Exclude the moved secret when counting CI policy secrets

What does this MR do and why?

When a secret moves to a new CI policy, count_secrets_for_policy is meant to skip that secret while counting how many secrets still use the old policy. It read the name with secret['name'], but SecretsManagerClient#list_secrets returns hashes with a "key" field, so the name was always nil and the secret was never skipped. This MR reads secret['key'] in both the group and project refreshers.

It also adds specs for both refreshers that call them while the moved secret still has its old metadata in OpenBao. Without the fix, the deletes the old policy and adds the secret to the new policy examples fail, because the old policy is kept (empty) instead of being deleted. The keeps the old policy for the other secret examples pass with or without the fix; they guard against skipping too much.

Closes #630744.

References

Follow-up from !257592 (merged).

Screenshots or screen recordings

Not applicable — backend change.

How to set up and validate locally

  1. Run bundle exec rspec ee/spec/services/secrets_management/ci_policies/group_secret_refresher_spec.rb ee/spec/services/secrets_management/ci_policies/project_secret_refresher_spec.rb.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

This contribution was prepared with the help of an AI assistant. I reviewed the changes and take responsibility for them.

Merge request reports

Loading
Loading