Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug] Fix Custom KMS Organizational Policy

Open
#57 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 2 days

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
google-cloud, terraform

Research direction

Start by reproducing a Terraform destroy of KMS keys under the current custom KMS organization policy, then inspect the custom KMS policy configurations and the rotation-period constraint involved. Done means Terraform can delete or update the keys without an organization-policy conflict.

Written by the indexing model from the issue text.

Description

bug

Bug Description

A custom KMS organization policy bug prevents Terraform from deleting encryption keys.

Environment and Deployment Context

Please provide details about your deployment to help us reproduce the issue.

  • Stellar Engine Version/Commit: main
  • Deployment Type:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Medium
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • All / General
  • FAST Stage (if applicable):
    • Stage 0 (Bootstrap)
    • Stage 1 (Resource Management)
    • Stage 2 (Network Creation)
    • Stage 3 (Security and Audit)
  • Affected Component: Custom KMS Org Policy configurations.
  • Terraform Version: 1.5.7
  • GCP Provider Version: 5.10.0

Steps to Reproduce

Steps to reproduce the behavior:

  1. Deploy KMS keys under the current custom KMS organization policy.
  2. Attempt to destroy or delete the keys via Terraform.
  3. See error related to violating constraints on unsetting rotation periods.

Expected Behavior

Terraform should be able to cleanly delete or manage the lifecycle of KMS keys without Org Policy conflicts.

Actual Behavior

The custom KMS organization policy prevents key deletion, blocking automated teardowns and updates.

Relevant Logs and Errors

N/A

Additional Context

The proposed fix is to modify the custom KMS organization policy or find a workaround to bypass the rotation period constraint during deletion.

Dominant language
HCL
Stars
51
Forks
21
Avg merge
1d 15h
Merged PRs (30d)
30

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from google/stellar-engine

All issues in google/stellar-engine

Similar issues

More Cloud issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.