Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Documentation] docs/ddg.md: billing_override under three later stages still names 1-resman's tfvars, the enable-services fallback one-liner cannot work, and the Stage 0 Assured Workloads note quotes the wrong error and a folder that does not exist

Cerrado Apto para principiantes
#258 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 2 días

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
90/100
Tipo de issue
Documentación
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
bash, google-cloud, terraform

Línea de trabajo

Comienza en docs/ddg.md con los cuatro pasajes identificados en el issue y, después, compara las declaraciones de las variables stage, enableServices.sh y las referencias a 0-bootstrap/organization.tf. Verifica que el comando de fallback pueda habilitar cada servicio por separado y que la documentación nombre los archivos stage correctos, el texto del error y la carpeta. Se considera terminado cuando los cuatro pasajes sean precisos sin cambios fuera de docs/ddg.md.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Documentation Level of Effort - Low Priority - Medium

Description of Documentation Need

PR #245 refreshed docs/ddg.md to v4.0.0 and closed #242. Four passages it did not reach are still wrong at v4.0.1 (d9adab8f) and on main (397fc2ee); line numbers below are from main. They are the same class as the ones #242 listed: text carried forward from an earlier stage or an earlier version without being updated.

1. The billing_override note under three later stages names Stage 1's tfvars. The external-billing note ("If you are using an external billing account where the ... service account cannot be granted billing permissions, you can use a billing override ...") appears four times. Under Stage 1 - Resource Management (line 321) it correctly says to define billing_override in fast/stages-aw/1-resman/terraform.tfvars. The three later copies name the same file:

  • FedRAMP High / Moderate - Stage 2.1 Networking, line 413: "define the billing_override variable in fast/stages-aw/1-resman/terraform.tfvars file"
  • IL4/IL5 Stage 2.1 - Networking, line 471: the same sentence
  • Stage 3 - Security and Audit Account Configuration, line 561: the same sentence, and it still says "where the networking service account cannot be granted billing permissions" — the note four lines above it (557) names the Stage 3 account, <prefix>-security-0@<prefix>-prod-iac-core-0.iam.gserviceaccount.com

Each of those stages declares its own billing_override (2-networking-a-fedramp/variables.tf:195, 2-networking-b-il5-ngfw/variables.tf:49, 3-security/variables.tf:56), and by the time a reader reaches these sections Stage 1 has already been applied, so following the note as written puts the value in a stage that no longer runs.

2. The enable-services fallback one-liner in the Prerequisites cannot work as written (line 172, offered under "If you run into issues with the above command [enableServices.sh], you can simply run the following deprecated command"):

echo "iam cloudkms pubsub serviceusage cloudresourcemanager bigquery assuredworkloads cloudbilling logging iamcredentials orgpolicy" | xargs -n1 -I {} gcloud services enable "{}.googleapis.com"

xargs -I implies one line per invocation and overrides -n1 (xargs warns: "options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value"), so the whole space-separated list is passed as ONE service name and gcloud answers PERMISSION_DENIED: Not found or permission denied for service(s): iam cloudkms pubsub ... orgpolicy.googleapis.com. Reproduced on Ubuntu 24.04 with the SDK's gcloud on 2026-09-18. A reader who reaches this line is, by the guide's own framing, someone whose first attempt already failed — and the fallback fails too.

3. The Stage 0 note quotes an error Terraform does not print (lines 274–275): "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." What terraform apply actually prints at v4.0.0 / v4.0.1 is

Error: Error creating Dataset: googleapi: Error 403: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint for 'projects/<number>' attempting to use service 'bigquery.googleapis.com'., accessDenied

(the Assured Workloads folder enforces gcp.restrictServiceUsage). The fix the note gives is right; quoting the error the reader will actually see (restrictServiceUsage ... bigquery.googleapis.com) is what lets them recognize it. Seen on a fresh FedRAMP High Stage 0 apply on 2026-09-18.

4. The same note names a folder that does not exist (line 278): "Click the StellarEngine-<compliance_regime> folder". The Assured Workloads folder 0-bootstrap creates is StellarEngine-<prefix> (0-bootstrap/organization.tf:192, display_name = "StellarEngine-${var.prefix}", and again at :198 and :213); there is no folder named for the regime.

Target Audience

Operators deploying a FAST landing zone from the guide for the first time — the audience that hits each of these exactly once, at the moment it costs the most: item 1 when a stage's project creation fails on billing, item 2 when the primary enable script has already failed, items 3–4 while reading a Terraform error they cannot match to the note.

Proposed Location

docs/ddg.md — the four passages above; no other file is involved.

Content Outline / Draft

  1. Lines 413, 471, 561: **fast/stages-aw/1-resman/terraform.tfvars** → the section's own stage — **fast/stages-aw/2-networking-a-fedramp/terraform.tfvars**, **fast/stages-aw/2-networking-b-il5-ngfw/terraform.tfvars**, **fast/stages-aw/3-security/terraform.tfvars** respectively — and on line 561 "the networking service account" → "the security service account".
  2. Line 172: either drop -I {} and let -n1 pass each word (... | xargs -n1 sh -c 'gcloud services enable "$0.googleapis.com"'), or ... | tr ' ' '\n' | xargs -I {} gcloud services enable {}.googleapis.com, or simply list the services on one gcloud services enable call — which is also what enableServices.sh does.
  3. Lines 274–275: "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." → "You may receive a 403 in this stage: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint ... attempting to use service 'bigquery.googleapis.com'."
  4. Line 278: StellarEngine- <compliance_regime> → StellarEngine- <prefix>.

Compliance Context (if applicable)

None of the four changes a control. Item 4 sits in the Assured Workloads remediation step, so a reader looking for a folder that does not exist is a reader who cannot complete the step that brings BigQuery into the regime's service set.

Lenguaje dominante
HCL
Estrellas
51
Forks
21
Merge medio
1 d 15 h
PR fusionados (30 d)
30

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de google/stellar-engine

Todos los issues de google/stellar-engine

Issues similares

Más issues de Cloud

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.