Parse variables allowlist from agent-config.yml

What does this MR do and why?

Adds an optional variables key to .gitlab/duo/agent-config.yml: up to 50 unique CI/CD variable keys matching ^[a-zA-Z_][a-zA-Z0-9_]*$. Gitlab::DuoAgentPlatform::Config#variables returns them deduplicated as strings, or [].

The key is parsed only. It becomes the second gate for exposing CI/CD variables to flows in the final MR of the split, which also adds the documentation. No changelog: no user-facing change yet.

Pure parser addition with no callers, no flag needed, no user-visible change; MR 5 wires it up behind the feature gate.

References

  • Work item: #602887
  • Split of !252729 (the original, now the final MR):
# Merge request Base
1 !254470 (merged) Add columns master
2 !254471 (merged) Parse variables in agent-config.yml master
3 !254472 Persist source ref protection 1
4a !254473 Expose dap_workload_allowed on APIs 1
4b !254474 Settings checkbox 4a
5 !252729 Gate workload variables (feature becomes active) 3, needs 2

Screenshots or screen recordings

Not applicable: no UI.

How to set up and validate locally

  1. On a project's default branch, add to .gitlab/duo/agent-config.yml:

    variables:
      - MY_API_TOKEN
  2. Run a flow: it still starts, the key is ignored.

  3. In a Rails console, Gitlab::DuoAgentPlatform::Config.new(project).variables returns ["MY_API_TOKEN"].

  4. Change the entry to 1invalid, list MY_API_TOKEN twice, or add 51 entries: Gitlab::DuoAgentPlatform::Config.new(project).valid_format? is false, and starting a flow fails with Invalid config file.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Alper Akgun

Merge request reports

Loading
Loading