[Bug] 2-networking-a-fedramp: the hierarchical firewall policy defaults to the unprefixed name net-default, which is unique per organization — a second deployment in the same org (a redeploy under a new prefix) fails at apply
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 78/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- google-cloud, terraform
- Domain
- cloud, infrastructure
Research direction
Start with fast/stages-aw/2-networking-a-fedramp/main.tf:44-47 and variables.tf:78, then compare the naming guidance in docs/ddg.md, the stage README, and terraform.tfvars.sample. Reproduce the Stage 2 redeployment with a second prefix and inspect the hierarchical firewall policy failure. Done means deployments in one organization no longer collide, or the required organization-unique setting is documented in the named guides and sample.
Written by the indexing model from the issue text.
Description
Bug Description
fast/stages-aw/2-networking-a-fedramp/main.tf:44-47 creates the stage's hierarchical firewall policy with
name = var.factories_config.firewall_policy_name, whose default (variables.tf:78) is "net-default". A hierarchical firewall policy's short name must be unique within the organization, and every other resource the stage names carries var.prefix. So the second deployment of the stage in an organization — the case the project's own guidance creates, since project IDs are never reusable and a rebuild has to use a new prefix — fails at apply, 320 of 322 resources in:
Error: Error creating FirewallPolicy: googleapi: Error 400: Invalid value for field 'resource.shortName': 'net-default'. The display name is already used. Please choose another one, invalid
with module.firewall-policy-default.google_compute_firewall_policy.hierarchical[0],
on ../../../modules/net-firewall-policy/hierarchical.tf line 17, in resource "google_compute_firewall_policy" "hierarchical":
The operator can set factories_config.firewall_policy_name in terraform.tfvars, but nothing in docs/ddg.md, the stage README or terraform.tfvars.sample says the name is org-unique or that a second deployment must change it.
Environment and Deployment Context
- Stellar Engine Version/Commit:
v4.0.0(6d7d08c0); unchanged onmain(20830097, 2026-09-18). - Deployment Type:
- US Region Restricted (e.g., Access Policy constraint)
- FedRAMP Moderate
- FedRAMP High
- DoD IL4
- DoD IL5
- Stand-alone / Custom
- FAST Stage (if applicable):
- Stage 0 (Bootstrap)
- Stage 1 (Resource Management)
- Stage 2 (Networking)
- Stage 3 (Security)
Steps to Reproduce
- Deploy Stages 0–2 in an organization with prefix A.
- Deploy Stages 0–2 again in the same organization with prefix B (a rebuild, or a second landing zone for testing), following
docs/ddg.md. - Stage 2's
terraform applyfor prefix B fails onmodule.firewall-policy-default.google_compute_firewall_policy.hierarchical[0]with the error above; everything else in the stage applies.
Expected Behavior
The policy name carries the prefix like the stage's other resources ("${var.prefix}-net-default"), so two deployments in one organization do not collide — or the guide states that factories_config.firewall_policy_name must be unique per organization and must be set for a second deployment.
Actual Behavior
The default collides; the operator discovers factories_config.firewall_policy_name by reading variables.tf.
Relevant Logs and Errors
See above.
Additional Context
- Suggested fix:
firewall_policy_name = optional(string)with the stage defaulting it to"${var.prefix}-net-default"when unset (the same pattern as the stage's VPC, subnet and NVA names); or, at minimum, a note indocs/ddg.mdunder Stage 2.1 and interraform.tfvars.sample. - Related: #228 (the prefix's length arithmetic) is about the same design principle — the prefix is what keeps one organization's deployments apart.
- Dominant language
- HCL
- Stars
- 51
- Forks
- 21
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 30
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from google/stellar-engine
-
documentation Level of Effort - High Priority - Medium
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
google/stellar-engine#232 ·
Maintainers usually reply within 2 days
-
Bug Gemini - Government Level of Effort - Low Priority - Low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
google/stellar-engine#135 ·
Maintainers usually reply within 2 days
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandOpenEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
google/stellar-engine#122 ·
Maintainers usually reply within 2 days
-
documentation Level of Effort - Medium Priority - Medium
Difficulty 2/5 Half a day Newbie friendliness 72/100
google/stellar-engine#117 · 1 comment ·
Maintainers usually reply within 2 days
-
[Feature Request] No research blueprint family — the README names universities as a target audience, every blueprint is FedRAMP High, FedRAMP Moderate or IL5Possibly taken @Calvin-Cheng1 claimed this 19 days ago. Openenhancement
google/stellar-engine#239 · 2 comments · 1 assignee ·
Maintainers usually reply within 2 days
All issues in google/stellar-engine
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
cloudflare/agents#2498 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
MemberJunction/MJ#5066 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
DataDog/datadog-serverless-functions#1219 ·
Maintainers usually reply within 1 day
-
area: providers/aws priority: p2 size: S type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
finos/open-resource-broker#418 · 1 comment ·
Maintainers usually reply within 1 day
-
GCP region parser selects the wrong region for multi-digit region numbersPossibly taken @nawaaaaaAaar claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
mlco2/codecarbon#1438 ·
Maintainers usually reply within 1 day