Skip to content

[Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed #196

Description

@JohnHales

Bug Description

v3.0.0 renamed fast/stages-aw/2-networking-a-fedramp-high to fast/stages-aw/2-networking-a-fedramp, but the documentation was only partly swept. docs/ddg.md still instructs operators to change directory into the old path, twice — at line 429, inside the section headed "FedRAMP High / Moderate - Stage 2.1 Networking", and again at line 639 under "Apply FAST Stage: 02-networking". Following the deployment guide on v3.0.0 or main therefore fails at the networking stage. docs/tdd.md:617 also still lists the old directory in its repository-structure tree.

The sweep was partial rather than missed entirely: docs/tdd.md:946was updated and now reads "FedRAMP High / Moderate Pattern (2-networking-a-fedramp)", so the design section is current while the deployment steps and the tree listing are not. The DDG is the document an operator follows end to end, so a wrong path there is a hard stop rather than a cosmetic inconsistency.

Environment and Deployment Context

  • Stellar Engine Version/Commit:main (also reproduces at the v3.0.0 tag, f64ce6cd)
  • Deployment Type:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Medium
    • FedRAMP High
    • FedRAMP Moderate
    • DoD IL4
    • DoD IL5
    • Stand-alone / Custom
  • FAST Stage (if applicable):
    • Stage 0 (Bootstrap)
    • Stage 1 (Resource Management)
    • Stage 2 (Network Creation)
    • Stage 3 (Security and Audit)
  • Affected Component:docs/ddg.md, docs/tdd.md, fast/stages-aw/2-networking-a-fedramp
  • Terraform Version: not reached — the guide fails before terraform init (our environment runs 1.15.7)
  • GCP Provider Version: not reached (our environment pins hashicorp/google6.50.0)

Steps to Reproduce

  1. Clone the repository at main, or check out the v3.0.0 tag.
  2. Open docs/ddg.md and go to the section "FedRAMP High / Moderate - Stage 2.1 Networking".
  3. Follow the step at line 429: "Change directory into fast/stages-aw/2-networking-a-fedramp-high".
  4. The directory does not exist. The same instruction appears again at line 639.

Expected Behavior

The deployment guide names a directory that exists in the tree it ships with, so an operator can follow the FedRAMP High / Moderate networking stage from start to finish without having to discover the correct path themselves.

Actual Behavior

The path does not exist at v3.0.0 or main. Verified against the repository tree: fast/stages-aw/ contains 2-networking-a-fedramp-high at 8f5b67a6 (v2.13.0) and at 3728fc98, and 2-networking-a-fedramp at f64ce6cd (v3.0.0) and at main. The rename landed in #162 (7033b8cc, merged 2026-08-10), with README updates in #173.

ReferencePath namedCorrect at main?
docs/ddg.md:429fast/stages-aw/2-networking-a-fedramp-highNo
docs/ddg.md:639fast/stages-aw/2-networking-a-fedramp-highNo
docs/tdd.md:6172-networking-a-fedramp-highNo
docs/tdd.md:9462-networking-a-fedrampYes

Relevant Logs and Errors

$ git checkout v3.0.0
$ cd fast/stages-aw/2-networking-a-fedramp-high
bash: cd: fast/stages-aw/2-networking-a-fedramp-high: No such file or directory
$ ls fast/stages-aw/
0-bootstrap 1-resman 2-networking-a-fedramp 2-networking-b-il5-ngfw 3-security

Additional Context

Migration notes for the rename.releases.md states that major releases "will include detailed migration notes, state refactoring scripts, or step-by-step instructions for upgrading existing environments without unexpected downtime or state drift." Renaming a Terraform root module changes both the working directory and, for anyone whose backend prefix follows the directory, the state location — exactly the case that policy describes. We could not find notes for it: the repository has 15 tags and no published GitHub Releases, and no upgrade or migration document in the tree. Even a short note saying "rename only, no state action required" would close this out for operators upgrading an existing landing zone.

