Loading
Allow security bot to access components from internal projects
What does this MR do and why?
Fixes #603881
When a pipeline execution policy includes a CI/CD component hosted in an internal project, the security policy bot is denied access because the component resolution path does not consult the bot-access setting (allows_pipeline_execution_policy_ci_config_access?).
How to set up and validate locally
Prerequisites
-
Create an internal project to host the CI/CD component (e.g.,
my-group/component-project)- Set visibility to Internal
- Create a component file at
templates/my-component.yml:spec: inputs: stage: default: test --- component-job: stage: $[[ inputs.stage ]] script: - echo "Running component job" - Create a tag (e.g.,
1.0.0) for the component version
-
Create a security policy project (e.g.,
my-group/security-policies)- Create a pipeline execution policy that references your component:
# .gitlab/security-policies/policy.yml pipeline_execution_policy: - name: "Component Policy" enabled: true pipeline_config_strategy: inject_ci content: include: - project: my-group/security-policies file: policy-ci.yml - Create
policy-ci.ymlin the security policy project:include: - component: gitlab.example.com/my-group/component-project/my-component@1.0.0
- Create a pipeline execution policy that references your component:
-
Create a target project (e.g.,
my-group/target-project)- Link the security policy project to this project
- Create a simple
.gitlab-ci.yml:test-job: script: - echo "Test"
-
Enable bot access on the component project
- Go to
component-project→ Settings → General → Security policy bot access - Enable the setting
- Add file pattern:
templates/**/*.yml - Set allowed group to your root group
- Go to
Before this MR (reproduce the bug)
- Go to
target-project→ Secure → Policies - Find the "Component Policy" and use the Test run feature to trigger the pipeline
- The test run fails with error:
Component 'gitlab.example.com/my-group/component-project/my-component@1.0.0' - project is `Internal`, it cannot be accessed by an External User
After this MR (verify the fix)
- Go to
target-project→ Secure → Policies - Find the "Component Policy" and use the Test run feature to trigger the pipeline
- The test run succeeds and includes the component job
- The security policy bot can access the component because the bot-access setting is now consulted
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.