Draft: Withdraw the Policy Store calendar rule until it can compile

What does this MR do and why?

The Policy Store catalogues (Gitlab::PolicyStore::Rules::ALL in the gitlab-policy-store gem, mirrored by the editor drawer) advertised a calendar (Freeze Window) rule, but the rule transpiler has no emitter for it. Every policy authored with one was accepted by the wizard and then rejected on save with rule 0: unsupported rule type "calendar", so the rule could never produce a saved policy.

This MR withdraws the type from both catalogues until the emitter lands:

  • The gem's catalogue drops calendar, so the create and update endpoints now refuse it at parameter validation (rules[0][type] does not have a valid value) like any other uncatalogued type.
  • The editor drawer no longer offers the Freeze Window card.
  • The transpiler keeps its clean refusal for payloads that still carry the type, and a gem spec now pins that the catalogue and the transpiler agree exactly, so a type cannot be catalogued again without an emitter.
  • The API docs drop the withdrawn type.

No stored policies can hold a calendar rule, because storing one was never possible.

References

Found while triaging the Policy Store experiment on staging (policies could not be created from the wizard). No tracked issue yet.

Screenshots or screen recordings

Before After
mr2_before_drawer mr2_after_drawer

Before: the rule drawer offered Freeze Window, which could never save. After: the drawer offers Custom Rule (Rego) and Environment State.

How to set up and validate locally

  1. Enable the experiment in a Rails console:

    Feature.enable(:security_policies_v2)
    ApplicationSetting.current.update!(policy_store_experiment_enabled: true)
    group = Group.find_by_full_path('<your-root-group>')
    group.namespace_settings.update!(policy_store_experiment_enabled: true)
  2. Check the rule catalogue no longer offers the type:

    curl --header "PRIVATE-TOKEN: <token>" "http://gdk.test:3000/api/v4/security/policy_store/rules"

    The response lists only custom and environment.

  3. Check the write endpoints refuse it at parameter validation:

    curl --request POST --header "PRIVATE-TOKEN: <admin-token>" --header "Content-Type: application/json" \
      --data '{"name":"cal","trigger_type":"deployment_requested","rules":[{"type":"calendar","value":{"timezone":"UTC"}}]}' \
      "http://gdk.test:3000/api/v4/organizations/1/security/policy_store"

    The response is 400 with rules[0][type] does not have a valid value (previously a 400 from the transpiler after the store was reached).

  4. As an authorized user, open Secure > Policy store > Create new policy on the opted-in group, open the Rules tab, and confirm the drawer offers only Custom Rule (Rego) and Environment State.

Edited by Dominic Bauer

Merge request reports

Loading
Loading