed pipeline on GitLab.com, not just dependency-bump ones. A reviewer flagged this on !246152 (merged): the excess jobs sit in the Redis buffer behind the worker's concurrency limit and can grow unbounded. The condition needs to stay selective. It just needs to stop querying the DB to do it.

Proper fix

Carry source_ref on the event payload so the condition can filter on it directly, with zero queries.

  1. Add source_ref to the schema in app/events/ci/pipeline_finished_event.rb as an optional property.
  2. Emit source_ref: pipeline.source_ref from the publisher in app/models/ci/pipeline.rb, in the after_transition any => Ci::Pipeline.completed_with_manual_statuses block.
  3. Update dependency_bump_mr_failure? to check event.data[:source_ref] for the dependency-management/ branch prefix first. Only pipelines that match go on to load the project and check Feature.enabled?(:enable_dependency_bump_breaking_changes, root_ancestor), which is the rare path.
  4. Remove the Gitlab::QueryLimiting.disable! override once the condition no longer queries.

Use source_ref, not ref. For a merge request pipeline created in the target project, Ci::Pipeline#ref is refs/merge-requests/:iid/head. For one created in a fork it's the plain source branch name. Only source_ref resolves both cases back to the dependency-bump branch name.

This is the same technique already used on this event: commit 039fbe1c363777 added source and partition_id to Ci::PipelineFinishedEvent so dependency_management_pipeline? could filter without a query. Follow the same rollout order documented in doc/development/eventstore/_index.md: add the property as optional and make the subscriber tolerate its absence first, then change the publisher to emit it.

Scope note: !246152 (merged) adds a second subscriber, TrackResolveDependencyBumpPipelineWorker, whose condition dependency_bump_mr_pipeline? has the same query-in-publish problem. That MR introduces the source_ref payload property and converts its own condition, with a fallback for pipelines published before the property existed. This issue covers:

  • Converting dependency_bump_mr_failure? to use source_ref.
  • Dropping the now-redundant fallback in dependency_bump_mr_pipeline? once the publisher change is fully deployed.
  • Removing the QueryLimiting.disable! override.

References

Edited by 🤖 GitLab Bot 🤖