This is the same change discussed in #195, which asks what else about it went unrecorded — that issue is about the design decision behind the rename and is not resolved by fixing these paths.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
       blocks
      (function() {
      function addCopyButtons() {
      document.querySelectorAll('pre code').forEach(function(codeBlock) {
      if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
      codeBlock.parentElement.setAttribute('data-copy-added', 'true');
      var btn = document.createElement('button');
      btn.textContent = 'Copy';
      btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
      btn.onmouseover = function() { this.style.opacity = '1'; };
      btn.onmouseout = function() { this.style.opacity = '0.7'; };
      btn.onclick = function() {
      navigator.clipboard.writeText(codeBlock.textContent).then(function() {
      btn.textContent = 'Copied!';
      setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
      });
      };
      codeBlock.parentElement.style.position = 'relative';
      codeBlock.parentElement.appendChild(btn);
      });
      }
      addCopyButtons();
      // Re-run on dynamic content
      var observer = new MutationObserver(addCopyButtons);
      observer.observe(document.body, { childList: true, subtree: true });
      })();
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed · Issue #196 · google/stellar-engine · GitHub
      Skip to content

      [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed #196

      Description

      @JohnHales

      Bug Description

      v3.0.0 renamed fast/stages-aw/2-networking-a-fedramp-high to fast/stages-aw/2-networking-a-fedramp, but the documentation was only partly swept. docs/ddg.md still instructs operators to change directory into the old path, twice — at line 429, inside the section headed "FedRAMP High / Moderate - Stage 2.1 Networking", and again at line 639 under "Apply FAST Stage: 02-networking". Following the deployment guide on v3.0.0 or main therefore fails at the networking stage. docs/tdd.md:617 also still lists the old directory in its repository-structure tree.

      The sweep was partial rather than missed entirely: docs/tdd.md:946was updated and now reads "FedRAMP High / Moderate Pattern (2-networking-a-fedramp)", so the design section is current while the deployment steps and the tree listing are not. The DDG is the document an operator follows end to end, so a wrong path there is a hard stop rather than a cosmetic inconsistency.

      Environment and Deployment Context

      • Stellar Engine Version/Commit:main (also reproduces at the v3.0.0 tag, f64ce6cd)
      • Deployment Type:
        • US Region Restricted (e.g., Access Policy constraint)
        • FedRAMP Medium
        • FedRAMP High
        • FedRAMP Moderate
        • DoD IL4
        • DoD IL5
        • Stand-alone / Custom
      • FAST Stage (if applicable):
        • Stage 0 (Bootstrap)
        • Stage 1 (Resource Management)
        • Stage 2 (Network Creation)
        • Stage 3 (Security and Audit)
      • Affected Component:docs/ddg.md, docs/tdd.md, fast/stages-aw/2-networking-a-fedramp
      • Terraform Version: not reached — the guide fails before terraform init (our environment runs 1.15.7)
      • GCP Provider Version: not reached (our environment pins hashicorp/google6.50.0)

      Steps to Reproduce

      1. Clone the repository at main, or check out the v3.0.0 tag.
      2. Open docs/ddg.md and go to the section "FedRAMP High / Moderate - Stage 2.1 Networking".
      3. Follow the step at line 429: "Change directory into fast/stages-aw/2-networking-a-fedramp-high".
      4. The directory does not exist. The same instruction appears again at line 639.

      Expected Behavior

      The deployment guide names a directory that exists in the tree it ships with, so an operator can follow the FedRAMP High / Moderate networking stage from start to finish without having to discover the correct path themselves.

      Actual Behavior

      The path does not exist at v3.0.0 or main. Verified against the repository tree: fast/stages-aw/ contains 2-networking-a-fedramp-high at 8f5b67a6 (v2.13.0) and at 3728fc98, and 2-networking-a-fedramp at f64ce6cd (v3.0.0) and at main. The rename landed in #162 (7033b8cc, merged 2026-08-10), with README updates in #173.

      ReferencePath namedCorrect at main?
      docs/ddg.md:429fast/stages-aw/2-networking-a-fedramp-highNo
      docs/ddg.md:639fast/stages-aw/2-networking-a-fedramp-highNo
      docs/tdd.md:6172-networking-a-fedramp-highNo
      docs/tdd.md:9462-networking-a-fedrampYes

      Relevant Logs and Errors

      $ git checkout v3.0.0
      $ cd fast/stages-aw/2-networking-a-fedramp-high
      bash: cd: fast/stages-aw/2-networking-a-fedramp-high: No such file or directory
      $ ls fast/stages-aw/
      0-bootstrap 1-resman 2-networking-a-fedramp 2-networking-b-il5-ngfw 3-security
      

      Additional Context

      Migration notes for the rename.releases.md states that major releases "will include detailed migration notes, state refactoring scripts, or step-by-step instructions for upgrading existing environments without unexpected downtime or state drift." Renaming a Terraform root module changes both the working directory and, for anyone whose backend prefix follows the directory, the state location — exactly the case that policy describes. We could not find notes for it: the repository has 15 tags and no published GitHub Releases, and no upgrade or migration document in the tree. Even a short note saying "rename only, no state action required" would close this out for operators upgrading an existing landing zone.

