[Bug] gem4gov-cli: the compliance regime has no effect on the engine's feature posture — FedRAMP High, IL4 and IL5 print the same list and apply the same engine_features.yaml
Los mantenedores suelen responder en 2 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 48/100
Línea de trabajo
Empieza con gem4gov app update-compliance y el flujo de onboarding; después inspecciona configure_gemini_enterprise_for_fedramp_high, configure_gemini_enterprise_for_il4, configure_gemini_enterprise_for_il5 y engine_features.yaml. Reproduce los comandos de FEDRAMP_HIGH e IL5 y compara los mapas de features devueltos. Se considera terminado cuando la configuración de features aplicada y el mensaje específico del régimen coinciden, tanto si los regímenes reciben conjuntos distintos como si se describe explícitamente un único conjunto compartido.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Bug Description
gem4gov app update-compliance and the onboarding flow both branch on the compliance regime, announce a regime-specific set of features that "are not yet authorized for <regime> and must be disabled", and then configure the engine identically.
Two things are the same across all three branches:
- The message. The 13 printed bullets are byte-identical for
FEDRAMP_HIGH,IL4andIL5; only the regime name in the lead sentence changes. - What is applied.
configure_gemini_enterprise_for_fedramp_high(:1526),configure_gemini_enterprise_for_il4(:1642) andconfigure_gemini_enterprise_for_il5(:1754) each load the same file and send its map unchanged:
yaml_path = os.path.join(script_dir, 'engine_features.yaml')
with open(yaml_path, 'r') as f:
engine_features = yaml.safe_load(f)
...
engine_patch_body = { "features": engine_features.get('features'), ... }
There is one engine_features.yaml in the package, and it carries no regime dimension. So the engine's feature posture — including the four disable-* keys — is identical whichever regime the operator picks.
The assistant PATCH in the same functions does diverge by regime (FedRAMP High's updateMask includes customerPolicy; IL5's does not), which shows per-regime behavior is intended somewhere. That is what makes the identical engine feature set look unintended rather than deliberate.
Environment and Deployment Context
- Stellar Engine Version/Commit:
v3.0.0(f64ce6cd). - Deployment Type:
- US Region Restricted (e.g., Access Policy constraint)
- FedRAMP Medium
- FedRAMP High
- FedRAMP Moderate
- DoD IL4
- DoD IL5
- Stand-alone / Custom
- **FAST Stage (if applicable):
- Stage 0 (Bootstrap)
- Stage 1 (Resource Management)
- Stage 2 (Networking)
- Stage 3 (Security)
Steps to Reproduce
- Run
gem4gov app update-compliance --project-id <project> --engine-id <engine-a> --compliance-regime FEDRAMP_HIGH. - Run the same command against a second engine with
--compliance-regime IL5. GETboth engines and diff theirfeaturesmaps.
Expected Behavior
Either each regime applies the feature set its own on-screen list describes, or — if the three regimes genuinely share one engine feature set — the tool says so once instead of naming a regime it did not act on.
Actual Behavior
The features maps are identical. Three regime choices produce one posture, announced three different ways.
Relevant Logs and Errors
None. Both runs report success.
Additional Context
The practical impact is that an operator deploying at IL5 is told a specific set of features is being disabled for IL5, and has no way to tell from the tool that the set applied is the FedRAMP High one.
If the sets should differ, this is a missing per-regime capability. If they should not, the messaging asserts a determination the code never makes. Either way the tool's output and its behavior disagree, and an auditor reading the transcript would conclude something the deployment cannot evidence.
- Lenguaje dominante
- HCL
- Estrellas
- 51
- Forks
- 21
- Merge medio
- 1 d 17 h
- PR fusionados (30 d)
- 29
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de google/stellar-engine
-
documentation Level of Effort - High Priority - Medium
Dificultad 1/5 1-3 horas Aptitud para principiantes 88/100
google/stellar-engine#232 ·
Los mantenedores suelen responder en 2 días
-
Bug Gemini - Government Level of Effort - Low Priority - Low
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
google/stellar-engine#135 ·
Los mantenedores suelen responder en 2 días
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandAbiertoEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
google/stellar-engine#122 ·
Los mantenedores suelen responder en 2 días
-
documentation Level of Effort - Medium Priority - Medium
Dificultad 2/5 Medio día Aptitud para principiantes 72/100
google/stellar-engine#117 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
[Feature Request] No research blueprint family — the README names universities as a target audience, every blueprint is FedRAMP High, FedRAMP Moderate or IL5Posiblemente ocupada @Calvin-Cheng1 la tomó hace 21 días. Abiertoenhancement
google/stellar-engine#239 · 2 comentarios · 1 asignado ·
Los mantenedores suelen responder en 2 días
Todos los issues de google/stellar-engine
Issues similares
-
area/install reliability status/ready
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
CLI: TUI shows onboarding when the provider's API key is only in the environment (e.g. OPENROUTER_API_KEY)Posiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. AbiertoCLI
Dificultad 2/5 1-3 horas Aptitud para principiantes 67/100
cline/cline#14923 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
review-followup
Dificultad 2/5 1-3 horas Aptitud para principiantes 77/100
griffinwork40/agent-afk#3217 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
FluidNumerics/fluid-walk-blocker#189 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día