Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug] 2-networking-a-fedramp: the hierarchical firewall policy defaults to the unprefixed name net-default, which is unique per organization — a second deployment in the same org (a redeploy under a new prefix) fails at apply

Closed
#254 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 2 days

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
78/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
google-cloud, terraform

Research direction

Start with fast/stages-aw/2-networking-a-fedramp/main.tf:44-47 and variables.tf:78, then compare the naming guidance in docs/ddg.md, the stage README, and terraform.tfvars.sample. Reproduce the Stage 2 redeployment with a second prefix and inspect the hierarchical firewall policy failure. Done means deployments in one organization no longer collide, or the required organization-unique setting is documented in the named guides and sample.

Written by the indexing model from the issue text.

Description

Bug Level of Effort - Low Priority - Low

Bug Description

fast/stages-aw/2-networking-a-fedramp/main.tf:44-47 creates the stage's hierarchical firewall policy with
name = var.factories_config.firewall_policy_name, whose default (variables.tf:78) is "net-default". A hierarchical firewall policy's short name must be unique within the organization, and every other resource the stage names carries var.prefix. So the second deployment of the stage in an organization — the case the project's own guidance creates, since project IDs are never reusable and a rebuild has to use a new prefix — fails at apply, 320 of 322 resources in:

Error: Error creating FirewallPolicy: googleapi: Error 400: Invalid value for field 'resource.shortName': 'net-default'. The display name is already used. Please choose another one, invalid

  with module.firewall-policy-default.google_compute_firewall_policy.hierarchical[0],
  on ../../../modules/net-firewall-policy/hierarchical.tf line 17, in resource "google_compute_firewall_policy" "hierarchical":

The operator can set factories_config.firewall_policy_name in terraform.tfvars, but nothing in docs/ddg.md, the stage README or terraform.tfvars.sample says the name is org-unique or that a second deployment must change it.

Environment and Deployment Context

  • Stellar Engine Version/Commit: v4.0.0 (6d7d08c0); unchanged on main (20830097, 2026-09-18).
  • Deployment Type:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • Stand-alone / Custom
  • FAST Stage (if applicable):
    • Stage 0 (Bootstrap)
    • Stage 1 (Resource Management)
    • Stage 2 (Networking)
    • Stage 3 (Security)

Steps to Reproduce

  1. Deploy Stages 0–2 in an organization with prefix A.
  2. Deploy Stages 0–2 again in the same organization with prefix B (a rebuild, or a second landing zone for testing), following docs/ddg.md.
  3. Stage 2's terraform apply for prefix B fails on module.firewall-policy-default.google_compute_firewall_policy.hierarchical[0] with the error above; everything else in the stage applies.

Expected Behavior

The policy name carries the prefix like the stage's other resources ("${var.prefix}-net-default"), so two deployments in one organization do not collide — or the guide states that factories_config.firewall_policy_name must be unique per organization and must be set for a second deployment.

Actual Behavior

The default collides; the operator discovers factories_config.firewall_policy_name by reading variables.tf.

Relevant Logs and Errors

See above.

Additional Context

  • Suggested fix: firewall_policy_name = optional(string) with the stage defaulting it to "${var.prefix}-net-default" when unset (the same pattern as the stage's VPC, subnet and NVA names); or, at minimum, a note in docs/ddg.md under Stage 2.1 and in terraform.tfvars.sample.
  • Related: #228 (the prefix's length arithmetic) is about the same design principle — the prefix is what keeps one organization's deployments apart.
Dominant language
HCL
Stars
51
Forks
21
Avg merge
1d 16h
Merged PRs (30d)
30

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from google/stellar-engine

All issues in google/stellar-engine

Similar issues

More Cloud issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.