Remove QueryLimiting override in dependency-bump resolution PipelineFinishedEvent subscription
DependencyManagement::SecurityUpdate subscribes TriggerResolveDependencyBumpWorkflowWorker to Ci::PipelineFinishedEvent. Its if: condition (dependency_bump_mr_failure?) is evaluated synchronously during publish (e.g. inside POST /api/v4/jobs/request) and does a Ci::Pipeline.find_by_id, pushing that already-saturated endpoint from 100→101 queries over the Gitlab::QueryLimiting cap.
As a temporary measure (introduced in !243891 (merged)) we call Gitlab::QueryLimiting.disable!(..., new_threshold: 105) in the condition.
Why
The original plan here was to reduce the condition to status == 'failed' and move all the ref / feature-flag / author filtering into the async worker. That's rejected now.
status == 'failed' alone is not selective. It means a Sidekiq job gets enqueued for every failed pipeline on GitLab.com, not just dependency-bump ones. A reviewer flagged this on !246152 (merged): the excess jobs sit in the Redis buffer behind the worker's concurrency limit and can grow unbounded. The condition needs to stay selective. It just needs to stop querying the DB to do it.
Proper fix
Carry source_ref on the event payload so the condition can filter on it directly, with zero queries.
- Add
source_refto the schema inapp/events/ci/pipeline_finished_event.rbas an optional property. - Emit
source_ref: pipeline.source_reffrom the publisher inapp/models/ci/pipeline.rb, in theafter_transition any => Ci::Pipeline.completed_with_manual_statusesblock. - Update
dependency_bump_mr_failure?to checkevent.data[:source_ref]for thedependency-management/branch prefix first. Only pipelines that match go on to load the project and checkFeature.enabled?(:enable_dependency_bump_breaking_changes, root_ancestor), which is the rare path. - Remove the
Gitlab::QueryLimiting.disable!override once the condition no longer queries.
Use source_ref, not ref. For a merge request pipeline created in the target project, Ci::Pipeline#ref is refs/merge-requests/:iid/head. For one created in a fork it's the plain source branch name. Only source_ref resolves both cases back to the dependency-bump branch name.
This is the same technique already used on this event: commit 039fbe1c363777 added source and partition_id to Ci::PipelineFinishedEvent so dependency_management_pipeline? could filter without a query. Follow the same rollout order documented in doc/development/eventstore/_index.md: add the property as optional and make the subscriber tolerate its absence first, then change the publisher to emit it.
Scope note: !246152 (merged) adds a second subscriber, TrackResolveDependencyBumpPipelineWorker, whose condition dependency_bump_mr_pipeline? has the same query-in-publish problem. That MR introduces the source_ref payload property and converts its own condition, with a fallback for pipelines published before the property existed. This issue covers:
- Converting
dependency_bump_mr_failure?to usesource_ref. - Dropping the now-redundant fallback in
dependency_bump_mr_pipeline?once the publisher change is fully deployed. - Removing the
QueryLimiting.disable!override.
References
- MR: !243891 (merged)
- MR: !246152 (merged)
- Filter:
ee/lib/gitlab/event_store/subscriptions/dependency_management_subscriptions.rb