Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Documentation] docs/ddg.md: billing_override under three later stages still names 1-resman's tfvars, the enable-services fallback one-liner cannot work, and the Stage 0 Assured Workloads note quotes the wrong error and a folder that does not exist

クローズ 初心者向け
#258 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
90/100
issue の種類
ドキュメント
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
bash, google-cloud, terraform

調査の方向性

docs/ddg.md の issue で特定された 4 つの箇所から始め、stage 変数の宣言、enableServices.sh、0-bootstrap/organization.tf への参照を比較します。fallback コマンドで各サービスを個別に有効化できること、またドキュメントに正しい stage ファイル、エラーテキスト、フォルダーが記載されていることを確認します。完了とは、docs/ddg.md 以外を変更せずに、4 つの箇所すべてが正確になっていることを意味します。

索引モデルが issue の本文から書いたものです。

説明

Documentation Level of Effort - Low Priority - Medium

Description of Documentation Need

PR #245 refreshed docs/ddg.md to v4.0.0 and closed #242. Four passages it did not reach are still wrong at v4.0.1 (d9adab8f) and on main (397fc2ee); line numbers below are from main. They are the same class as the ones #242 listed: text carried forward from an earlier stage or an earlier version without being updated.

1. The billing_override note under three later stages names Stage 1's tfvars. The external-billing note ("If you are using an external billing account where the ... service account cannot be granted billing permissions, you can use a billing override ...") appears four times. Under Stage 1 - Resource Management (line 321) it correctly says to define billing_override in fast/stages-aw/1-resman/terraform.tfvars. The three later copies name the same file:

  • FedRAMP High / Moderate - Stage 2.1 Networking, line 413: "define the billing_override variable in fast/stages-aw/1-resman/terraform.tfvars file"
  • IL4/IL5 Stage 2.1 - Networking, line 471: the same sentence
  • Stage 3 - Security and Audit Account Configuration, line 561: the same sentence, and it still says "where the networking service account cannot be granted billing permissions" — the note four lines above it (557) names the Stage 3 account, <prefix>-security-0@<prefix>-prod-iac-core-0.iam.gserviceaccount.com

Each of those stages declares its own billing_override (2-networking-a-fedramp/variables.tf:195, 2-networking-b-il5-ngfw/variables.tf:49, 3-security/variables.tf:56), and by the time a reader reaches these sections Stage 1 has already been applied, so following the note as written puts the value in a stage that no longer runs.

2. The enable-services fallback one-liner in the Prerequisites cannot work as written (line 172, offered under "If you run into issues with the above command [enableServices.sh], you can simply run the following deprecated command"):

echo "iam cloudkms pubsub serviceusage cloudresourcemanager bigquery assuredworkloads cloudbilling logging iamcredentials orgpolicy" | xargs -n1 -I {} gcloud services enable "{}.googleapis.com"

xargs -I implies one line per invocation and overrides -n1 (xargs warns: "options --max-args and --replace/-I/-i are mutually exclusive, ignoring previous --max-args value"), so the whole space-separated list is passed as ONE service name and gcloud answers PERMISSION_DENIED: Not found or permission denied for service(s): iam cloudkms pubsub ... orgpolicy.googleapis.com. Reproduced on Ubuntu 24.04 with the SDK's gcloud on 2026-09-18. A reader who reaches this line is, by the guide's own framing, someone whose first attempt already failed — and the fallback fails too.

3. The Stage 0 note quotes an error Terraform does not print (lines 274–275): "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." What terraform apply actually prints at v4.0.0 / v4.0.1 is

Error: Error creating Dataset: googleapi: Error 403: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint for 'projects/<number>' attempting to use service 'bigquery.googleapis.com'., accessDenied

(the Assured Workloads folder enforces gcp.restrictServiceUsage). The fix the note gives is right; quoting the error the reader will actually see (restrictServiceUsage ... bigquery.googleapis.com) is what lets them recognize it. Seen on a fresh FedRAMP High Stage 0 apply on 2026-09-18.

4. The same note names a folder that does not exist (line 278): "Click the StellarEngine-<compliance_regime> folder". The Assured Workloads folder 0-bootstrap creates is StellarEngine-<prefix> (0-bootstrap/organization.tf:192, display_name = "StellarEngine-${var.prefix}", and again at :198 and :213); there is no folder named for the regime.

Target Audience

Operators deploying a FAST landing zone from the guide for the first time — the audience that hits each of these exactly once, at the moment it costs the most: item 1 when a stage's project creation fails on billing, item 2 when the primary enable script has already failed, items 3–4 while reading a Terraform error they cannot match to the note.

Proposed Location

docs/ddg.md — the four passages above; no other file is involved.

Content Outline / Draft

  1. Lines 413, 471, 561: **fast/stages-aw/1-resman/terraform.tfvars** → the section's own stage — **fast/stages-aw/2-networking-a-fedramp/terraform.tfvars**, **fast/stages-aw/2-networking-b-il5-ngfw/terraform.tfvars**, **fast/stages-aw/3-security/terraform.tfvars** respectively — and on line 561 "the networking service account" → "the security service account".
  2. Line 172: either drop -I {} and let -n1 pass each word (... | xargs -n1 sh -c 'gcloud services enable "$0.googleapis.com"'), or ... | tr ' ' '\n' | xargs -I {} gcloud services enable {}.googleapis.com, or simply list the services on one gcloud services enable call — which is also what enableServices.sh does.
  3. Lines 274–275: "You may receive an error in this stage where it reports that bigquery.googleapis.com is not usable in the Assured Workloads." → "You may receive a 403 in this stage: Request is disallowed by organization's constraints/gcp.restrictServiceUsage constraint ... attempting to use service 'bigquery.googleapis.com'."
  4. Line 278: StellarEngine- <compliance_regime> → StellarEngine- <prefix>.

Compliance Context (if applicable)

None of the four changes a control. Item 4 sits in the Assured Workloads remediation step, so a reader looking for a folder that does not exist is a reader who cannot complete the step that brings BigQuery into the regime's service set.

主要言語
HCL
スター
51
フォーク
21
平均マージ
1日 15時間
マージ済み PR(30日)
30

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

google/stellar-engine のほかの issue

google/stellar-engine の issue をすべて見る

似ている issue

Cloud の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。