Warn about secret loss on group and project transfer

Why this MR ?

  • When a project is transferred or a group is transferred, we deprovision the Secrets Manager and permanently delete every secret. For a group it is the whole subtree - the group, all its subgroups and all their projects. Nothing warns the user anywhere in the UI, and neither of the transfer docs pages mentions it
  • Came up while going through the GA readiness work. We plan to do LA launch on .com ASAP and a quick fix for #596039 to unblock the launch. Proper fix will follow later after finalizing the UX
  • More context https://gitlab.slack.com/archives/C099JU3AZN1/p1787046126121669

What does this MR do ?

  • Adds a warning bullet to the project and group transfer modals
  • Adds the same warning to the Settings > General > Advanced transfer forms. Both docs pages document that path and not the modals, so the warning has to be on both surfaces
  • Adds a restriction bullet to both transfer docs pages, linking the Secrets Manager docs for anyone who has not used the feature
  • Bumps the transfer modal alert from info to warning, since the list now includes permanent data loss. Happy to put it back if UX prefers info

What this MR leaves out

  • No secret count. groupSecretsCount counts a single group while a group transfer deletes the whole subtree, so the number would understate the loss. The count based warning is #596039
  • The warning always shows, same as the other bullets in these lists. The modals get the project or group as a plain prop and have no Secrets Manager state on the client side
  • Cross organization transfer is a separate code path that does not deprovision at all, tracked in #604393

References

Screenshots (newly added text highlighted)

Before After
01-before-project-settings 05-after-project-settings
02-before-group-settings 06-after-group-settings
03-before-project-modal 07-after-project-modal
04-before-group-modal 08-after-group-modal

How to set up and validate locally

The warning is unconditional, so you do not need to enable the Secrets Manager or create a secret to see it.

  1. Project transfer form - go to a project, then Settings > General > Advanced > Transfer project
  2. Group transfer form - go to a group, then Settings > General > Advanced > Transfer group
  3. Project and group transfer modals - open the Actions menu on a project or group in a projects or groups list and select Transfer
  4. On each of the four, check the new bullet is in the list and that Learn more. lands on https://docs.gitlab.com/ci/secrets/secrets_manager/#transfer-of-a-project-or-group

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Jayakrishnan Mallissery

Merge request reports

Loading
Loading