Add GraphQL catalog queries for the policy store

What does this MR do and why?

This change adds a new Policy Store feature to GitLab's GraphQL API (introduced as an experimental feature in GitLab 19.4). It exposes a catalog of available building blocks — actions, rules, and triggers — that users can reference when creating security policies.

The catalog is accessible via both Groups and Organizations through a new policyStore field, but only when the policy store experiment is enabled (controlled by a feature flag at the group or instance level). If the experiment isn't active, the field returns null.

The change includes the necessary API type definitions, a resolver that checks whether the feature is enabled before returning data, and full test coverage for the new fields and their behavior.

Related to https://gitlab.com/gitlab-org/gitlab/-/work_items/613019.

References

Verification

  • Type specs: ee/spec/graphql/types/govern/policy_store_{trigger,rule,action,}type_spec.rb; request spec ee/spec/requests/api/graphql/govern/policy_store_catalogs_spec.rb covers both parents and every gating axis separately (flag, instance setting, license, group opt-in, non-root group) — judged by CI.
  • bundle exec rake gitlab:permissions:validate → GraphQL permissions are valid; RuboCop clean; pre-push hooks graphql_introspection_check, permissions-verify, and graphql_docs passed.
  • The catalog types override def id because BaseObject#id builds a GlobalID that plain hashes lack.
  • Adversarial review verdict on the initial (root-level) shape, verbatim: pass with findings; the follow-up commit moved the fields onto Group/Organization to fix the under-gating described above. Accepted findings: plain lists rather than connections, and String catalog ids rather than an enum (the catalog is data and will come from a remote store service later).

Screenshots or screen recordings

Description UI
New queries Screenshot 2026-08-18 at 13.58.33.png

How to set up and validate locally

  1. In rails console, activate the experiment (Ultimate license required):

    Feature.enable(:security_policies_v2)
    Gitlab::CurrentSettings.update!(policy_store_experiment_enabled: true)
  2. Validate the organization catalogs in GraphiQL (/-/graphql-explorer):

    { organization(id: "gid://gitlab/Organizations::Organization/1") { policyStore { triggers { id name } rules { id name } actions { id name } } } }
  3. For the group catalogs, also opt a root group in:

    Group.find_by_full_path('gitlab-org').namespace_settings.update!(policy_store_experiment_enabled: true)

    then query:

    { group(fullPath: "gitlab-org") { policyStore { triggers { id name } rules { id name } actions { id name } } } }
  4. Expect the static catalogs: the deployment_requested trigger; custom, calendar, and environment rules; block and require_approval actions.

  5. Expect policyStore to return null when the feature flag or instance setting is off, on non-root groups, and on root groups that have not opted in.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

Edited by Artur Fedorov

Merge request reports

Loading
Loading