Skip to content

Policy presets

Policy presets are optional starter policies. They do not modify GitLab project settings and they do not hide findings. A preset only provides:

  • an initial set of enabled rule IDs
  • default severity overrides for selected rules

Presets are versioned independently from the Python package.

Available presets

Preset Version Rules Intended use
minimal 1.0 7 Small baseline for essential repository, branch, and CI checks.
team 1.0 25 Practical collaborative-development policy for normal team repositories.
strict 1.0 47 Full rule catalogue with stronger severity defaults for governance/security checks.

Inspect them from the installed CLI:

gitlab-project-audit list-presets
gitlab-project-audit list-presets --json

Select a preset in configuration

preset: team

The rest of the YAML remains normal policy configuration:

preset: team

disabled_rules:
  - project.license-present

severity_overrides:
  governance.pipeline-required: critical

Select a preset from the CLI

gitlab-project-audit audit group/project --preset strict

You can also expand a preset without running an audit:

gitlab-project-audit print-effective-config --preset strict

Precedence

The effective policy is built in this order:

  1. built-in defaults
  2. selected preset
  3. repository/configuration file
  4. explicit CLI overrides

The configuration file therefore overrides preset rule selection and severity defaults.

If a configuration file says:

preset: strict
enabled_rules:
  - project.readme-present

then only project.readme-present remains enabled. The preset is a starting point, not a hidden mandatory layer.

When --preset is supplied, it chooses the preset base even if the file contains a different preset: name. Explicit policy fields inside the file still override that selected base.

Minimal

The minimal preset enables seven essential checks:

  • project description
  • default branch
  • README
  • default-branch protection
  • pipeline-before-merge
  • CI configuration presence
  • CI configuration parsing

It does not apply severity overrides.

Team

The team preset expands coverage to common collaboration, documentation, CI hygiene, variable metadata, pipeline failures, and release notes. It also raises several important governance/CI checks to high.

Strict

The strict preset enables all 47 registered rules and increases severity for selected branch, approval, CI, variable, pipeline, and release controls.

This does not mean every repository must use strict policy. It is an explicit opt-in profile.

Stability

Preset definitions are versioned. The current versions are 1.0. Material changes to the meaning of a named preset require an explicit version decision rather than silently changing its behavior.