[Documentation] docs/ddg.md: billing_override under three later stages still names 1-resman's tfvars, the enable-services fallback one-liner cannot work, and the Stage 0 Assured Workloads note quotes the wrong error and a folder that does not exist
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 90/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- bash, google-cloud, terraform
- Domain
- cloud, documentation, infrastructure
Research direction
Start in docs/ddg.md at the four passages identified in the issue, then compare the stage variable declarations, enableServices.sh, and 0-bootstrap/organization.tf references. Verify the fallback command can enable each service separately and that the documentation names the correct stage files, error text, and folder. Done means all four passages are accurate without changes outside docs/ddg.md.
Written by the indexing model from the issue text.
Description
Description of Documentation Need
PR #245 refreshed docs/ddg.md to v4.0.0 and closed #242. Four passages it did not reach are still wrong at v4.0.1 (d9adab8f) and on main (397fc2ee); line numbers below are from main. They are the same class as the ones #242 listed: text carried forward from an earlier stage or an earlier version without being updated.
1. The billing_override note under three later stages names Stage 1's tfvars. The external-billing note ("If you are using an external billing account where the ... service account cannot be granted billing permissions, you can use a billing override ...") appears four times. Under Stage 1 - Resource Management (line 321) it correctly says to define billing_override in fast/stages-aw/1-resman/terraform.tfvars. The three later copies name the same file:
- FedRAMP High / Moderate - Stage 2.1 Networking, line 413: "define the
billing_overridevariable in fast/stages-aw/1-resman/terraform.tfvars file" - IL4/IL5 Stage 2.1 - Networking, line 471: the same sentence
- Stage 3 - Security and Audit Account Configuration, line 561: the same sentence, and it still says "where the networking service account cannot be granted billing permissions" — the note four lines above it (557) names the Stage 3 account,
<prefix>-security-0@<prefix>-prod-iac-core-0.iam.gserviceaccount.com
Each of those stages declares its own billing_override (2-networking-a-fedramp/variables.tf:195, 2-networking-b-il5-ngfw/variables.tf:49, 3-security/variables.tf:56), and by the time a reader reaches these sections Stage 1 has already been applied, so following the note as written puts the value in a stage that no longer runs.
2. The enable-services fallback one-liner in the Prerequisites cannot work as written (line 172, offered under "If you run into issues with the above command [enableServices.sh], you can simply run the following deprecated command"):
echo "iam cloudkms pubsub serviceusage cloudresourcemanager bigquery assuredworkloads cloudbilling logging iamcredentials orgpolicy" | xargs -n1 -I {} gcloud services enable "{}.googleapis.com"
xargs -I implies one line per invocation and overrides -n1 (xargs warns: "options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value"), so the whole space-separated list is passed as ONE service name and gcloud answers PERMISSION_DENIED: Not found or permission denied for service(s): iam cloudkms pubsub ... orgpolicy.googleapis.com. Reproduced on Ubuntu 24.04 with the SDK's gcloud on 2026-09-18. A reader who reaches this line is, by the guide's own framing, someone whose first attempt already failed — and the fallback fails too.
3. The Stage 0 note quotes an error Terraform does not print (lines 274–275): "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." What terraform apply actually prints at v4.0.0 / v4.0.1 is
Error: Error creating Dataset: googleapi: Error 403: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint for 'projects/<number>' attempting to use service 'bigquery.googleapis.com'., accessDenied
(the Assured Workloads folder enforces gcp.restrictServiceUsage). The fix the note gives is right; quoting the error the reader will actually see (restrictServiceUsage ... bigquery.googleapis.com) is what lets them recognize it. Seen on a fresh FedRAMP High Stage 0 apply on 2026-09-18.
4. The same note names a folder that does not exist (line 278): "Click the StellarEngine-<compliance_regime> folder". The Assured Workloads folder 0-bootstrap creates is StellarEngine-<prefix> (0-bootstrap/organization.tf:192, display_name = "StellarEngine-${var.prefix}", and again at :198 and :213); there is no folder named for the regime.
Target Audience
Operators deploying a FAST landing zone from the guide for the first time — the audience that hits each of these exactly once, at the moment it costs the most: item 1 when a stage's project creation fails on billing, item 2 when the primary enable script has already failed, items 3–4 while reading a Terraform error they cannot match to the note.
Proposed Location
docs/ddg.md — the four passages above; no other file is involved.
Content Outline / Draft
- Lines 413, 471, 561:
**fast/stages-aw/1-resman/terraform.tfvars**→ the section's own stage —**fast/stages-aw/2-networking-a-fedramp/terraform.tfvars**,**fast/stages-aw/2-networking-b-il5-ngfw/terraform.tfvars**,**fast/stages-aw/3-security/terraform.tfvars**respectively — and on line 561 "the networking service account" → "the security service account". - Line 172: either drop
-I {}and let-n1pass each word (... | xargs -n1 sh -c 'gcloud services enable "$0.googleapis.com"'), or... | tr ' ' '\n' | xargs -I {} gcloud services enable {}.googleapis.com, or simply list the services on onegcloud services enablecall — which is also whatenableServices.shdoes. - Lines 274–275: "You may receive an error in this stage where it reports that
bigquery.googleapis.comis not usable in the Assured Workloads." → "You may receive a403in this stage:Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint ... attempting to use service 'bigquery.googleapis.com'." - Line 278:
StellarEngine-<compliance_regime>→StellarEngine-<prefix>.
Compliance Context (if applicable)
None of the four changes a control. Item 4 sits in the Assured Workloads remediation step, so a reader looking for a folder that does not exist is a reader who cannot complete the step that brings BigQuery into the regime's service set.
- Dominant language
- HCL
- Stars
- 51
- Forks
- 21
- Avg merge
- 1d 15h
- Merged PRs (30d)
- 30
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from google/stellar-engine
-
documentation Level of Effort - High Priority - Medium
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
google/stellar-engine#232 ·
Maintainers usually reply within 2 days
-
Bug Gemini - Government Level of Effort - Low Priority - Low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
google/stellar-engine#135 ·
Maintainers usually reply within 2 days
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandOpenEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
google/stellar-engine#122 ·
Maintainers usually reply within 2 days
-
documentation Level of Effort - Medium Priority - Medium
Difficulty 2/5 Half a day Newbie friendliness 72/100
google/stellar-engine#117 · 1 comment ·
Maintainers usually reply within 2 days
-
bug documentation
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
google/stellar-engine#91 ·
Maintainers usually reply within 2 days
All issues in google/stellar-engine
Similar issues
-
enhancement needs-triage service/kinesisanalyticsv2
Difficulty 1/5 1-3 hours Newbie friendliness 75/100
hashicorp/terraform-provider-aws#50261 · 2 comments ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
certimate-go/certimate#1471 ·
-
Add a check for GitHub flexible federated identity credentials missing an immutable repository claimPossibly taken @harshit3355 claimed this 1 day ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
bridgecrewio/checkov#7714 ·
Maintainers usually reply within 1 day
-
alicloud_nas_file_system: support Agentic storage typePossibly taken @BaoZhiFei claimed this 1 day ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
aliyun/terraform-provider-alicloud#10730 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100