Loading
Persist source ref protection on flow workloads
What does this MR do and why?
Workload pipelines run on an internal refs/workloads/* ref, so Ci::Pipeline#protected_ref? was always false for them and protected CI/CD variables could never reach a flow.
Ci::Workloads::WorkloadBranchServicereports whether the source ref is protected.Ci::Workloads::RunWorkloadServicestores it on the workload (protected_ref, column from MR 1).Ci::Pipeline#protected_ref?uses the stored value for workload-sourced pipelines.Ai::DuoWorkflows::StartWorkflowServicepasses it through.
No extra variables are exposed yet: StartWorkflowService requests no CI/CD variables, and flow triggers keep the default false.
Database: one extra single-row query for workload-sourced pipelines, memoized, on p_ci_workloads_pipeline_id_idx (pipeline_id, partition_id):
SELECT "p_ci_workloads".* FROM "p_ci_workloads"
WHERE "p_ci_workloads"."pipeline_id" = 2809347353 AND "p_ci_workloads"."partition_id" = 105 LIMIT 1;The existing workload INSERT gains the protected_ref boolean column.
References
| # | Merge request | Base |
|---|---|---|
| 1 | !254470 (merged) Add columns (merged) | master |
| 2 | !254471 (merged) Parse variables in agent-config.yml (merged) |
master |
| 3 | !254472 Persist source ref protection | master |
| 4a | !254473 Expose allowed_in_workloads on APIs |
1 |
| 4b | !254474 Settings checkbox | 4a |
| 5 | !252729 Gate workload variables (feature becomes active) | 3, needs 2 |
Screenshots or screen recordings
Not applicable: no UI.
How to set up and validate locally
- In a project, protect a branch
release(Settings > Repository > Protected branches). - Start a flow from
release(for example from the Duo Agentic Chat with that branch checked out, or withsource_branch: releaseon the start API). - In a Rails console,
Ci::Workloads::Workload.lasthasprotected_ref: trueandCi::Workloads::Workload.last.pipeline.protected_ref?istrue. - Start a flow from an unprotected branch: both are
false. - A regular (non-flow) pipeline on
releasestill reportsprotected_ref?astrue.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Alper Akgun