Loading
Draft: Add push_pipelines_for_job_token_allowed CI/CD setting
What does this MR do and why?
Add push_pipelines_for_job_token_allowed CI/CD setting.
Allow projects to opt in to push pipelines (both branch and tag pushes) triggered by a CI job token, independently of the default block introduced in !197418 (merged).
Originally scoped to tag pushes only, the approach was expanded to cover all push pipelines (branch and tag) based on feedback in #569974 (comment 3529584877).
Resolves #569974
References
Screenshots or screen recordings
| Before | After |
|---|---|
![]() |
How to set up and validate locally
Prerequisites
-
Run database migrations:
bundle exec rails db:migrate -
Enable the feature flag:
# In rails console Feature.enable(:pipelines_with_ci_job_token_push)
UI verification
- Navigate to a project's Settings > CI/CD > Job token permissions.
- Confirm the new checkbox "Allow push pipelines via a CI/CD job token" is visible.
- Check the new checkbox and click Save.
- Reload the page and confirm the checkbox state is persisted.
- Disable the feature flag (
Feature.disable(:pipelines_with_ci_job_token_push)) and confirm the checkbox is no longer rendered.
REST API verification
# Read the setting (replace :id and :token)
curl --header "PRIVATE-TOKEN: <token>" \
"https://gitlab.example.com/api/v4/projects/:id" | jq '.ci_push_pipelines_for_job_token_allowed'
# Enable the setting
curl --request PUT \
--header "PRIVATE-TOKEN: <token>" \
--header "Content-Type: application/json" \
--data '{"ci_push_pipelines_for_job_token_allowed": true}' \
"https://gitlab.example.com/api/v4/projects/:id"GraphQL verification
# Query current value
query {
project(fullPath: "namespace/project") {
ciCdSettings {
pushPipelinesForJobTokenAllowed
}
}
}
# Mutation to update
mutation {
projectCiCdSettingsUpdate(input: {
fullPath: "namespace/project"
pushPipelinesForJobTokenAllowed: true
}) {
ciCdSettings {
pushPipelinesForJobTokenAllowed
}
errors
}
}Pipeline behaviour verification
- In a CI job, push a branch or tag to the project using a job token:
# Tag push git tag v1.0.0-test git push origin v1.0.0-test # Branch push git push origin HEAD:some-branch - With the setting disabled: confirm the pipeline creation is blocked (check job log for
Pipeline creation blocked for CI job token push). - With the setting enabled: confirm a pipeline is triggered successfully for both branch and tag pushes.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Related to #569974
Edited by Aboobacker MK
