Track dependency firewall policy rule changes via InternalEvents
What does this MR do and why?
Emits the dependency_firewall_policy_rule_changed InternalEvent (Snowplow) once per rule change whenever a dependency firewall policy is created, updated, or deleted via policy.yml.
Event details
| Field | Value |
|---|---|
| Event name | dependency_firewall_policy_rule_changed |
label |
Action: create, update, or delete |
property |
Rule type: license or vulnerability |
value |
Enforcement: 1 (enforced/block), 0 (warn) |
Implementation
Tracking is added to PersistPolicyService#execute, mirroring the existing track_approval_policy_feature_usage pattern. The three collections computed by policy_configuration.policy_changes determine what fired:
- Created policies → one
createevent per rule - Updated policies → events per
RulesDiff.created/updated/deleted - Deleted policies → one
deleteevent per rule
The dependency_firewall_phase1 feature flag already gates the whole DF policy flow, so no separate rollout flag is needed.
Testing
Full test coverage in persist_policy_service_spec.rb covering:
- Create path (enforced + warn enforcement)
- Update path (add rule, update rule content, remove rule, enforcement flip)
- Delete path (whole policy deleted)
- Isolation (no events for other policy types)
Known gap: A no-op test (unchanged policy fires no events) is not reliably achievable because build(:dependency_firewall_policy, ...) includes :policy_scope in its checksum hash but the DB JSON schema disallows that field, so checksums always diverge and the policy always appears as changed. The isolation context already covers the "non-DF policy fires no events" case.
MR acceptance checklist
- Changelog trailers added to relevant commits (
Changelog: added,EE: true) - Tests added and passing (77 examples, 0 failures)
- RuboCop clean
- Event definition under
ee/config/events/(EE-only) -
introduced_by_urlupdated in event YAML - Analytics Instrumentation review (auto-requested by Danger)
References
Related parent: https://gitlab.com/groups/gitlab-org/-/work_items/5133