      This is the same change discussed in #195, which asks what else about it went unrecorded — that issue is about the design decision behind the rename and is not resolved by fixing these paths.

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        bugSomething isn't working

        Type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed · Issue #196 · google/stellar-engine · GitHub
          Skip to content

          [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed #196

          Description

          @JohnHales

          Bug Description

          v3.0.0 renamed fast/stages-aw/2-networking-a-fedramp-high to fast/stages-aw/2-networking-a-fedramp, but the documentation was only partly swept. docs/ddg.md still instructs operators to change directory into the old path, twice — at line 429, inside the section headed "FedRAMP High / Moderate - Stage 2.1 Networking", and again at line 639 under "Apply FAST Stage: 02-networking". Following the deployment guide on v3.0.0 or main therefore fails at the networking stage. docs/tdd.md:617 also still lists the old directory in its repository-structure tree.

          The sweep was partial rather than missed entirely: docs/tdd.md:946was updated and now reads "FedRAMP High / Moderate Pattern (2-networking-a-fedramp)", so the design section is current while the deployment steps and the tree listing are not. The DDG is the document an operator follows end to end, so a wrong path there is a hard stop rather than a cosmetic inconsistency.

          Environment and Deployment Context

          • Stellar Engine Version/Commit:main (also reproduces at the v3.0.0 tag, f64ce6cd)
          • Deployment Type:
            • US Region Restricted (e.g., Access Policy constraint)
            • FedRAMP Medium
            • FedRAMP High
            • FedRAMP Moderate
            • DoD IL4
            • DoD IL5
            • Stand-alone / Custom
          • FAST Stage (if applicable):
            • Stage 0 (Bootstrap)
            • Stage 1 (Resource Management)
            • Stage 2 (Network Creation)
            • Stage 3 (Security and Audit)
          • Affected Component:docs/ddg.md, docs/tdd.md, fast/stages-aw/2-networking-a-fedramp
          • Terraform Version: not reached — the guide fails before terraform init (our environment runs 1.15.7)
          • GCP Provider Version: not reached (our environment pins hashicorp/google6.50.0)

          Steps to Reproduce

          1. Clone the repository at main, or check out the v3.0.0 tag.
          2. Open docs/ddg.md and go to the section "FedRAMP High / Moderate - Stage 2.1 Networking".
          3. Follow the step at line 429: "Change directory into fast/stages-aw/2-networking-a-fedramp-high".
          4. The directory does not exist. The same instruction appears again at line 639.

          Expected Behavior

          The deployment guide names a directory that exists in the tree it ships with, so an operator can follow the FedRAMP High / Moderate networking stage from start to finish without having to discover the correct path themselves.

          Actual Behavior

          The path does not exist at v3.0.0 or main. Verified against the repository tree: fast/stages-aw/ contains 2-networking-a-fedramp-high at 8f5b67a6 (v2.13.0) and at 3728fc98, and 2-networking-a-fedramp at f64ce6cd (v3.0.0) and at main. The rename landed in #162 (7033b8cc, merged 2026-08-10), with README updates in #173.

          ReferencePath namedCorrect at main?
          docs/ddg.md:429fast/stages-aw/2-networking-a-fedramp-highNo
          docs/ddg.md:639fast/stages-aw/2-networking-a-fedramp-highNo
          docs/tdd.md:6172-networking-a-fedramp-highNo
          docs/tdd.md:9462-networking-a-fedrampYes

          Relevant Logs and Errors

          $ git checkout v3.0.0
          $ cd fast/stages-aw/2-networking-a-fedramp-high
          bash: cd: fast/stages-aw/2-networking-a-fedramp-high: No such file or directory
          $ ls fast/stages-aw/
          0-bootstrap 1-resman 2-networking-a-fedramp 2-networking-b-il5-ngfw 3-security
          

          Additional Context

          Migration notes for the rename.releases.md states that major releases "will include detailed migration notes, state refactoring scripts, or step-by-step instructions for upgrading existing environments without unexpected downtime or state drift." Renaming a Terraform root module changes both the working directory and, for anyone whose backend prefix follows the directory, the state location — exactly the case that policy describes. We could not find notes for it: the repository has 15 tags and no published GitHub Releases, and no upgrade or migration document in the tree. Even a short note saying "rename only, no state action required" would close this out for operators upgrading an existing landing zone.

