[Cells 1.0] Implement a background process to re-encrypt any data encrypted with legacy keys

Goal

The goal is to implement the background processor that would re-encrypt any data encrypted with legacy keys, as proposed at &15226.

High-level algorithm

For all keys except the last one (i.e. the current one), find all data that were encrypted with that (this is possible if we're using ActiveRecord::Encryption), and re-encrypt the data with record.encrypt (it will use the latest key by default).

The background process could run as a CRON and would be a no-op if there's only a single key.

That way, when an organization is moved to a new cell, the legacy cell key would be added as a legacy key to allow the data to be decrypted, while the background process re-encrypts any legacy-encrypted data.

Estimate

This is a big task, for which scaling is the main challenge (i.e. how fast the re-encryption would be done for big tables etc). Fortunately, the main use-case is to re-encrypt data of moved organization, which reduces the scope compared to global key rotation.

Edited by Rémy Coutable