Allow manually running imported jobs from the Builds page without code read permission #3173
kobe opened 11 hours ago

Type: Enhancement
Affected Version: 16.8.6
Priority: Normal

Problem

We use a centralized project to maintain reusable CI/CD jobs, which are imported into multiple application projects through .onedev-buildspec.yml.

However, imported jobs cannot be manually executed from the project's Builds page. Attempting to run them results in a "Job not found" error.

These jobs are available and can be executed from Code → Files or Code → Commits.

Use Case

Our development workflow separates developers and testers:

  • Developers have code read access and can manage CI/CD configurations.
  • Testers only have permissions to view and execute builds, along with managing issues.
  • Testers do not have code read permission for security reasons.
  • CI/CD jobs are centrally maintained and imported by application projects.

Currently, testers cannot manually trigger imported build jobs from the Builds page.

As a workaround, we must either:

  1. Let testers use artifacts generated by automatically triggered builds.
  2. Duplicate the same job definition in every application project.

The second option defeats the purpose of centralized CI/CD job management and introduces unnecessary maintenance overhead.

Expected Behavior

  1. The Builds page should recognize all available jobs, including those imported from other projects.
  2. Users with build execution permission should be able to manually run imported jobs without requiring code read permission.
  3. Imported jobs should behave the same as locally defined jobs when manually triggered.
  4. Job visibility and execution should respect the existing build permissions without exposing source code or sensitive CI/CD configurations.

Actual Behavior

  • Imported jobs work from Code → Files / Commits.
  • Imported jobs cannot be manually started from Builds.
  • The interface reports "Job not found".
  • Testers without code read permission cannot access the alternative execution entry points.

Suggested Improvement

Please allow the Builds page to discover and execute imported jobs based on the selected branch or commit, while maintaining the existing permission model.

This would make centralized CI/CD job management practical for teams that separate development and testing responsibilities.

  • kobe commented 11 hours ago

    Additional Suggestion: Two-Level Job Import Configuration

    It would be even better if OneDev could support customizable job import rules at two levels:

    1. Global Configuration (Shared CI/CD Template)

    Allow the shared CI/CD template to define which jobs are available or enabled for import by default.

    Support three modes:

    • All – Include all jobs.
    • Include Only – Include only selected jobs.
    • Exclude – Include all jobs except selected jobs.

    This would allow administrators to centrally manage default job import policies across projects.

    2. Project-Level Configuration (Individual Projects)

    Allow each application project to customize which jobs it imports from the shared template.

    Support the same three modes:

    • All – Import all available jobs.
    • Include Only – Import specific jobs.
    • Exclude – Import all except specified jobs.

    Additionally, provide an Inherit Default option to follow the global configuration.

    Expected Behavior

    • Global settings provide centralized default import rules.
    • Project-level settings allow each project to customize its imported jobs.
    • Project-level overrides should take precedence over global defaults, within the jobs permitted by the shared template.
    • Changes to the shared template should automatically propagate to projects inheriting its configuration.
    • Only jobs selected for import should appear in the project's available job list and manual build execution options.

    Example

    A shared CI/CD template contains:

    • Backend Build
    • Frontend Build
    • Backend Release
    • Frontend Release
    • AI Code Review
    • Quality Report

    Different projects may have different requirements:

    • Backend Project: Backend Build, Backend Release, AI Code Review, Quality Report
    • Frontend Project: Frontend Build, Frontend Release, AI Code Review
    • Small Utility Project: Backend Build only

    With this two-level configuration, teams could maintain a single centralized CI/CD template while allowing each project to use only the jobs it needs.

    This would significantly improve the flexibility and maintainability of shared CI/CD configurations in OneDev.

1/1
Type
Enhancement
Priority
Major
Assignee
Labels
No labels
Issue Votes (0)
Watchers (2)
Reference
OD-3173
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover