Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Bug] 2-networking-a-fedramp: the hierarchical firewall policy defaults to the unprefixed name net-default, which is unique per organization — a second deployment in the same org (a redeploy under a new prefix) fails at apply

クローズ
#254 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
78/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
google-cloud, terraform

調査の方向性

Start with fast/stages-aw/2-networking-a-fedramp/main.tf:44-47 and variables.tf:78, then compare the naming guidance in docs/ddg.md, the stage README, and terraform.tfvars.sample. Reproduce the Stage 2 redeployment with a second prefix and inspect the hierarchical firewall policy failure. Done means deployments in one organization no longer collide, or the required organization-unique setting is documented in the named guides and sample.

索引モデルが issue の本文から書いたものです。

説明

Bug Level of Effort - Low Priority - Low

Bug Description

fast/stages-aw/2-networking-a-fedramp/main.tf:44-47 creates the stage's hierarchical firewall policy with
name = var.factories_config.firewall_policy_name, whose default (variables.tf:78) is "net-default". A hierarchical firewall policy's short name must be unique within the organization, and every other resource the stage names carries var.prefix. So the second deployment of the stage in an organization — the case the project's own guidance creates, since project IDs are never reusable and a rebuild has to use a new prefix — fails at apply, 320 of 322 resources in:

Error: Error creating FirewallPolicy: googleapi: Error 400: Invalid value for field 'resource.shortName': 'net-default'. The display name is already used. Please choose another one, invalid

  with module.firewall-policy-default.google_compute_firewall_policy.hierarchical[0],
  on ../../../modules/net-firewall-policy/hierarchical.tf line 17, in resource "google_compute_firewall_policy" "hierarchical":

The operator can set factories_config.firewall_policy_name in terraform.tfvars, but nothing in docs/ddg.md, the stage README or terraform.tfvars.sample says the name is org-unique or that a second deployment must change it.

Environment and Deployment Context

  • Stellar Engine Version/Commit: v4.0.0 (6d7d08c0); unchanged on main (20830097, 2026-09-18).
  • Deployment Type:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • Stand-alone / Custom
  • FAST Stage (if applicable):
    • Stage 0 (Bootstrap)
    • Stage 1 (Resource Management)
    • Stage 2 (Networking)
    • Stage 3 (Security)

Steps to Reproduce

  1. Deploy Stages 0–2 in an organization with prefix A.
  2. Deploy Stages 0–2 again in the same organization with prefix B (a rebuild, or a second landing zone for testing), following docs/ddg.md.
  3. Stage 2's terraform apply for prefix B fails on module.firewall-policy-default.google_compute_firewall_policy.hierarchical[0] with the error above; everything else in the stage applies.

Expected Behavior

The policy name carries the prefix like the stage's other resources ("${var.prefix}-net-default"), so two deployments in one organization do not collide — or the guide states that factories_config.firewall_policy_name must be unique per organization and must be set for a second deployment.

Actual Behavior

The default collides; the operator discovers factories_config.firewall_policy_name by reading variables.tf.

Relevant Logs and Errors

See above.

Additional Context

  • Suggested fix: firewall_policy_name = optional(string) with the stage defaulting it to "${var.prefix}-net-default" when unset (the same pattern as the stage's VPC, subnet and NVA names); or, at minimum, a note in docs/ddg.md under Stage 2.1 and in terraform.tfvars.sample.
  • Related: #228 (the prefix's length arithmetic) is about the same design principle — the prefix is what keeps one organization's deployments apart.
主要言語
HCL
スター
51
フォーク
21
平均マージ
1日 17時間
マージ済み PR(30日)
29

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

google/stellar-engine のほかの issue

google/stellar-engine の issue をすべて見る

似ている issue

Cloud の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。