How to trigger a downstream pipeline of a protect branch in Gitlab with keyword 'trigger'

Viewed 714

The error says it has no permission. The question is how to use the pipeline token in the upstream pipeline/project. (I know with 'curl' script the token could be set but now I just would like to use the keyword 'trigger') Thanks!

@VonC Thanks for your reply. Here's the job in the yaml. ‘trigger' is used to start the downstream pipeline. But since they're different and the downstream pipeline is running against the master pipeline, the guy who triggers the pipeline should be a maintainer of the downstream project. Otherwise, the job will not run and the prompt is 'no permission to trigger downstream pipeline'.


trigger-test
  stage: test
  trigger:
    project: myprj/downstream-test
    branch: master
  allow_failure: true
  only:
    - master
1 Answers

UPDATE

You can also use server side git hooks and allow Developer roles to merge into your protected branches.
This will allow any Developer to trigger your protected branch, but the hook will restrict access to actual protected repository based on your rules.

Gitlab also provides very convenient envs for the hooks, for example ..gitlab_server_protected_repo.git/custom_hooks/pre-receive:

#!/bin/bash 

if [[ "$GL_USERNAME" != @(user1|user2|user3) ]]; then 
  echo "GL-HOOK-ERR: $GL_USERNAME restricted"
  exit 1
fi

More on that: https://docs.gitlab.com/ee/administration/server_hooks.html

OLD

Yep, at this time this is a big security concern in Gitlab CI, related links:

The workaround is not such satisfying but it works:

  1. Make desired branch protect in 'Downstream' repository
  2. Create Pipeline triggers (actually this is a token, the name is misleading) in 'Downstream' project : Settings -> CI/CD -> Pipeline triggers.
  3. As an Admin - locate this token as a Group CI/CD variable (or in the project which will trigger 'Downstream' project) - Group Settings -> CI/CD -> Variables.
  4. Use it in you pipeline:
      curl -X POST \
        --form token=$YOU_TRIGGER_TOKEN_VARIABLE \
        --form ref=target_branch \
        "$CI_API_V4_URL/projects/55/trigger/pipeline"

The issue with workaround - UI doesn't visually track relationship between initiated pipeline and downstream.

The other solution which is not secure:

  1. Create user with Maintainer role (if your protected branch allows to merge only for Maintainers)
  2. Create personal user token
  3. Locate and use it the same as in previous solution.

Anyone who understand what power does this token provides - can do everything with protected branches via his own .gitlab-ci.yml pipeline, referencing this token.

Related