Add rollout channel token model

What does this MR do and why?

Adds Cd::RolloutChannelToken: a new model + table to persist the token an AutoFlow channel is opened with (e.g. when a rollout's approval step suspends), so Rails has a handle to push a human's decision back into that channel later via SendToWorkflowChannel.

Follows the same shape as the sibling Cd::RolloutStep table: organization_id/rollout_id created inline with the table, FKs added via two separate follow-up migrations (add_concurrent_foreign_key + disable_ddl_transaction!), and the encrypted-column pattern from Packages::Conan::JwtSigningKey.

This is model + migration only; nothing yet reads or writes rows through it (that lands in the follow-up issue that turns AutoFlow channel-open events into rows here).

How to set up and validate locally

  1. bundle exec rails db:migrate
  2. bundle exec rspec ee/spec/models/cd/rollout_channel_token_spec.rb
  3. In a Rails console:
rollout = FactoryBot.create(:cd_rollout) # or any existing Cd::Rollout
token = Cd::RolloutChannelToken.create!(rollout: rollout, channel_name: 'approval-1', token: SecureRandom.hex(16))
token.token                     # => plaintext, decrypted transparently
token.serializable_hash         # => does not include "token"
rollout.destroy!                # cascades: token row is gone
Cd::RolloutChannelToken.exists?(token.id) # => false

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Related to #617019

Merge request reports

Loading
Loading