          This is the same change discussed in #195, which asks what else about it went unrecorded — that issue is about the design decision behind the rename and is not resolved by fixing these paths.

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            bugSomething isn't working

            Type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed · Issue #196 · google/stellar-engine · GitHub
              Skip to content

              [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed #196

              Description

              @JohnHales

              Bug Description

              v3.0.0 renamed fast/stages-aw/2-networking-a-fedramp-high to fast/stages-aw/2-networking-a-fedramp, but the documentation was only partly swept. docs/ddg.md still instructs operators to change directory into the old path, twice — at line 429, inside the section headed "FedRAMP High / Moderate - Stage 2.1 Networking", and again at line 639 under "Apply FAST Stage: 02-networking". Following the deployment guide on v3.0.0 or main therefore fails at the networking stage. docs/tdd.md:617 also still lists the old directory in its repository-structure tree.

              The sweep was partial rather than missed entirely: docs/tdd.md:946was updated and now reads "FedRAMP High / Moderate Pattern (2-networking-a-fedramp)", so the design section is current while the deployment steps and the tree listing are not. The DDG is the document an operator follows end to end, so a wrong path there is a hard stop rather than a cosmetic inconsistency.

              Environment and Deployment Context

              • Stellar Engine Version/Commit:main (also reproduces at the v3.0.0 tag, f64ce6cd)
              • Deployment Type:
                • US Region Restricted (e.g., Access Policy constraint)
                • FedRAMP Medium
                • FedRAMP High
                • FedRAMP Moderate
                • DoD IL4
                • DoD IL5
                • Stand-alone / Custom
              • FAST Stage (if applicable):
                • Stage 0 (Bootstrap)
                • Stage 1 (Resource Management)
                • Stage 2 (Network Creation)
                • Stage 3 (Security and Audit)
              • Affected Component:docs/ddg.md, docs/tdd.md, fast/stages-aw/2-networking-a-fedramp
              • Terraform Version: not reached — the guide fails before terraform init (our environment runs 1.15.7)
              • GCP Provider Version: not reached (our environment pins hashicorp/google6.50.0)

              Steps to Reproduce

              1. Clone the repository at main, or check out the v3.0.0 tag.
              2. Open docs/ddg.md and go to the section "FedRAMP High / Moderate - Stage 2.1 Networking".
              3. Follow the step at line 429: "Change directory into fast/stages-aw/2-networking-a-fedramp-high".
              4. The directory does not exist. The same instruction appears again at line 639.

              Expected Behavior

              The deployment guide names a directory that exists in the tree it ships with, so an operator can follow the FedRAMP High / Moderate networking stage from start to finish without having to discover the correct path themselves.

              Actual Behavior

              The path does not exist at v3.0.0 or main. Verified against the repository tree: fast/stages-aw/ contains 2-networking-a-fedramp-high at 8f5b67a6 (v2.13.0) and at 3728fc98, and 2-networking-a-fedramp at f64ce6cd (v3.0.0) and at main. The rename landed in #162 (7033b8cc, merged 2026-08-10), with README updates in #173.

              ReferencePath namedCorrect at main?
              docs/ddg.md:429fast/stages-aw/2-networking-a-fedramp-highNo
              docs/ddg.md:639fast/stages-aw/2-networking-a-fedramp-highNo
              docs/tdd.md:6172-networking-a-fedramp-highNo
              docs/tdd.md:9462-networking-a-fedrampYes

              Relevant Logs and Errors

              $ git checkout v3.0.0
              $ cd fast/stages-aw/2-networking-a-fedramp-high
              bash: cd: fast/stages-aw/2-networking-a-fedramp-high: No such file or directory
              $ ls fast/stages-aw/
              0-bootstrap 1-resman 2-networking-a-fedramp 2-networking-b-il5-ngfw 3-security
              

              Additional Context

              Migration notes for the rename.releases.md states that major releases "will include detailed migration notes, state refactoring scripts, or step-by-step instructions for upgrading existing environments without unexpected downtime or state drift." Renaming a Terraform root module changes both the working directory and, for anyone whose backend prefix follows the directory, the state location — exactly the case that policy describes. We could not find notes for it: the repository has 15 tags and no published GitHub Releases, and no upgrade or migration document in the tree. Even a short note saying "rename only, no state action required" would close this out for operators upgrading an existing landing zone.

              This is the same change discussed in #195, which asks what else about it went unrecorded — that issue is about the design decision behind the rename and is not resolved by fixing these paths.

