[Feature Request] No research blueprint family — the README names universities as a target audience, every blueprint is FedRAMP High, FedRAMP Moderate or IL5
Maintainers usually reply within 2 days
@Calvin-Cheng1 is already working on this.
Since Sep 16, 2026.
Assessment
This issue has not been assessed yet.
Description
Feature Description
A blueprints/research/ family for the unspecified regime, aimed at universities and research institutions.
Use Case
The README lists "Educational and Research Institutions" under Target Audience. Every shipped blueprint targets FedRAMP High, FedRAMP Moderate or IL5. A university running NSF or NIH work usually has no Assured Workloads requirement, so it pays the compliance overhead and gets nothing back.
Three gaps show up on every deployment I do:
- Egress. Researchers run
pip install, pull from HuggingFace, and fetch datasets from Zenodo and nf-core. An inspected-egress topology blocks all of it. Per-spoke Cloud NAT lets it through. - Who creates projects. Central IT on the critical path for every new principal investigator (PI) project works for ten researchers and fails at hundreds.
- Blast radius. A PI who needs a public IP for one sandbox VM shouldn't need an org-wide policy change.
Proposed Solution
A blueprint family covering: NCC egress (see #58), department folders with tag-scoped org-policy delegation (see #14), sandbox and hardened folder presets (see #12), and project templates for each.
I have all of it deployed in a fork and can contribute it. Opening this first to check you want the family at all, and where it should live, before sending PRs against the three issues separately.
Compliance & Deployment Context
- Target Deployment Type(s):
- All / General — specifically the unspecified regime, where no Assured Workloads folder is created.
- Relevant NIST 800-53r5 Controls: Not compliance-driven. The delegation piece touches AC-6 (least privilege) by replacing org-wide policy admin with folder-scoped grants.
Reusability Check
- I have checked if this functionality can be achieved by extending an existing module or blueprint.
- I have verified that this does not duplicate existing functionality.
Alternatives Considered
Leaving it in its current fork.
Additional Context
Related: #58, #14, #12.
- Dominant language
- HCL
- Stars
- 51
- Forks
- 21
- Avg merge
- 1d 15h
- Merged PRs (30d)
- 30
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from google/stellar-engine
-
documentation Level of Effort - High Priority - Medium
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
google/stellar-engine#232 ·
Maintainers usually reply within 2 days
-
Bug Gemini - Government Level of Effort - Low Priority - Low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
google/stellar-engine#135 ·
Maintainers usually reply within 2 days
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandOpenEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
google/stellar-engine#122 ·
Maintainers usually reply within 2 days
-
documentation Level of Effort - Medium Priority - Medium
Difficulty 2/5 Half a day Newbie friendliness 72/100
google/stellar-engine#117 · 1 comment ·
Maintainers usually reply within 2 days
-
bug documentation
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
google/stellar-engine#91 ·
Maintainers usually reply within 2 days