[Feature Request] No FedRAMP Moderate blueprint family — the platform supports FRM but every workload blueprint is still FedRAMP High or IL5 only
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 38/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- google-cloud
- 領域
- cloud, infrastructure, security
調査の方向性
blueprints/ から始め、v2.13.0 と v3.0.0 における既存の 4 つのファミリーを比較し、その後 FAST のステージ 0-bootstrap、1-resman、2-networking、3-security と networking-stage README を読みます。リポジトリに FedRAMP Moderate ワークロードのカバレッジに関する決定済みで文書化されたアプローチがあり、既存の blueprints のうち安全なものと変更が必要なものが特定されていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Feature Description
blueprints/ contains four families — fedramp-high, il5, stand-alone and third-party-solutions. There is no fedramp-moderate family, and the tree is identical at v2.13.0 and v3.0.0. Meanwhile the platform itself gained FedRAMP Moderate support in v3.0.0: kms_protection_level is now a variable across 0-bootstrap, 1-resman, 2-networking and 3-security, and the networking stage README is now "FedRAMP High / Moderate Network".
So an operator can now stand up a FedRAMP Moderate landing zone and then has no blueprint written for that regime to deploy a workload into it.
Use Case
FedRAMP Moderate is the larger share of federal and state workloads, and the reason to choose it over High is usually cost and operational burden — Moderate permits SOFTWARE protection level where High typically requires HSM, for example. Today that saving stops at the landing-zone boundary: the moment a team deploys Cloud SQL, App Engine, Cloud Run or Gemini Enterprise, the only blueprints available are the FedRAMP High ones, which carry High's controls and costs.
The practical outcomes are all bad: deploy the High blueprint into a Moderate environment and inherit controls (and spend) the regime does not require; hand-roll a Moderate variant and lose the reusability the repository exists to provide; or fall back to High for the whole deployment and lose the reason for choosing Moderate.
Proposed Solution
Either a blueprints/fedramp-moderate/ family, or — probably better given the overlap — a regime input on the existing blueprints so one blueprint can emit the correct posture per regime, in the same spirit as kms_protection_level in the FAST stages. A statement of intent would help on its own: even a README note saying which blueprints are safe to use unmodified under Moderate, and which are not, would unblock planning.
Compliance & Deployment Context
- Target Deployment Type(s):
- US Region Restricted (e.g., Access Policy constraint)
- FedRAMP Medium
- FedRAMP High
- FedRAMP Moderate
- DoD IL4
- DoD IL5
- All / General
- Relevant NIST 800-53r5 Controls: SC-12 / SC-13 (key management and protection level are where High and Moderate visibly diverge today); CM-6 for the baseline the blueprints encode.
Reusability Check
- I have checked if this functionality can be achieved by extending an existing module or blueprint.
- I have verified that this does not duplicate existing functionality.
Extending the existing blueprints is exactly what is proposed above — a new parallel tree is the alternative, not the preference. On duplication: #102 is open and covers only the gemini-enterprise blueprint; #101, the platform-level request, is closed as completed. Nothing covers the rest of the blueprint library.
Alternatives Considered
Deploying the FedRAMP High blueprints into a Moderate environment — works, but over-controls and over-spends, and misrepresents the deployed posture in an SSP. Forking a blueprint per customer — loses reusability and drifts from upstream fixes. Widening #102 to cover all blueprints — possible, but its title and body are scoped to Gemini Enterprise, so a separate request tracks better.
Additional Context
Verified against the repository tree at v2.13.0 (8f5b67a6) and v3.0.0 (f64ce6cd): the four blueprint families are unchanged between the two tags.
- 主要言語
- HCL
- スター
- 51
- フォーク
- 21
- 平均マージ
- 1日 16時間
- マージ済み PR(30日)
- 30
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
google/stellar-engine のほかの issue
-
documentation Level of Effort - High Priority - Medium
難易度 1/5 1〜3時間 初心者へのやさしさ 88/100
google/stellar-engine#232 ·
メンテナーはふだん 2 日以内に返信
-
Bug Gemini - Government Level of Effort - Low Priority - Low
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
google/stellar-engine#135 ·
メンテナーはふだん 2 日以内に返信
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandオープンEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
google/stellar-engine#122 ·
メンテナーはふだん 2 日以内に返信
-
documentation Level of Effort - Medium Priority - Medium
難易度 2/5 半日 初心者へのやさしさ 72/100
google/stellar-engine#117 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
[Feature Request] No research blueprint family — the README names universities as a target audience, every blueprint is FedRAMP High, FedRAMP Moderate or IL5対応中かも @Calvin-Cheng1 が 19 日前に担当しました。 オープンenhancement
google/stellar-engine#239 · コメント 2 件 · 担当者 1 名 ·
メンテナーはふだん 2 日以内に返信
google/stellar-engine の issue をすべて見る
似ている issue
-
area: providers/aws priority: p2 size: S type: bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
finos/open-resource-broker#418 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
GCP region parser selects the wrong region for multi-digit region numbers対応中かも @nawaaaaaAaar が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
mlco2/codecarbon#1438 ·
メンテナーはふだん 1 日以内に返信
-
bug needs-triage service/agentregistry
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
hashicorp/terraform-provider-aws#50277 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
enhancement internal-synced
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
-
azureblob: sync at the account root fails on soft deleted containers and deletes nothing対応中かも @LudovicBondon が今日担当しました。 オープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
メンテナーはふだん 3 日以内に返信