Skip to content

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit - #213

Open
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency
Open

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit#213
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency

Conversation

@scottonix

Copy link
Copy Markdown

Description

Three small consistency fixes in fast/stages-aw/0-bootstrap, each found while deploying the stage:

  1. billing_override is referenced but never declared.templates/providers.tf.tpl renders four references to var.billing_override into every generated providers file, including 0-bootstrap-providers.tf, but stage 0 has no variable "billing_override" (stages 1, 2 and 3 declare it). Terraform only rejects the reference once a resource uses the google.billing alias, so the stage works today by accident; the moment anyone adds a resource on that alias in stage 0, init/plan fail with Reference to undeclared input variable. Declare the variable with the same shape and default as the other stages.
  2. output "assured_workload" produced folders/folders/NNN when assured_workloads.regime is COMPLIANCE_REGIME_UNSPECIFIED: it wrapped module.no-compliance-folder[0].folder.id in "folders/", but google_folder.id already carries that prefix. organization.tf uses the bare id for the same folder (the Common Services folder's parent). The output now uses the folder module's fully qualified id.
  3. The prefix limit said 9, the validation says 7.var.prefix is validated to length <= 7, while its description, terraform.tfvars.sample and the README all told the user 9 characters or fewer; a prefix of 8 or 9 characters fails on the first plan. The validation is the behaviour (main.tf builds <prefix>-prod from it), so the text now matches it.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: none affected.

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

Terraform 1.10.5.

  • terraform validate on 0-bootstrap passes with the change.
  • (1) was characterised with a minimal reproduction: a configuration whose google.billing alias provider block contains try(var.billing_override.project, "x") validates and plans while no resource uses the alias, and fails with Reference to undeclared input variable on all four references as soon as one does. Stage 0 currently has no resource on that alias, which is why the rendered 0-bootstrap-providers.tf has not broken anyone yet.
  • (2) was observed on a live deployment with the regime unspecified: terraform output assured_workload returned folders/folders/<id>; the generated 0-bootstrap.auto.tfvars.json that stage 1 consumes was correct, because it is built from organization.tf's bare id.
  • (3) is a documentation change; the validation block is unchanged.

…output, align the prefix limit
Three small consistency fixes in the bootstrap stage:
- templates/providers.tf.tpl renders four references to var.billing_override
into every generated providers file, including 0-bootstrap-providers.tf, but
stage 0 never declared the variable (stages 1, 2 and 3 do). Terraform only
rejects the reference once a resource uses the google.billing alias, so the
stage works today by accident; declare the variable with the same shape and
default as the other stages so the generated file is self-consistent.
- output assured_workload wrapped module.no-compliance-folder[0].folder.id in
"folders/" although google_folder.id already carries that prefix, producing
"folders/folders/NNN" whenever assured_workloads.regime is
COMPLIANCE_REGIME_UNSPECIFIED. organization.tf uses the bare id for the same
folder; the output now uses the module's fully qualified id.
- var.prefix is validated to 7 characters or fewer, but its description, the
tfvars sample and the README all said 9. The validation is the behaviour;
the text now matches it.
Signed-off-by: Scott McDonald <scott.mcdonald@onixnet.com>
@aghassemloueiaghassemlouei added bug Something isn't working Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete labels Aug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't workingLevel of Effort - LowQuick, well-defined tasks with no unknowns; takes a few hours up to one day to completePriority - MediumStandard features and non-blocking bugs; important for the current milestone but not urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@scottonix@aghassemlouei
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit by scottonix · Pull Request #213 · google/stellar-engine · GitHub
Skip to content

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit - #213

Open
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency
Open

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit#213
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency

Conversation

@scottonix

Copy link
Copy Markdown

Description

Three small consistency fixes in fast/stages-aw/0-bootstrap, each found while deploying the stage:

  1. billing_override is referenced but never declared.templates/providers.tf.tpl renders four references to var.billing_override into every generated providers file, including 0-bootstrap-providers.tf, but stage 0 has no variable "billing_override" (stages 1, 2 and 3 declare it). Terraform only rejects the reference once a resource uses the google.billing alias, so the stage works today by accident; the moment anyone adds a resource on that alias in stage 0, init/plan fail with Reference to undeclared input variable. Declare the variable with the same shape and default as the other stages.
  2. output "assured_workload" produced folders/folders/NNN when assured_workloads.regime is COMPLIANCE_REGIME_UNSPECIFIED: it wrapped module.no-compliance-folder[0].folder.id in "folders/", but google_folder.id already carries that prefix. organization.tf uses the bare id for the same folder (the Common Services folder's parent). The output now uses the folder module's fully qualified id.
  3. The prefix limit said 9, the validation says 7.var.prefix is validated to length <= 7, while its description, terraform.tfvars.sample and the README all told the user 9 characters or fewer; a prefix of 8 or 9 characters fails on the first plan. The validation is the behaviour (main.tf builds <prefix>-prod from it), so the text now matches it.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: none affected.

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

Terraform 1.10.5.

  • terraform validate on 0-bootstrap passes with the change.
  • (1) was characterised with a minimal reproduction: a configuration whose google.billing alias provider block contains try(var.billing_override.project, "x") validates and plans while no resource uses the alias, and fails with Reference to undeclared input variable on all four references as soon as one does. Stage 0 currently has no resource on that alias, which is why the rendered 0-bootstrap-providers.tf has not broken anyone yet.
  • (2) was observed on a live deployment with the regime unspecified: terraform output assured_workload returned folders/folders/<id>; the generated 0-bootstrap.auto.tfvars.json that stage 1 consumes was correct, because it is built from organization.tf's bare id.
  • (3) is a documentation change; the validation block is unchanged.

