[Bug] gem4gov app update-compliance: the engine patch is rejected (updateMask contains the immutable path disable_analytics), so the compliance feature states are never applied by the command
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 76/100
Research direction
Start in gem4gov-cli/gem4gov.py at configure_gemini_enterprise_for_fedramp_high (lines 1403-1436), then inspect the corresponding IL4, IL5, and onboard engine patches. Reproduce the update-compliance command against an existing engine and verify that the compliance feature states are applied or that an engine-patch error makes the command fail instead of reporting completion.
Written by the indexing model from the issue text.
Description
Bug Description
gem4gov app update-compliance --compliance-regime FEDRAMP_HIGH (and the same code on the IL4/IL5 paths and in onboard) patches the engine with the body {"features": <engine_features.yaml>, "disableAnalytics": true} and updateMask=features,disableAnalytics (gem4gov-cli/gem4gov.py:1420-1436 at v4.0.0). Discovery Engine rejects the call:
An error occurred while configuring the engine for FedRAMP High: <HttpError 400 when requesting
https://us-discoveryengine.googleapis.com/v1alpha/projects/<project>/locations/us/collections/default_collection/engines/<engine>?updateMask=features%2CdisableAnalytics&alt=json
returned "Field "updateMask" contains an immutable path "disable_analytics".">
disableAnalytics is immutable after the engine is created, and a rejected updateMask rejects the whole patch — so the features map (the FedRAMP High allow/deny list: disable-google-drive-upload, disable-image-generation, notebook-lm off, and so on) is not written either. The CLI catches the exception, prints it, and continues to the widget, assistant and project patches, then prints Compliance configuration complete!. An operator reading the summary believes the engine is hardened; it carries whatever feature states it was created with. When the engine came from the blueprint's Terraform (gemini-stage-0/discovery-engine.tf, which sets the features and disable_analytics at create) the end state happens to be right; an engine created any other way, or one whose features were changed in the console, is left as it was.
Environment and Deployment Context
- Stellar Engine Version/Commit:
v4.0.0(6d7d08c0);gem4gov-cli/gem4gov.pylines 1403-1436 (configure_gemini_enterprise_for_fedramp_high), the same pattern at 1516-1550 (IL4) and 1628-1660 (IL5), and inonboard. - Deployment Type:
- US Region Restricted (e.g., Access Policy constraint)
- FedRAMP Moderate
- FedRAMP High
- DoD IL4
- DoD IL5
- Stand-alone / Custom
- FAST Stage (if applicable): none —
blueprints/fedramp-high/gemini-enterprise/gem4gov-cli
Steps to Reproduce
- Deploy
gemini-stage-0(Brownfield) so an engine exists;gem4gov initagainst the project. gem4gov app update-compliance --project-id <project> --engine-id <engine> --compliance-regime FEDRAMP_HIGH.- Observe the
HttpError 400 ... immutable path "disable_analytics"line, followed byCompliance configuration complete!.
Expected Behavior
The engine patch applies the regime's feature states (an updateMask of features alone succeeds), or the command fails loudly when it cannot.
Actual Behavior
The engine patch is rejected in full; the command reports success.
Relevant Logs and Errors
See above; reproduced twice on 2026-09-21 on a fresh Brownfield deployment (the second time on an engine recreated through Helper Functions > Replace Gemini Enterprise Application).
Additional Context
- Suggested fix: send
updateMask=features(dropdisableAnalyticsfrom the patch — it is set at create by the blueprint and cannot change), and treat the engine patch's failure as a failure of the command.
- Dominant language
- HCL
- Stars
- 51
- Forks
- 21
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 30
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from google/stellar-engine
-
documentation Level of Effort - High Priority - Medium
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
google/stellar-engine#232 ·
Maintainers usually reply within 2 days
-
Bug Gemini - Government Level of Effort - Low Priority - Low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
google/stellar-engine#135 ·
Maintainers usually reply within 2 days
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandOpenEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
google/stellar-engine#122 ·
Maintainers usually reply within 2 days
-
documentation Level of Effort - Medium Priority - Medium
Difficulty 2/5 Half a day Newbie friendliness 72/100
google/stellar-engine#117 · 1 comment ·
Maintainers usually reply within 2 days
-
[Feature Request] No research blueprint family — the README names universities as a target audience, every blueprint is FedRAMP High, FedRAMP Moderate or IL5Possibly taken @Calvin-Cheng1 claimed this 19 days ago. Openenhancement
google/stellar-engine#239 · 2 comments · 1 assignee ·
Maintainers usually reply within 2 days
All issues in google/stellar-engine
Similar issues
-
area: capture good first issue priority: P2 type: defect
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
jiegui2025/hwspec#51 ·
Maintainers usually reply within 1 day
-
[Feature]:Openenhancement
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
thephpleague/commonmark#1159 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
EchoTools/nevr-runtime#117 · 2 comments ·
Maintainers usually reply within 1 day
-
Proxy drops log notifications from backends that don't send FastMCP's msg/extra dictPossibly taken @asasemahmed claimed this today. Openbug server
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day