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                bugSomething isn't working

                Type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed · Issue #196 · google/stellar-engine · GitHub
                  Skip to content

                  [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed #196

                  Description

                  @JohnHales

                  Bug Description

                  v3.0.0 renamed fast/stages-aw/2-networking-a-fedramp-high to fast/stages-aw/2-networking-a-fedramp, but the documentation was only partly swept. docs/ddg.md still instructs operators to change directory into the old path, twice — at line 429, inside the section headed "FedRAMP High / Moderate - Stage 2.1 Networking", and again at line 639 under "Apply FAST Stage: 02-networking". Following the deployment guide on v3.0.0 or main therefore fails at the networking stage. docs/tdd.md:617 also still lists the old directory in its repository-structure tree.

                  The sweep was partial rather than missed entirely: docs/tdd.md:946was updated and now reads "FedRAMP High / Moderate Pattern (2-networking-a-fedramp)", so the design section is current while the deployment steps and the tree listing are not. The DDG is the document an operator follows end to end, so a wrong path there is a hard stop rather than a cosmetic inconsistency.

                  Environment and Deployment Context

                  • Stellar Engine Version/Commit:main (also reproduces at the v3.0.0 tag, f64ce6cd)
                  • Deployment Type:
                    • US Region Restricted (e.g., Access Policy constraint)
                    • FedRAMP Medium
                    • FedRAMP High
                    • FedRAMP Moderate
                    • DoD IL4
                    • DoD IL5
                    • Stand-alone / Custom
                  • FAST Stage (if applicable):
                    • Stage 0 (Bootstrap)
                    • Stage 1 (Resource Management)
                    • Stage 2 (Network Creation)
                    • Stage 3 (Security and Audit)
                  • Affected Component:docs/ddg.md, docs/tdd.md, fast/stages-aw/2-networking-a-fedramp
                  • Terraform Version: not reached — the guide fails before terraform init (our environment runs 1.15.7)
                  • GCP Provider Version: not reached (our environment pins hashicorp/google6.50.0)

                  Steps to Reproduce

                  1. Clone the repository at main, or check out the v3.0.0 tag.
                  2. Open docs/ddg.md and go to the section "FedRAMP High / Moderate - Stage 2.1 Networking".
                  3. Follow the step at line 429: "Change directory into fast/stages-aw/2-networking-a-fedramp-high".
                  4. The directory does not exist. The same instruction appears again at line 639.

                  Expected Behavior

                  The deployment guide names a directory that exists in the tree it ships with, so an operator can follow the FedRAMP High / Moderate networking stage from start to finish without having to discover the correct path themselves.

                  Actual Behavior

                  The path does not exist at v3.0.0 or main. Verified against the repository tree: fast/stages-aw/ contains 2-networking-a-fedramp-high at 8f5b67a6 (v2.13.0) and at 3728fc98, and 2-networking-a-fedramp at f64ce6cd (v3.0.0) and at main. The rename landed in #162 (7033b8cc, merged 2026-08-10), with README updates in #173.

                  ReferencePath namedCorrect at main?
                  docs/ddg.md:429fast/stages-aw/2-networking-a-fedramp-highNo
                  docs/ddg.md:639fast/stages-aw/2-networking-a-fedramp-highNo
                  docs/tdd.md:6172-networking-a-fedramp-highNo
                  docs/tdd.md:9462-networking-a-fedrampYes

                  Relevant Logs and Errors

                  $ git checkout v3.0.0
                  $ cd fast/stages-aw/2-networking-a-fedramp-high
                  bash: cd: fast/stages-aw/2-networking-a-fedramp-high: No such file or directory
                  $ ls fast/stages-aw/
                  0-bootstrap 1-resman 2-networking-a-fedramp 2-networking-b-il5-ngfw 3-security
                  

                  Additional Context

                  Migration notes for the rename.releases.md states that major releases "will include detailed migration notes, state refactoring scripts, or step-by-step instructions for upgrading existing environments without unexpected downtime or state drift." Renaming a Terraform root module changes both the working directory and, for anyone whose backend prefix follows the directory, the state location — exactly the case that policy describes. We could not find notes for it: the repository has 15 tags and no published GitHub Releases, and no upgrade or migration document in the tree. Even a short note saying "rename only, no state action required" would close this out for operators upgrading an existing landing zone.

                  This is the same change discussed in #195, which asks what else about it went unrecorded — that issue is about the design decision behind the rename and is not resolved by fixing these paths.

