Exclude the moved secret when counting CI policy secrets
What does this MR do and why?
When a secret moves to a new CI policy, count_secrets_for_policy is meant to skip that secret while counting how many secrets still use the old policy. It read the name with secret['name'], but SecretsManagerClient#list_secrets returns hashes with a "key" field, so the name was always nil and the secret was never skipped. This MR reads secret['key'] in both the group and project refreshers.
It also adds specs for both refreshers that call them while the moved secret still has its old metadata in OpenBao. Without the fix, the deletes the old policy and adds the secret to the new policy examples fail, because the old policy is kept (empty) instead of being deleted. The keeps the old policy for the other secret examples pass with or without the fix; they guard against skipping too much.
Closes #630744.
References
Follow-up from !257592 (merged).
Screenshots or screen recordings
Not applicable — backend change.
How to set up and validate locally
- Run
bundle exec rspec ee/spec/services/secrets_management/ci_policies/group_secret_refresher_spec.rb ee/spec/services/secrets_management/ci_policies/project_secret_refresher_spec.rb.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist.
This contribution was prepared with the help of an AI assistant. I reviewed the changes and take responsibility for them.