Persist source ref protection on flow workloads

What does this MR do and why?

Workload pipelines run on an internal refs/workloads/* ref, so Ci::Pipeline#protected_ref? was always false for them and protected CI/CD variables could never reach a flow.

  • Ci::Workloads::WorkloadBranchService reports whether the source ref is protected.
  • Ci::Workloads::RunWorkloadService stores it on the workload (protected_ref, column from MR 1).
  • Ci::Pipeline#protected_ref? uses the stored value for workload-sourced pipelines.
  • Ai::DuoWorkflows::StartWorkflowService passes it through.

No extra variables are exposed yet: StartWorkflowService requests no CI/CD variables, and flow triggers keep the default false.

Database: one extra single-row query for workload-sourced pipelines, memoized, on p_ci_workloads_pipeline_id_idx (pipeline_id, partition_id):

SELECT "p_ci_workloads".* FROM "p_ci_workloads"
WHERE "p_ci_workloads"."pipeline_id" = 2809347353 AND "p_ci_workloads"."partition_id" = 105 LIMIT 1;

The existing workload INSERT gains the protected_ref boolean column.

References

  • Work item: #602887
  • Split of !252729 (the original, now the final MR):
# Merge request Base
1 !254470 (merged) Add columns (merged) master
2 !254471 (merged) Parse variables in agent-config.yml (merged) master
3 !254472 Persist source ref protection master
4a !254473 Expose allowed_in_workloads on APIs 1
4b !254474 Settings checkbox 4a
5 !252729 Gate workload variables (feature becomes active) 3, needs 2

Screenshots or screen recordings

Not applicable: no UI.

How to set up and validate locally

  1. In a project, protect a branch release (Settings > Repository > Protected branches).
  2. Start a flow from release (for example from the Duo Agentic Chat with that branch checked out, or with source_branch: release on the start API).
  3. In a Rails console, Ci::Workloads::Workload.last has protected_ref: true and Ci::Workloads::Workload.last.pipeline.protected_ref? is true.
  4. Start a flow from an unprotected branch: both are false.
  5. A regular (non-flow) pipeline on release still reports protected_ref? as true.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Alper Akgun

Merge request reports

Loading
Loading