[Documentation] docs/ddg.md: billing_override under three later stages still names 1-resman's tfvars, the enable-services fallback one-liner cannot work, and the Stage 0 Assured Workloads note quotes the wrong error and a folder that does not exist
Los mantenedores suelen responder en 2 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 90/100
- Tipo de issue
- Documentación
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- bash, google-cloud, terraform
- Área
- cloud, documentation, infrastructure
Línea de trabajo
Comienza en docs/ddg.md con los cuatro pasajes identificados en el issue y, después, compara las declaraciones de las variables stage, enableServices.sh y las referencias a 0-bootstrap/organization.tf. Verifica que el comando de fallback pueda habilitar cada servicio por separado y que la documentación nombre los archivos stage correctos, el texto del error y la carpeta. Se considera terminado cuando los cuatro pasajes sean precisos sin cambios fuera de docs/ddg.md.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description of Documentation Need
PR #245 refreshed docs/ddg.md to v4.0.0 and closed #242. Four passages it did not reach are still wrong at v4.0.1 (d9adab8f) and on main (397fc2ee); line numbers below are from main. They are the same class as the ones #242 listed: text carried forward from an earlier stage or an earlier version without being updated.
1. The billing_override note under three later stages names Stage 1's tfvars. The external-billing note ("If you are using an external billing account where the ... service account cannot be granted billing permissions, you can use a billing override ...") appears four times. Under Stage 1 - Resource Management (line 321) it correctly says to define billing_override in fast/stages-aw/1-resman/terraform.tfvars. The three later copies name the same file:
- FedRAMP High / Moderate - Stage 2.1 Networking, line 413: "define the
billing_overridevariable in fast/stages-aw/1-resman/terraform.tfvars file" - IL4/IL5 Stage 2.1 - Networking, line 471: the same sentence
- Stage 3 - Security and Audit Account Configuration, line 561: the same sentence, and it still says "where the networking service account cannot be granted billing permissions" — the note four lines above it (557) names the Stage 3 account,
<prefix>-security-0@<prefix>-prod-iac-core-0.iam.gserviceaccount.com
Each of those stages declares its own billing_override (2-networking-a-fedramp/variables.tf:195, 2-networking-b-il5-ngfw/variables.tf:49, 3-security/variables.tf:56), and by the time a reader reaches these sections Stage 1 has already been applied, so following the note as written puts the value in a stage that no longer runs.
2. The enable-services fallback one-liner in the Prerequisites cannot work as written (line 172, offered under "If you run into issues with the above command [enableServices.sh], you can simply run the following deprecated command"):
echo "iam cloudkms pubsub serviceusage cloudresourcemanager bigquery assuredworkloads cloudbilling logging iamcredentials orgpolicy" | xargs -n1 -I {} gcloud services enable "{}.googleapis.com"
xargs -I implies one line per invocation and overrides -n1 (xargs warns: "options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value"), so the whole space-separated list is passed as ONE service name and gcloud answers PERMISSION_DENIED: Not found or permission denied for service(s): iam cloudkms pubsub ... orgpolicy.googleapis.com. Reproduced on Ubuntu 24.04 with the SDK's gcloud on 2026-09-18. A reader who reaches this line is, by the guide's own framing, someone whose first attempt already failed — and the fallback fails too.
3. The Stage 0 note quotes an error Terraform does not print (lines 274–275): "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." What terraform apply actually prints at v4.0.0 / v4.0.1 is
Error: Error creating Dataset: googleapi: Error 403: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint for 'projects/<number>' attempting to use service 'bigquery.googleapis.com'., accessDenied
(the Assured Workloads folder enforces gcp.restrictServiceUsage). The fix the note gives is right; quoting the error the reader will actually see (restrictServiceUsage ... bigquery.googleapis.com) is what lets them recognize it. Seen on a fresh FedRAMP High Stage 0 apply on 2026-09-18.
4. The same note names a folder that does not exist (line 278): "Click the StellarEngine-<compliance_regime> folder". The Assured Workloads folder 0-bootstrap creates is StellarEngine-<prefix> (0-bootstrap/organization.tf:192, display_name = "StellarEngine-${var.prefix}", and again at :198 and :213); there is no folder named for the regime.
Target Audience
Operators deploying a FAST landing zone from the guide for the first time — the audience that hits each of these exactly once, at the moment it costs the most: item 1 when a stage's project creation fails on billing, item 2 when the primary enable script has already failed, items 3–4 while reading a Terraform error they cannot match to the note.
Proposed Location
docs/ddg.md — the four passages above; no other file is involved.
Content Outline / Draft
- Lines 413, 471, 561:
**fast/stages-aw/1-resman/terraform.tfvars**→ the section's own stage —**fast/stages-aw/2-networking-a-fedramp/terraform.tfvars**,**fast/stages-aw/2-networking-b-il5-ngfw/terraform.tfvars**,**fast/stages-aw/3-security/terraform.tfvars**respectively — and on line 561 "the networking service account" → "the security service account". - Line 172: either drop
-I {}and let-n1pass each word (... | xargs -n1 sh -c 'gcloud services enable "$0.googleapis.com"'), or... | tr ' ' '\n' | xargs -I {} gcloud services enable {}.googleapis.com, or simply list the services on onegcloud services enablecall — which is also whatenableServices.shdoes. - Lines 274–275: "You may receive an error in this stage where it reports that
bigquery.googleapis.comis not usable in the Assured Workloads." → "You may receive a403in this stage:Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint ... attempting to use service 'bigquery.googleapis.com'." - Line 278:
StellarEngine-<compliance_regime>→StellarEngine-<prefix>.
Compliance Context (if applicable)
None of the four changes a control. Item 4 sits in the Assured Workloads remediation step, so a reader looking for a folder that does not exist is a reader who cannot complete the step that brings BigQuery into the regime's service set.
- Lenguaje dominante
- HCL
- Estrellas
- 51
- Forks
- 21
- Merge medio
- 1 d 15 h
- PR fusionados (30 d)
- 30
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de google/stellar-engine
-
documentation Level of Effort - High Priority - Medium
Dificultad 1/5 1-3 horas Aptitud para principiantes 88/100
google/stellar-engine#232 ·
Los mantenedores suelen responder en 2 días
-
Bug Gemini - Government Level of Effort - Low Priority - Low
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
google/stellar-engine#135 ·
Los mantenedores suelen responder en 2 días
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandAbiertoEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
google/stellar-engine#122 ·
Los mantenedores suelen responder en 2 días
-
documentation Level of Effort - Medium Priority - Medium
Dificultad 2/5 Medio día Aptitud para principiantes 72/100
google/stellar-engine#117 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
bug documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
google/stellar-engine#91 ·
Los mantenedores suelen responder en 2 días
Todos los issues de google/stellar-engine
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
langgenius/dify-official-plugins#3983 · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
azure-diagnostics bug
Dificultad 2/5 1-2 días Aptitud para principiantes 78/100
microsoft/GitHub-Copilot-for-Azure#3293 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 1-3 horas Aptitud para principiantes 78/100
TheOdinProject/curriculum#31433 ·
Los mantenedores suelen responder en 1 día
-
needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
wazuh/wazuh-virtual-machines#993 ·
Los mantenedores suelen responder en 1 día