Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Bug] gem4gov app update-compliance: the engine patch is rejected (updateMask contains the immutable path disable_analytics), so the compliance feature states are never applied by the command

クローズ
#259 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
76/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
google-cloud, python
領域
api, cli, cloud

調査の方向性

Start in gem4gov-cli/gem4gov.py at configure_gemini_enterprise_for_fedramp_high (lines 1403-1436), then inspect the corresponding IL4, IL5, and onboard engine patches. Reproduce the update-compliance command against an existing engine and verify that the compliance feature states are applied or that an engine-patch error makes the command fail instead of reporting completion.

索引モデルが issue の本文から書いたものです。

説明

Bug Level of Effort - Low Priority - Medium

Bug Description

gem4gov app update-compliance --compliance-regime FEDRAMP_HIGH (and the same code on the IL4/IL5 paths and in onboard) patches the engine with the body {"features": <engine_features.yaml>, "disableAnalytics": true} and updateMask=features,disableAnalytics (gem4gov-cli/gem4gov.py:1420-1436 at v4.0.0). Discovery Engine rejects the call:

An error occurred while configuring the engine for FedRAMP High: <HttpError 400 when requesting
https://us-discoveryengine.googleapis.com/v1alpha/projects/<project>/locations/us/collections/default_collection/engines/<engine>?updateMask=features%2CdisableAnalytics&alt=json
returned "Field "updateMask" contains an immutable path "disable_analytics".">

disableAnalytics is immutable after the engine is created, and a rejected updateMask rejects the whole patch — so the features map (the FedRAMP High allow/deny list: disable-google-drive-upload, disable-image-generation, notebook-lm off, and so on) is not written either. The CLI catches the exception, prints it, and continues to the widget, assistant and project patches, then prints Compliance configuration complete!. An operator reading the summary believes the engine is hardened; it carries whatever feature states it was created with. When the engine came from the blueprint's Terraform (gemini-stage-0/discovery-engine.tf, which sets the features and disable_analytics at create) the end state happens to be right; an engine created any other way, or one whose features were changed in the console, is left as it was.

Environment and Deployment Context

  • Stellar Engine Version/Commit: v4.0.0 (6d7d08c0); gem4gov-cli/gem4gov.py lines 1403-1436 (configure_gemini_enterprise_for_fedramp_high), the same pattern at 1516-1550 (IL4) and 1628-1660 (IL5), and in onboard.
  • Deployment Type:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • Stand-alone / Custom
  • FAST Stage (if applicable): none — blueprints/fedramp-high/gemini-enterprise/gem4gov-cli

Steps to Reproduce

  1. Deploy gemini-stage-0 (Brownfield) so an engine exists; gem4gov init against the project.
  2. gem4gov app update-compliance --project-id <project> --engine-id <engine> --compliance-regime FEDRAMP_HIGH.
  3. Observe the HttpError 400 ... immutable path "disable_analytics" line, followed by Compliance configuration complete!.

Expected Behavior

The engine patch applies the regime's feature states (an updateMask of features alone succeeds), or the command fails loudly when it cannot.

Actual Behavior

The engine patch is rejected in full; the command reports success.

Relevant Logs and Errors

See above; reproduced twice on 2026-09-21 on a fresh Brownfield deployment (the second time on an engine recreated through Helper Functions > Replace Gemini Enterprise Application).

Additional Context

  • Suggested fix: send updateMask=features (drop disableAnalytics from the patch — it is set at create by the blueprint and cannot change), and treat the engine patch's failure as a failure of the command.
主要言語
HCL
スター
55
フォーク
21
平均マージ
1日 16時間
マージ済み PR(30日)
23

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

google/stellar-engine のほかの issue

google/stellar-engine の issue をすべて見る

似ている issue

Backend & API Design の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。