Allow security bot to access components from internal projects

What does this MR do and why?

Fixes #603881

When a pipeline execution policy includes a CI/CD component hosted in an internal project, the security policy bot is denied access because the component resolution path does not consult the bot-access setting (allows_pipeline_execution_policy_ci_config_access?).

How to set up and validate locally

Prerequisites

  1. Create an internal project to host the CI/CD component (e.g., my-group/component-project)

    • Set visibility to Internal
    • Create a component file at templates/my-component.yml:
      spec:
        inputs:
          stage:
            default: test
      ---
      component-job:
        stage: $[[ inputs.stage ]]
        script:
          - echo "Running component job"
    • Create a tag (e.g., 1.0.0) for the component version
  2. Create a security policy project (e.g., my-group/security-policies)

    • Create a pipeline execution policy that references your component:
      # .gitlab/security-policies/policy.yml
      pipeline_execution_policy:
        - name: "Component Policy"
          enabled: true
          pipeline_config_strategy: inject_ci
          content:
            include:
              - project: my-group/security-policies
                file: policy-ci.yml
    • Create policy-ci.yml in the security policy project:
      include:
        - component: gitlab.example.com/my-group/component-project/my-component@1.0.0
  3. Create a target project (e.g., my-group/target-project)

    • Link the security policy project to this project
    • Create a simple .gitlab-ci.yml:
      test-job:
        script:
          - echo "Test"
  4. Enable bot access on the component project

    • Go to component-project → Settings → General → Security policy bot access
    • Enable the setting
    • Add file pattern: templates/**/*.yml
    • Set allowed group to your root group

Before this MR (reproduce the bug)

  1. Go to target-project → Secure → Policies
  2. Find the "Component Policy" and use the Test run feature to trigger the pipeline
  3. The test run fails with error:
    Component 'gitlab.example.com/my-group/component-project/my-component@1.0.0' - 
    project is `Internal`, it cannot be accessed by an External User

After this MR (verify the fix)

  1. Go to target-project → Secure → Policies
  2. Find the "Component Policy" and use the Test run feature to trigger the pipeline
  3. The test run succeeds and includes the component job
  4. The security policy bot can access the component because the bot-access setting is now consulted

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading