Expose policyRego on the GovernPolicy GraphQL type
What does this MR do and why?
Adds a policyRego field to the GovernPolicy GraphQL type (ee/app/graphql/types/govern/policy_type.rb), experiment-flagged with milestone 19.4 like the type's other fields.
The field mirrors the REST entity API::Entities::Govern::Policy, which derives policy_rego from the policy's compiled rules via Gitlab::PolicyStore::RuleProgramMerger. The detail page renders this value as the "Compiled policy Rego" card, so this MR brings the same data to GraphQL consumers.
Failure behavior also mirrors REST: if the rules cannot be merged, the resolver tracks the exception with Gitlab::ErrorTracking (tagged with the policy id) and resolves the field to null rather than failing the whole query.
Covered by a resolver spec (ee/spec/graphql/types/govern/policy_type_spec.rb) and request-spec coverage (ee/spec/requests/api/graphql/organizations/policy_store_policies_spec.rb), plus the regenerated GraphQL reference docs and introspection result.
This MR was extracted from !252321 (merged) to separate the backend change from the frontend one. That MR, which migrates the single-policy read to GraphQL, is stacked on this branch and consumes the policyRego field.
References
Related to #617790
Screenshots or screen recordings
Not applicable — this is a backend-only GraphQL schema change with no UI impact.
How to set up and validate locally
- Enable the Policy Store experiment for the organization.
- Open GraphiQL at
/-/graphql-explorer. - Run the following query:
{
organization(id: "gid://gitlab/Organizations::Organization/1") {
policyStore {
policies {
id
name
policyRego
}
}
}
}- Confirm
policyRegoreturns the merged Rego program for policies with compiled rules, andnullfor policies whose rules cannot be merged.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.