Expose policyRego on the GovernPolicy GraphQL type

What does this MR do and why?

Adds a policyRego field to the GovernPolicy GraphQL type (ee/app/graphql/types/govern/policy_type.rb), experiment-flagged with milestone 19.4 like the type's other fields.

The field mirrors the REST entity API::Entities::Govern::Policy, which derives policy_rego from the policy's compiled rules via Gitlab::PolicyStore::RuleProgramMerger. The detail page renders this value as the "Compiled policy Rego" card, so this MR brings the same data to GraphQL consumers.

Failure behavior also mirrors REST: if the rules cannot be merged, the resolver tracks the exception with Gitlab::ErrorTracking (tagged with the policy id) and resolves the field to null rather than failing the whole query.

Covered by a resolver spec (ee/spec/graphql/types/govern/policy_type_spec.rb) and request-spec coverage (ee/spec/requests/api/graphql/organizations/policy_store_policies_spec.rb), plus the regenerated GraphQL reference docs and introspection result.

This MR was extracted from !252321 (merged) to separate the backend change from the frontend one. That MR, which migrates the single-policy read to GraphQL, is stacked on this branch and consumes the policyRego field.

References

Related to #617790

Screenshots or screen recordings

Not applicable — this is a backend-only GraphQL schema change with no UI impact.

How to set up and validate locally

  1. Enable the Policy Store experiment for the organization.
  2. Open GraphiQL at /-/graphql-explorer.
  3. Run the following query:
{
  organization(id: "gid://gitlab/Organizations::Organization/1") {
    policyStore {
      policies {
        id
        name
        policyRego
      }
    }
  }
}
  1. Confirm policyRego returns the merged Rego program for policies with compiled rules, and null for policies whose rules cannot be merged.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading