Track dependency firewall policy rule changes via InternalEvents

What does this MR do and why?

Emits the dependency_firewall_policy_rule_changed InternalEvent (Snowplow) once per rule change whenever a dependency firewall policy is created, updated, or deleted via policy.yml.

Event details

Field Value
Event name dependency_firewall_policy_rule_changed
label Action: create, update, or delete
property Rule type: license or vulnerability
value Enforcement: 1 (enforced/block), 0 (warn)

Implementation

Tracking is added to PersistPolicyService#execute, mirroring the existing track_approval_policy_feature_usage pattern. The three collections computed by policy_configuration.policy_changes determine what fired:

  • Created policies → one create event per rule
  • Updated policies → events per RulesDiff.created/updated/deleted
  • Deleted policies → one delete event per rule

The dependency_firewall_phase1 feature flag already gates the whole DF policy flow, so no separate rollout flag is needed.

Testing

Full test coverage in persist_policy_service_spec.rb covering:

  • Create path (enforced + warn enforcement)
  • Update path (add rule, update rule content, remove rule, enforcement flip)
  • Delete path (whole policy deleted)
  • Isolation (no events for other policy types)

Known gap: A no-op test (unchanged policy fires no events) is not reliably achievable because build(:dependency_firewall_policy, ...) includes :policy_scope in its checksum hash but the DB JSON schema disallows that field, so checksums always diverge and the policy always appears as changed. The isolation context already covers the "non-DF policy fires no events" case.

MR acceptance checklist

  • Changelog trailers added to relevant commits (Changelog: added, EE: true)
  • Tests added and passing (77 examples, 0 failures)
  • RuboCop clean
  • Event definition under ee/config/events/ (EE-only)
  • introduced_by_url updated in event YAML
  • Analytics Instrumentation review (auto-requested by Danger)

References

Related parent: https://gitlab.com/groups/gitlab-org/-/work_items/5133

Edited by Michael Eddington

Merge request reports

Loading
Loading