[Documentation] docs/ddg.md: billing_override under three later stages still names 1-resman's tfvars, the enable-services fallback one-liner cannot work, and the Stage 0 Assured Workloads note quotes the wrong error and a folder that does not exist
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 90/100
- issue の種類
- ドキュメント
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- bash, google-cloud, terraform
調査の方向性
docs/ddg.md の issue で特定された 4 つの箇所から始め、stage 変数の宣言、enableServices.sh、0-bootstrap/organization.tf への参照を比較します。fallback コマンドで各サービスを個別に有効化できること、またドキュメントに正しい stage ファイル、エラーテキスト、フォルダーが記載されていることを確認します。完了とは、docs/ddg.md 以外を変更せずに、4 つの箇所すべてが正確になっていることを意味します。
索引モデルが issue の本文から書いたものです。
説明
Description of Documentation Need
PR #245 refreshed docs/ddg.md to v4.0.0 and closed #242. Four passages it did not reach are still wrong at v4.0.1 (d9adab8f) and on main (397fc2ee); line numbers below are from main. They are the same class as the ones #242 listed: text carried forward from an earlier stage or an earlier version without being updated.
1. The billing_override note under three later stages names Stage 1's tfvars. The external-billing note ("If you are using an external billing account where the ... service account cannot be granted billing permissions, you can use a billing override ...") appears four times. Under Stage 1 - Resource Management (line 321) it correctly says to define billing_override in fast/stages-aw/1-resman/terraform.tfvars. The three later copies name the same file:
- FedRAMP High / Moderate - Stage 2.1 Networking, line 413: "define the
billing_overridevariable in fast/stages-aw/1-resman/terraform.tfvars file" - IL4/IL5 Stage 2.1 - Networking, line 471: the same sentence
- Stage 3 - Security and Audit Account Configuration, line 561: the same sentence, and it still says "where the networking service account cannot be granted billing permissions" — the note four lines above it (557) names the Stage 3 account,
<prefix>-security-0@<prefix>-prod-iac-core-0.iam.gserviceaccount.com
Each of those stages declares its own billing_override (2-networking-a-fedramp/variables.tf:195, 2-networking-b-il5-ngfw/variables.tf:49, 3-security/variables.tf:56), and by the time a reader reaches these sections Stage 1 has already been applied, so following the note as written puts the value in a stage that no longer runs.
2. The enable-services fallback one-liner in the Prerequisites cannot work as written (line 172, offered under "If you run into issues with the above command [enableServices.sh], you can simply run the following deprecated command"):
echo "iam cloudkms pubsub serviceusage cloudresourcemanager bigquery assuredworkloads cloudbilling logging iamcredentials orgpolicy" | xargs -n1 -I {} gcloud services enable "{}.googleapis.com"
xargs -I implies one line per invocation and overrides -n1 (xargs warns: "options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value"), so the whole space-separated list is passed as ONE service name and gcloud answers PERMISSION_DENIED: Not found or permission denied for service(s): iam cloudkms pubsub ... orgpolicy.googleapis.com. Reproduced on Ubuntu 24.04 with the SDK's gcloud on 2026-09-18. A reader who reaches this line is, by the guide's own framing, someone whose first attempt already failed — and the fallback fails too.
3. The Stage 0 note quotes an error Terraform does not print (lines 274–275): "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." What terraform apply actually prints at v4.0.0 / v4.0.1 is
Error: Error creating Dataset: googleapi: Error 403: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint for 'projects/<number>' attempting to use service 'bigquery.googleapis.com'., accessDenied
(the Assured Workloads folder enforces gcp.restrictServiceUsage). The fix the note gives is right; quoting the error the reader will actually see (restrictServiceUsage ... bigquery.googleapis.com) is what lets them recognize it. Seen on a fresh FedRAMP High Stage 0 apply on 2026-09-18.
4. The same note names a folder that does not exist (line 278): "Click the StellarEngine-<compliance_regime> folder". The Assured Workloads folder 0-bootstrap creates is StellarEngine-<prefix> (0-bootstrap/organization.tf:192, display_name = "StellarEngine-${var.prefix}", and again at :198 and :213); there is no folder named for the regime.
Target Audience
Operators deploying a FAST landing zone from the guide for the first time — the audience that hits each of these exactly once, at the moment it costs the most: item 1 when a stage's project creation fails on billing, item 2 when the primary enable script has already failed, items 3–4 while reading a Terraform error they cannot match to the note.
Proposed Location
docs/ddg.md — the four passages above; no other file is involved.
Content Outline / Draft
- Lines 413, 471, 561:
**fast/stages-aw/1-resman/terraform.tfvars**→ the section's own stage —**fast/stages-aw/2-networking-a-fedramp/terraform.tfvars**,**fast/stages-aw/2-networking-b-il5-ngfw/terraform.tfvars**,**fast/stages-aw/3-security/terraform.tfvars**respectively — and on line 561 "the networking service account" → "the security service account". - Line 172: either drop
-I {}and let-n1pass each word (... | xargs -n1 sh -c 'gcloud services enable "$0.googleapis.com"'), or... | tr ' ' '\n' | xargs -I {} gcloud services enable {}.googleapis.com, or simply list the services on onegcloud services enablecall — which is also whatenableServices.shdoes. - Lines 274–275: "You may receive an error in this stage where it reports that
bigquery.googleapis.comis not usable in the Assured Workloads." → "You may receive a403in this stage:Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint ... attempting to use service 'bigquery.googleapis.com'." - Line 278:
StellarEngine-<compliance_regime>→StellarEngine-<prefix>.
Compliance Context (if applicable)
None of the four changes a control. Item 4 sits in the Assured Workloads remediation step, so a reader looking for a folder that does not exist is a reader who cannot complete the step that brings BigQuery into the regime's service set.
- 主要言語
- HCL
- スター
- 51
- フォーク
- 21
- 平均マージ
- 1日 15時間
- マージ済み PR(30日)
- 30
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
google/stellar-engine のほかの issue
-
documentation Level of Effort - High Priority - Medium
難易度 1/5 1〜3時間 初心者へのやさしさ 88/100
google/stellar-engine#232 ·
メンテナーはふだん 2 日以内に返信
-
Bug Gemini - Government Level of Effort - Low Priority - Low
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
google/stellar-engine#135 ·
メンテナーはふだん 2 日以内に返信
-
[Feature Request] gem4gov: implement BigQuery import in the standalone datastore import commandオープンEnhancement Gemini - Government Level of Effort - Medium Priority - Medium
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
google/stellar-engine#122 ·
メンテナーはふだん 2 日以内に返信
-
documentation Level of Effort - Medium Priority - Medium
難易度 2/5 半日 初心者へのやさしさ 72/100
google/stellar-engine#117 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
bug documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
google/stellar-engine#91 ·
メンテナーはふだん 2 日以内に返信
google/stellar-engine の issue をすべて見る
似ている issue
-
area: cli area: cloud bug difficulty:2 help wanted S3: minor
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
manaflow-ai/cmux#15691 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
@aws-cdk/aws-bedrock-alpha needs-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
Tools4everBV/HelloID-Conn-Prov-Target-Microsoft-Entra-ID-Exchange-Online#52 ·
-
jira
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
coreos/fedora-coreos-tracker#2231 · コメント 1 件 ·
-
bug good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
juspay/xyne-spaces#2452 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信