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    bugSomething isn't working

                    Type

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed · Issue #196 · google/stellar-engine · GitHub
                      Skip to content

                      [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed #196

                      Description

                      @JohnHales

                      Bug Description

                      v3.0.0 renamed fast/stages-aw/2-networking-a-fedramp-high to fast/stages-aw/2-networking-a-fedramp, but the documentation was only partly swept. docs/ddg.md still instructs operators to change directory into the old path, twice — at line 429, inside the section headed "FedRAMP High / Moderate - Stage 2.1 Networking", and again at line 639 under "Apply FAST Stage: 02-networking". Following the deployment guide on v3.0.0 or main therefore fails at the networking stage. docs/tdd.md:617 also still lists the old directory in its repository-structure tree.

                      The sweep was partial rather than missed entirely: docs/tdd.md:946was updated and now reads "FedRAMP High / Moderate Pattern (2-networking-a-fedramp)", so the design section is current while the deployment steps and the tree listing are not. The DDG is the document an operator follows end to end, so a wrong path there is a hard stop rather than a cosmetic inconsistency.

                      Environment and Deployment Context

                      • Stellar Engine Version/Commit:main (also reproduces at the v3.0.0 tag, f64ce6cd)
                      • Deployment Type:
                        • US Region Restricted (e.g., Access Policy constraint)
                        • FedRAMP Medium
                        • FedRAMP High
                        • FedRAMP Moderate
                        • DoD IL4
                        • DoD IL5
                        • Stand-alone / Custom
                      • FAST Stage (if applicable):
                        • Stage 0 (Bootstrap)
                        • Stage 1 (Resource Management)
                        • Stage 2 (Network Creation)
                        • Stage 3 (Security and Audit)
                      • Affected Component:docs/ddg.md, docs/tdd.md, fast/stages-aw/2-networking-a-fedramp
                      • Terraform Version: not reached — the guide fails before terraform init (our environment runs 1.15.7)
                      • GCP Provider Version: not reached (our environment pins hashicorp/google6.50.0)

                      Steps to Reproduce

                      1. Clone the repository at main, or check out the v3.0.0 tag.
                      2. Open docs/ddg.md and go to the section "FedRAMP High / Moderate - Stage 2.1 Networking".
                      3. Follow the step at line 429: "Change directory into fast/stages-aw/2-networking-a-fedramp-high".
                      4. The directory does not exist. The same instruction appears again at line 639.

                      Expected Behavior

                      The deployment guide names a directory that exists in the tree it ships with, so an operator can follow the FedRAMP High / Moderate networking stage from start to finish without having to discover the correct path themselves.

                      Actual Behavior

                      The path does not exist at v3.0.0 or main. Verified against the repository tree: fast/stages-aw/ contains 2-networking-a-fedramp-high at 8f5b67a6 (v2.13.0) and at 3728fc98, and 2-networking-a-fedramp at f64ce6cd (v3.0.0) and at main. The rename landed in #162 (7033b8cc, merged 2026-08-10), with README updates in #173.

                      ReferencePath namedCorrect at main?
                      docs/ddg.md:429fast/stages-aw/2-networking-a-fedramp-highNo
                      docs/ddg.md:639fast/stages-aw/2-networking-a-fedramp-highNo
                      docs/tdd.md:6172-networking-a-fedramp-highNo
                      docs/tdd.md:9462-networking-a-fedrampYes

                      Relevant Logs and Errors

                      $ git checkout v3.0.0
                      $ cd fast/stages-aw/2-networking-a-fedramp-high
                      bash: cd: fast/stages-aw/2-networking-a-fedramp-high: No such file or directory
                      $ ls fast/stages-aw/
                      0-bootstrap 1-resman 2-networking-a-fedramp 2-networking-b-il5-ngfw 3-security
                      

                      Additional Context

                      Migration notes for the rename.releases.md states that major releases "will include detailed migration notes, state refactoring scripts, or step-by-step instructions for upgrading existing environments without unexpected downtime or state drift." Renaming a Terraform root module changes both the working directory and, for anyone whose backend prefix follows the directory, the state location — exactly the case that policy describes. We could not find notes for it: the repository has 15 tags and no published GitHub Releases, and no upgrade or migration document in the tree. Even a short note saying "rename only, no state action required" would close this out for operators upgrading an existing landing zone.

                      This is the same change discussed in #195, which asks what else about it went unrecorded — that issue is about the design decision behind the rename and is not resolved by fixing these paths.

