Create, Edit, and Delete for Policy Management
<!-- The first four sections: "Problem to solve", "Intended users", "User experience goal", and "Proposal", are strongly recommended, while the rest of the sections can be filled out during the problem validation or breakdown phase. However, keep in mind that providing complete and relevant information early helps our product team validate the problem and start working on a solution. --> ### Problem to solve <!-- What problem do we solve? Try to define the who/what/why of the opportunity as a user story. For example, "As a (who), I want (what), so I can (why/value)." --> As a security analyst, I want to be able to view, create, edit, and delete my policies directly in GitLab UI, so that I can keep my policies organized in a more visual way than what is possible in a text-based configuration file. ### Intended users <!-- Who will use this feature? If known, include any of the following: types of users (e.g. Developer), personas, or specific company roles (e.g. Release Manager). It's okay to write "Unknown" and fill this field in later. Personas are described at https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/ * [Cameron (Compliance Manager)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#cameron-compliance-manager) * [Parker (Product Manager)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#parker-product-manager) * [Delaney (Development Team Lead)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#delaney-development-team-lead) * [Presley (Product Designer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#presley-product-designer) * [Sasha (Software Developer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sasha-software-developer) * [Devon (DevOps Engineer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#devon-devops-engineer) * [Sidney (Systems Administrator)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sidney-systems-administrator) * [Sam (Security Analyst)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sam-security-analyst) * [Rachel (Release Manager)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#rachel-release-manager) * [Alex (Security Operations Engineer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#alex-security-operations-engineer) * [Simone (Software Engineer in Test)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#simone-software-engineer-in-test) * [Allison (Application Ops)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#allison-application-ops) * [Priyanka (Platform Engineer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#priyanka-platform-engineer) * [Dana (Data Analyst)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#dana-data-analyst) --> * [Sam (Security Analyst)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#sam-security-analyst) * [Alex (Security Operations Engineer)](https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/#alex-security-operations-engineer) ### User experience goal <!-- What is the single user experience workflow this problem addresses? For example, "The user should be able to use the UI/API/.gitlab-ci.yml with GitLab to <perform a specific task>" https://about.gitlab.com/handbook/engineering/ux/ux-research-training/user-story-mapping/ --> The user will be able to use the GitLab UI to create, edit, and delete their Policies. ### Proposal <!-- How are we going to solve the problem? Try to include the user journey! https://about.gitlab.com/handbook/journeys/#user-journey --> Although the long-term plan is for Policy management to include a wide range of policies (ModSecurity, Falco, Secure Scanners, etc.), for now we will continue to focus only on Cilium Network Policies. * Users will be able to create new policies * Users will be able to edit existing policies and save their changes to those policies * Users will be able to delete existing policies **Stretch Goal** * Users will have a visual way of editing Cilium L3 and L4 policies, except for service-type and DNS-type policies. ### Experience #### Creating a new policy | Policy tab | First run - New policy (rule mode) | First run - New policy (yaml mode) | Inputs - (rule mode) | | ------ | ------ | ------ | ------ | | ![a1_Policy_Tab](/uploads/7a169da2ed6eccab4681c85f5c7755dc/a1_Policy_Tab.png) | ![a2-1_New-policy_syntax-process_first-run](/uploads/efa72427b893e0bcca332ee0195e0443/a2-1_New-policy_syntax-process_first-run.png) | ![a4_New-policy_syntax-process_yaml_mode](/uploads/191f3b031e5620003e9b5662ac25ebb7/a4_New-policy_syntax-process_yaml_mode.png) | ![a2_New-policy_syntax-process](/uploads/897501b191992d5846d7bf0eccf114b6/a2_New-policy_syntax-process.png) | #### Editing an existing policy | Policy tab - policy selected | Editing a policy (rule mode) | Editing a policy - rule preview | Editing a policy - (yaml mode) | | ------ | ------ | ------ | ------ | | ![b1_Policy_Tab_-_policy_selected](/uploads/7a8d0537a1234fbced9aa923f51fd8d3/b1_Policy_Tab_-_policy_selected.png) | ![b2_Edit-policy_syntax-process](/uploads/4887b8563a19f206e0e4df1a602bda7c/b2_Edit-policy_syntax-process.png) | ![b2-1_Edit-policy_syntax-process_rule-preview](/uploads/f6d3c0f115be91ecdddc18d4496b8f4a/b2-1_Edit-policy_syntax-process_rule-preview.png) | ![b3_Edit-policy_syntax-process_yaml_mode](/uploads/815317e188088f06c9fa2456ae2e7cd9/b3_Edit-policy_syntax-process_yaml_mode.png) | #### Edge cases and errors | Deleting a policy | Rule mode validation | Cannot parse yaml file | | ---- | ------ | ------ | | ![b4_Edit-policy_syntax-process_deleting-a-policy](/uploads/44e7520c3956c432b5111fb93df0b275/b4_Edit-policy_syntax-process_deleting-a-policy.png) | ![a3_New-policy_syntax-process_validation](/uploads/4e7dee8b385a74669713815e47aaf259/a3_New-policy_syntax-process_validation.png) | ![c1_Edit-policy_syntax-process_yaml_mode-cannot-parse-yaml](/uploads/c3a2b6867bfb9efbb2252121a9ca7c8d/c1_Edit-policy_syntax-process_yaml_mode-cannot-parse-yaml.png) | ### Further details <!-- Include use cases, benefits, goals, or any other details that will help us understand the problem better. --> This is a minimal step toward a longer-term policy management solution. We are not planning to enforce a two-step approval process for policy changes at this time. ### Permissions and Security <!-- What permissions are required to perform the described actions? Are they consistent with the existing permissions as documented for users, groups, and projects as appropriate? Is the proposed behavior consistent between the UI, API, and other access methods (e.g. email replies)?--> Users must be a `Maintainer` or `Owner` on the project to create, edit, or delete policies. ### Documentation <!-- See the Feature Change Documentation Workflow https://docs.gitlab.com/ee/development/documentation/workflow.html#for-a-product-change * Add all known Documentation Requirements in this section. See https://docs.gitlab.com/ee/development/documentation/feature-change-workflow.html#documentation-requirements * If this feature requires changing permissions, update the permissions document. See https://docs.gitlab.com/ee/user/permissions.html --> Documentation will be updated with instructions on how to create, edit, and delete policies. ### Availability & Testing <!-- This section needs to be retained and filled in during the workflow planning breakdown phase of this feature proposal, if not earlier. What risks does this change pose to our availability? How might it affect the quality of the product? What additional test coverage or changes to tests will be needed? Will it require cross-browser testing? Please list the test areas (unit, integration and end-to-end) that needs to be added or updated to ensure that this feature will work as intended. Please use the list below as guidance. * Unit test changes * Integration test changes * End-to-end test change See the test engineering planning process and reach out to your counterpart Software Engineer in Test for assistance: https://about.gitlab.com/handbook/engineering/quality/test-engineering/#test-planning --> ### What does success look like, and how can we measure that? <!-- Define both the success metrics and acceptance criteria. Note that success metrics indicate the desired business outcomes, while acceptance criteria indicate when the solution is working correctly. If there is no way to measure success, link to an issue that will implement a way to measure this. --> ### What is the type of buyer? <!-- What is the buyer persona for this feature? See https://about.gitlab.com/handbook/marketing/product-marketing/roles-personas/buyer-persona/ In which enterprise tier should this feature go? See https://about.gitlab.com/handbook/product/pricing/#four-tiers --> ~"GitLab Ultimate" ### Is this a cross-stage feature? <!-- Communicate if this change will affect multiple Stage Groups or product areas. We recommend always start with the assumption that a feature request will have an impact into another Group. Loop in the most relevant PM and Product Designer from that Group to provide strategic support to help align the Group's broader plan and vision, as well as to avoid UX and technical debt. https://about.gitlab.com/handbook/product/#cross-stage-features --> ### Links / references https://gitlab.com/groups/gitlab-org/-/epics/3328 ### Release notes This improvement to the Container Network Policy editor allows users to easily create, edit, and delete their policies from directly within the GitLab UI. The editor's capabilities include a `.yaml` mode for experienced users and an intuitive rules editor UI for users new to Network Policies. You can find the new policy management capabilities at **Security & Compliance > Threat Management > Policies**.
epic