Add rollout channel token model
What does this MR do and why?
Adds Cd::RolloutChannelToken: a new model + table to persist the token an AutoFlow channel is opened with (e.g. when a rollout's approval step suspends), so Rails has a handle to push a human's decision back into that channel later via SendToWorkflowChannel.
Follows the same shape as the sibling Cd::RolloutStep table: organization_id/rollout_id created inline with the table, FKs added via two separate follow-up migrations (add_concurrent_foreign_key + disable_ddl_transaction!), and the encrypted-column pattern from Packages::Conan::JwtSigningKey.
This is model + migration only; nothing yet reads or writes rows through it (that lands in the follow-up issue that turns AutoFlow channel-open events into rows here).
How to set up and validate locally
bundle exec rails db:migratebundle exec rspec ee/spec/models/cd/rollout_channel_token_spec.rb- In a Rails console:
rollout = FactoryBot.create(:cd_rollout) # or any existing Cd::Rollout
token = Cd::RolloutChannelToken.create!(rollout: rollout, channel_name: 'approval-1', token: SecureRandom.hex(16))
token.token # => plaintext, decrypted transparently
token.serializable_hash # => does not include "token"
rollout.destroy! # cascades: token row is gone
Cd::RolloutChannelToken.exists?(token.id) # => falseMR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Related to #617019