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        bugSomething isn't working

                        Type

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed · Issue #196 · google/stellar-engine · GitHub
                          Skip to content

                          [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed #196

                          Description

                          @JohnHales

                          Bug Description

                          v3.0.0 renamed fast/stages-aw/2-networking-a-fedramp-high to fast/stages-aw/2-networking-a-fedramp, but the documentation was only partly swept. docs/ddg.md still instructs operators to change directory into the old path, twice — at line 429, inside the section headed "FedRAMP High / Moderate - Stage 2.1 Networking", and again at line 639 under "Apply FAST Stage: 02-networking". Following the deployment guide on v3.0.0 or main therefore fails at the networking stage. docs/tdd.md:617 also still lists the old directory in its repository-structure tree.

                          The sweep was partial rather than missed entirely: docs/tdd.md:946was updated and now reads "FedRAMP High / Moderate Pattern (2-networking-a-fedramp)", so the design section is current while the deployment steps and the tree listing are not. The DDG is the document an operator follows end to end, so a wrong path there is a hard stop rather than a cosmetic inconsistency.

                          Environment and Deployment Context

                          • Stellar Engine Version/Commit:main (also reproduces at the v3.0.0 tag, f64ce6cd)
                          • Deployment Type:
                            • US Region Restricted (e.g., Access Policy constraint)
                            • FedRAMP Medium
                            • FedRAMP High
                            • FedRAMP Moderate
                            • DoD IL4
                            • DoD IL5
                            • Stand-alone / Custom
                          • FAST Stage (if applicable):
                            • Stage 0 (Bootstrap)
                            • Stage 1 (Resource Management)
                            • Stage 2 (Network Creation)
                            • Stage 3 (Security and Audit)
                          • Affected Component:docs/ddg.md, docs/tdd.md, fast/stages-aw/2-networking-a-fedramp
                          • Terraform Version: not reached — the guide fails before terraform init (our environment runs 1.15.7)
                          • GCP Provider Version: not reached (our environment pins hashicorp/google6.50.0)

                          Steps to Reproduce

                          1. Clone the repository at main, or check out the v3.0.0 tag.
                          2. Open docs/ddg.md and go to the section "FedRAMP High / Moderate - Stage 2.1 Networking".
                          3. Follow the step at line 429: "Change directory into fast/stages-aw/2-networking-a-fedramp-high".
                          4. The directory does not exist. The same instruction appears again at line 639.

                          Expected Behavior

                          The deployment guide names a directory that exists in the tree it ships with, so an operator can follow the FedRAMP High / Moderate networking stage from start to finish without having to discover the correct path themselves.

                          Actual Behavior

                          The path does not exist at v3.0.0 or main. Verified against the repository tree: fast/stages-aw/ contains 2-networking-a-fedramp-high at 8f5b67a6 (v2.13.0) and at 3728fc98, and 2-networking-a-fedramp at f64ce6cd (v3.0.0) and at main. The rename landed in #162 (7033b8cc, merged 2026-08-10), with README updates in #173.

                          ReferencePath namedCorrect at main?
                          docs/ddg.md:429fast/stages-aw/2-networking-a-fedramp-highNo
                          docs/ddg.md:639fast/stages-aw/2-networking-a-fedramp-highNo
                          docs/tdd.md:6172-networking-a-fedramp-highNo
                          docs/tdd.md:9462-networking-a-fedrampYes

                          Relevant Logs and Errors

                          $ git checkout v3.0.0
                          $ cd fast/stages-aw/2-networking-a-fedramp-high
                          bash: cd: fast/stages-aw/2-networking-a-fedramp-high: No such file or directory
                          $ ls fast/stages-aw/
                          0-bootstrap 1-resman 2-networking-a-fedramp 2-networking-b-il5-ngfw 3-security
                          

                          Additional Context

                          Migration notes for the rename.releases.md states that major releases "will include detailed migration notes, state refactoring scripts, or step-by-step instructions for upgrading existing environments without unexpected downtime or state drift." Renaming a Terraform root module changes both the working directory and, for anyone whose backend prefix follows the directory, the state location — exactly the case that policy describes. We could not find notes for it: the repository has 15 tags and no published GitHub Releases, and no upgrade or migration document in the tree. Even a short note saying "rename only, no state action required" would close this out for operators upgrading an existing landing zone.

                          This is the same change discussed in #195, which asks what else about it went unrecorded — that issue is about the design decision behind the rename and is not resolved by fixing these paths.

