[Bug] 2-networking-a-fedramp: the hierarchical firewall policy defaults to the unprefixed name net-default, which is unique per organization — a second deployment in the same org (a redeploy under a new prefix) fails at apply
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 78/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- google-cloud, terraform
- 領域
- cloud, infrastructure
調査の方向性
Start with fast/stages-aw/2-networking-a-fedramp/main.tf:44-47 and variables.tf:78, then compare the naming guidance in docs/ddg.md, the stage README, and terraform.tfvars.sample. Reproduce the Stage 2 redeployment with a second prefix and inspect the hierarchical firewall policy failure. Done means deployments in one organization no longer collide, or the required organization-unique setting is documented in the named guides and sample.
索引モデルが issue の本文から書いたものです。
説明
Bug Description
fast/stages-aw/2-networking-a-fedramp/main.tf:44-47 creates the stage's hierarchical firewall policy with
name = var.factories_config.firewall_policy_name, whose default (variables.tf:78) is "net-default". A hierarchical firewall policy's short name must be unique within the organization, and every other resource the stage names carries var.prefix. So the second deployment of the stage in an organization — the case the project's own guidance creates, since project IDs are never reusable and a rebuild has to use a new prefix — fails at apply, 320 of 322 resources in:
Error: Error creating FirewallPolicy: googleapi: Error 400: Invalid value for field 'resource.shortName': 'net-default'. The display name is already used. Please choose another one, invalid
with module.firewall-policy-default.google_compute_firewall_policy.hierarchical[0],
on ../../../modules/net-firewall-policy/hierarchical.tf line 17, in resource "google_compute_firewall_policy" "hierarchical":
The operator can set factories_config.firewall_policy_name in terraform.tfvars, but nothing in docs/ddg.md, the stage README or terraform.tfvars.sample says the name is org-unique or that a second deployment must change it.
Environment and Deployment Context
- Stellar Engine Version/Commit:
v4.0.0(6d7d08c0); unchanged onmain(20830097, 2026-09-18). - Deployment Type:
- US Region Restricted (e.g., Access Policy constraint)
- FedRAMP Moderate
- FedRAMP High
- DoD IL4
- DoD IL5
- Stand-alone / Custom
- FAST Stage (if applicable):
- Stage 0 (Bootstrap)
- Stage 1 (Resource Management)
- Stage 2 (Networking)
- Stage 3 (Security)
Steps to Reproduce
- Deploy Stages 0–2 in an organization with prefix A.
- Deploy Stages 0–2 again in the same organization with prefix B (a rebuild, or a second landing zone for testing), following
docs/ddg.md. - Stage 2's
terraform applyfor prefix B fails onmodule.firewall-policy-default.google_compute_firewall_policy.hierarchical[0]with the error above; everything else in the stage applies.
Expected Behavior
The policy name carries the prefix like the stage's other resources ("${var.prefix}-net-default"), so two deployments in one organization do not collide — or the guide states that factories_config.firewall_policy_name must be unique per organization and must be set for a second deployment.
Actual Behavior
The default collides; the operator discovers factories_config.firewall_policy_name by reading variables.tf.
Relevant Logs and Errors
See above.
Additional Context
- Suggested fix:
firewall_policy_name = optional(string)with the stage defaulting it to"${var.prefix}-net-default"when unset (the same pattern as the stage's VPC, subnet and NVA names); or, at minimum, a note indocs/ddg.mdunder Stage 2.1 and interraform.tfvars.sample. - Related: #228 (the prefix's length arithmetic) is about the same design principle — the prefix is what keeps one organization's deployments apart.
- 主要言語
- HCL
- スター
- 51
- フォーク
- 21
- 平均マージ
- 1日 17時間
- マージ済み PR(30日)
- 29
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
google/stellar-engine のほかの issue
-
documentation Level of Effort - High Priority - Medium
難易度 1/5 1〜3時間 初心者へのやさしさ 88/100
google/stellar-engine#232 ·
メンテナーはふだん 2 日以内に返信
-
Bug Gemini - Government Level of Effort - Low Priority - Low
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
google/stellar-engine#135 ·
メンテナーはふだん 2 日以内に返信
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandオープンEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
google/stellar-engine#122 ·
メンテナーはふだん 2 日以内に返信
-
documentation Level of Effort - Medium Priority - Medium
難易度 2/5 半日 初心者へのやさしさ 72/100
google/stellar-engine#117 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
[Feature Request] No research blueprint family — the README names universities as a target audience, every blueprint is FedRAMP High, FedRAMP Moderate or IL5対応中かも @Calvin-Cheng1 が 20 日前に担当しました。 オープンenhancement
google/stellar-engine#239 · コメント 2 件 · 担当者 1 名 ·
メンテナーはふだん 2 日以内に返信
google/stellar-engine の issue をすべて見る
似ている issue
-
kind/bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
ansible-collections/community.aws#2503 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
denoland/svelte-adapter#28 · コメント 3 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
メンテナーはふだん 1 日以内に返信