Let the policy store own a policy by organization alone

What does this MR do and why?

Follows the schema change in !249126 (merged), which made govern_policies.namespace_id nullable so a governance policy can be owned by an organization rather than by a top-level group.

Gitlab::PolicyStore is still stricter than the column it models, so it rejects the row that change exists to allow. This drops namespace_id from Ports::PolicyRepository::REQUIRED_ATTRIBUTES and gives it a nil default on the Policy value object. The attribute stays, since both ownership forms are valid, and nothing that passes a namespace today changes behaviour.

Gem-only, matching !249126. Govern::Policy keeps belongs_to :namespace, optional: false and is relaxed separately in the stack behind it.

How to set up and validate locally

  1. On the rails console, create an organization-owned policy and verify it is accepted rather than raising
Gitlab::PolicyStore.create(
  organization_id: 1,
  name: 'Organization owned',
  trigger_type: 'merge_request'
)
  1. Verify the returned policy has namespace_id of nil and organization_id of 1. Before this change the same call raised Gitlab::PolicyStore::ValidationError with Missing required attributes: namespace_id
  2. Create a group-owned policy and verify the namespace still round-trips
Gitlab::PolicyStore.create(
  organization_id: 1,
  namespace_id: Group.first.id,
  name: 'Group owned',
  trigger_type: 'merge_request'
).namespace_id

References

Edited by Marcos Rocha

Merge request reports

Loading
Loading