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            bugSomething isn't working

                            Type

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed · Issue #196 · google/stellar-engine · GitHub
                              Skip to content

                              [Bug] docs/ddg.md points at fast/stages-aw/2-networking-a-fedramp-high, which v3.0.0 renamed — the deployment guide's networking step cannot be followed #196

                              Description

                              @JohnHales

                              Bug Description

                              v3.0.0 renamed fast/stages-aw/2-networking-a-fedramp-high to fast/stages-aw/2-networking-a-fedramp, but the documentation was only partly swept. docs/ddg.md still instructs operators to change directory into the old path, twice — at line 429, inside the section headed "FedRAMP High / Moderate - Stage 2.1 Networking", and again at line 639 under "Apply FAST Stage: 02-networking". Following the deployment guide on v3.0.0 or main therefore fails at the networking stage. docs/tdd.md:617 also still lists the old directory in its repository-structure tree.

                              The sweep was partial rather than missed entirely: docs/tdd.md:946was updated and now reads "FedRAMP High / Moderate Pattern (2-networking-a-fedramp)", so the design section is current while the deployment steps and the tree listing are not. The DDG is the document an operator follows end to end, so a wrong path there is a hard stop rather than a cosmetic inconsistency.

                              Environment and Deployment Context

                              • Stellar Engine Version/Commit:main (also reproduces at the v3.0.0 tag, f64ce6cd)
                              • Deployment Type:
                                • US Region Restricted (e.g., Access Policy constraint)
                                • FedRAMP Medium
                                • FedRAMP High
                                • FedRAMP Moderate
                                • DoD IL4
                                • DoD IL5
                                • Stand-alone / Custom
                              • FAST Stage (if applicable):
                                • Stage 0 (Bootstrap)
                                • Stage 1 (Resource Management)
                                • Stage 2 (Network Creation)
                                • Stage 3 (Security and Audit)
                              • Affected Component:docs/ddg.md, docs/tdd.md, fast/stages-aw/2-networking-a-fedramp
                              • Terraform Version: not reached — the guide fails before terraform init (our environment runs 1.15.7)
                              • GCP Provider Version: not reached (our environment pins hashicorp/google6.50.0)

                              Steps to Reproduce

                              1. Clone the repository at main, or check out the v3.0.0 tag.
                              2. Open docs/ddg.md and go to the section "FedRAMP High / Moderate - Stage 2.1 Networking".
                              3. Follow the step at line 429: "Change directory into fast/stages-aw/2-networking-a-fedramp-high".
                              4. The directory does not exist. The same instruction appears again at line 639.

                              Expected Behavior

                              The deployment guide names a directory that exists in the tree it ships with, so an operator can follow the FedRAMP High / Moderate networking stage from start to finish without having to discover the correct path themselves.

                              Actual Behavior

                              The path does not exist at v3.0.0 or main. Verified against the repository tree: fast/stages-aw/ contains 2-networking-a-fedramp-high at 8f5b67a6 (v2.13.0) and at 3728fc98, and 2-networking-a-fedramp at f64ce6cd (v3.0.0) and at main. The rename landed in #162 (7033b8cc, merged 2026-08-10), with README updates in #173.

                              ReferencePath namedCorrect at main?
                              docs/ddg.md:429fast/stages-aw/2-networking-a-fedramp-highNo
                              docs/ddg.md:639fast/stages-aw/2-networking-a-fedramp-highNo
                              docs/tdd.md:6172-networking-a-fedramp-highNo
                              docs/tdd.md:9462-networking-a-fedrampYes

                              Relevant Logs and Errors

                              $ git checkout v3.0.0
                              $ cd fast/stages-aw/2-networking-a-fedramp-high
                              bash: cd: fast/stages-aw/2-networking-a-fedramp-high: No such file or directory
                              $ ls fast/stages-aw/
                              0-bootstrap 1-resman 2-networking-a-fedramp 2-networking-b-il5-ngfw 3-security
                              

                              Additional Context

                              Migration notes for the rename.releases.md states that major releases "will include detailed migration notes, state refactoring scripts, or step-by-step instructions for upgrading existing environments without unexpected downtime or state drift." Renaming a Terraform root module changes both the working directory and, for anyone whose backend prefix follows the directory, the state location — exactly the case that policy describes. We could not find notes for it: the repository has 15 tags and no published GitHub Releases, and no upgrade or migration document in the tree. Even a short note saying "rename only, no state action required" would close this out for operators upgrading an existing landing zone.

                              This is the same change discussed in #195, which asks what else about it went unrecorded — that issue is about the design decision behind the rename and is not resolved by fixing these paths.

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                bugSomething isn't working

                                Type

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions