Include CSP in the policy hierarchy
What does this MR do and why?
When a group is designated as a CSP group, it is included in the hierarchy of all_security_orchestration_policy_configurations.
This is the first step behind a feature flag to ensure that CSP policies are propagated to all groups and projects.
Feature flag can toggle this behavior for a specific group, or its the root ancestor group.
References
Screenshots or screen recordings
| Before (or with FF disabled) | After |
|---|---|
![]() |
![]() |
How to set up and validate locally
- In rails console enable the feature flag
Feature.enable(:security_policies_csp) - Create a top-level group and designate it as CSP:
Security::PolicySetting.instance.update! csp_namespace: Group.find(<group_id>) - In the group, create a few security policies
- Create another top-level group
- Visit
Secure -> Policiesand verify that CSP policies are shown as well
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Related to #541510 (closed)
Edited by Martin Cavoj

