Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Documentation] docs/ddg.md: billing_override under three later stages still names 1-resman's tfvars, the enable-services fallback one-liner cannot work, and the Stage 0 Assured Workloads note quotes the wrong error and a folder that does not exist

Closed Beginner friendly
#258 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 2 days

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
90/100
Issue type
Documentation
Clarity
Clearly specified
Activity status
Active
Tech stack
bash, google-cloud, terraform

Research direction

Start in docs/ddg.md at the four passages identified in the issue, then compare the stage variable declarations, enableServices.sh, and 0-bootstrap/organization.tf references. Verify the fallback command can enable each service separately and that the documentation names the correct stage files, error text, and folder. Done means all four passages are accurate without changes outside docs/ddg.md.

Written by the indexing model from the issue text.

Description

Documentation Level of Effort - Low Priority - Medium

Description of Documentation Need

PR #245 refreshed docs/ddg.md to v4.0.0 and closed #242. Four passages it did not reach are still wrong at v4.0.1 (d9adab8f) and on main (397fc2ee); line numbers below are from main. They are the same class as the ones #242 listed: text carried forward from an earlier stage or an earlier version without being updated.

1. The billing_override note under three later stages names Stage 1's tfvars. The external-billing note ("If you are using an external billing account where the ... service account cannot be granted billing permissions, you can use a billing override ...") appears four times. Under Stage 1 - Resource Management (line 321) it correctly says to define billing_override in fast/stages-aw/1-resman/terraform.tfvars. The three later copies name the same file:

  • FedRAMP High / Moderate - Stage 2.1 Networking, line 413: "define the billing_override variable in fast/stages-aw/1-resman/terraform.tfvars file"
  • IL4/IL5 Stage 2.1 - Networking, line 471: the same sentence
  • Stage 3 - Security and Audit Account Configuration, line 561: the same sentence, and it still says "where the networking service account cannot be granted billing permissions" — the note four lines above it (557) names the Stage 3 account, <prefix>-security-0@<prefix>-prod-iac-core-0.iam.gserviceaccount.com

Each of those stages declares its own billing_override (2-networking-a-fedramp/variables.tf:195, 2-networking-b-il5-ngfw/variables.tf:49, 3-security/variables.tf:56), and by the time a reader reaches these sections Stage 1 has already been applied, so following the note as written puts the value in a stage that no longer runs.

2. The enable-services fallback one-liner in the Prerequisites cannot work as written (line 172, offered under "If you run into issues with the above command [enableServices.sh], you can simply run the following deprecated command"):

echo "iam cloudkms pubsub serviceusage cloudresourcemanager bigquery assuredworkloads cloudbilling logging iamcredentials orgpolicy" | xargs -n1 -I {} gcloud services enable "{}.googleapis.com"

xargs -I implies one line per invocation and overrides -n1 (xargs warns: "options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value"), so the whole space-separated list is passed as ONE service name and gcloud answers PERMISSION_DENIED: Not found or permission denied for service(s): iam cloudkms pubsub ... orgpolicy.googleapis.com. Reproduced on Ubuntu 24.04 with the SDK's gcloud on 2026-09-18. A reader who reaches this line is, by the guide's own framing, someone whose first attempt already failed — and the fallback fails too.

3. The Stage 0 note quotes an error Terraform does not print (lines 274–275): "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." What terraform apply actually prints at v4.0.0 / v4.0.1 is

Error: Error creating Dataset: googleapi: Error 403: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint for 'projects/<number>' attempting to use service 'bigquery.googleapis.com'., accessDenied

(the Assured Workloads folder enforces gcp.restrictServiceUsage). The fix the note gives is right; quoting the error the reader will actually see (restrictServiceUsage ... bigquery.googleapis.com) is what lets them recognize it. Seen on a fresh FedRAMP High Stage 0 apply on 2026-09-18.

4. The same note names a folder that does not exist (line 278): "Click the StellarEngine-<compliance_regime> folder". The Assured Workloads folder 0-bootstrap creates is StellarEngine-<prefix> (0-bootstrap/organization.tf:192, display_name = "StellarEngine-${var.prefix}", and again at :198 and :213); there is no folder named for the regime.

Target Audience

Operators deploying a FAST landing zone from the guide for the first time — the audience that hits each of these exactly once, at the moment it costs the most: item 1 when a stage's project creation fails on billing, item 2 when the primary enable script has already failed, items 3–4 while reading a Terraform error they cannot match to the note.

Proposed Location

docs/ddg.md — the four passages above; no other file is involved.

Content Outline / Draft

  1. Lines 413, 471, 561: **fast/stages-aw/1-resman/terraform.tfvars** → the section's own stage — **fast/stages-aw/2-networking-a-fedramp/terraform.tfvars**, **fast/stages-aw/2-networking-b-il5-ngfw/terraform.tfvars**, **fast/stages-aw/3-security/terraform.tfvars** respectively — and on line 561 "the networking service account" → "the security service account".
  2. Line 172: either drop -I {} and let -n1 pass each word (... | xargs -n1 sh -c 'gcloud services enable "$0.googleapis.com"'), or ... | tr ' ' '\n' | xargs -I {} gcloud services enable {}.googleapis.com, or simply list the services on one gcloud services enable call — which is also what enableServices.sh does.
  3. Lines 274–275: "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." → "You may receive a 403 in this stage: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint ... attempting to use service 'bigquery.googleapis.com'."
  4. Line 278: StellarEngine- <compliance_regime> → StellarEngine- <prefix>.

Compliance Context (if applicable)

None of the four changes a control. Item 4 sits in the Assured Workloads remediation step, so a reader looking for a folder that does not exist is a reader who cannot complete the step that brings BigQuery into the regime's service set.

Dominant language
HCL
Stars
51
Forks
21
Avg merge
1d 15h
Merged PRs (30d)
30

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from google/stellar-engine

All issues in google/stellar-engine

Similar issues

More Cloud issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.