…output, align the prefix limit
Three small consistency fixes in the bootstrap stage:
- templates/providers.tf.tpl renders four references to var.billing_override
into every generated providers file, including 0-bootstrap-providers.tf, but
stage 0 never declared the variable (stages 1, 2 and 3 do). Terraform only
rejects the reference once a resource uses the google.billing alias, so the
stage works today by accident; declare the variable with the same shape and
default as the other stages so the generated file is self-consistent.
- output assured_workload wrapped module.no-compliance-folder[0].folder.id in
"folders/" although google_folder.id already carries that prefix, producing
"folders/folders/NNN" whenever assured_workloads.regime is
COMPLIANCE_REGIME_UNSPECIFIED. organization.tf uses the bare id for the same
folder; the output now uses the module's fully qualified id.
- var.prefix is validated to 7 characters or fewer, but its description, the
tfvars sample and the README all said 9. The validation is the behaviour;
the text now matches it.
Signed-off-by: Scott McDonald <scott.mcdonald@onixnet.com>
@aghassemloueiaghassemlouei added bug Something isn't working Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete labels Aug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't workingLevel of Effort - LowQuick, well-defined tasks with no unknowns; takes a few hours up to one day to completePriority - MediumStandard features and non-blocking bugs; important for the current milestone but not urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@scottonix@aghassemlouei
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit by scottonix · Pull Request #213 · google/stellar-engine · GitHub
Skip to content

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit - #213

Open
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency
Open

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit#213
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency

Conversation

@scottonix

Copy link
Copy Markdown

Description

Three small consistency fixes in fast/stages-aw/0-bootstrap, each found while deploying the stage:

  1. billing_override is referenced but never declared.templates/providers.tf.tpl renders four references to var.billing_override into every generated providers file, including 0-bootstrap-providers.tf, but stage 0 has no variable "billing_override" (stages 1, 2 and 3 declare it). Terraform only rejects the reference once a resource uses the google.billing alias, so the stage works today by accident; the moment anyone adds a resource on that alias in stage 0, init/plan fail with Reference to undeclared input variable. Declare the variable with the same shape and default as the other stages.
  2. output "assured_workload" produced folders/folders/NNN when assured_workloads.regime is COMPLIANCE_REGIME_UNSPECIFIED: it wrapped module.no-compliance-folder[0].folder.id in "folders/", but google_folder.id already carries that prefix. organization.tf uses the bare id for the same folder (the Common Services folder's parent). The output now uses the folder module's fully qualified id.
  3. The prefix limit said 9, the validation says 7.var.prefix is validated to length <= 7, while its description, terraform.tfvars.sample and the README all told the user 9 characters or fewer; a prefix of 8 or 9 characters fails on the first plan. The validation is the behaviour (main.tf builds <prefix>-prod from it), so the text now matches it.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: none affected.

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

Terraform 1.10.5.

  • terraform validate on 0-bootstrap passes with the change.
  • (1) was characterised with a minimal reproduction: a configuration whose google.billing alias provider block contains try(var.billing_override.project, "x") validates and plans while no resource uses the alias, and fails with Reference to undeclared input variable on all four references as soon as one does. Stage 0 currently has no resource on that alias, which is why the rendered 0-bootstrap-providers.tf has not broken anyone yet.
  • (2) was observed on a live deployment with the regime unspecified: terraform output assured_workload returned folders/folders/<id>; the generated 0-bootstrap.auto.tfvars.json that stage 1 consumes was correct, because it is built from organization.tf's bare id.
  • (3) is a documentation change; the validation block is unchanged.

…output, align the prefix limit
Three small consistency fixes in the bootstrap stage:
- templates/providers.tf.tpl renders four references to var.billing_override
into every generated providers file, including 0-bootstrap-providers.tf, but
stage 0 never declared the variable (stages 1, 2 and 3 do). Terraform only
rejects the reference once a resource uses the google.billing alias, so the
stage works today by accident; declare the variable with the same shape and
default as the other stages so the generated file is self-consistent.
- output assured_workload wrapped module.no-compliance-folder[0].folder.id in
"folders/" although google_folder.id already carries that prefix, producing
"folders/folders/NNN" whenever assured_workloads.regime is
COMPLIANCE_REGIME_UNSPECIFIED. organization.tf uses the bare id for the same
folder; the output now uses the module's fully qualified id.
- var.prefix is validated to 7 characters or fewer, but its description, the
tfvars sample and the README all said 9. The validation is the behaviour;
the text now matches it.
Signed-off-by: Scott McDonald <scott.mcdonald@onixnet.com>
@aghassemloueiaghassemlouei added bug Something isn't working Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete labels Aug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't workingLevel of Effort - LowQuick, well-defined tasks with no unknowns; takes a few hours up to one day to completePriority - MediumStandard features and non-blocking bugs; important for the current milestone but not urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@scottonix@aghassemlouei
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit by scottonix · Pull Request #213 · google/stellar-engine · GitHub
Skip to content

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit - #213

Open
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency
Open

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit#213
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency

Conversation

@scottonix

Copy link
Copy Markdown

Description

Three small consistency fixes in fast/stages-aw/0-bootstrap, each found while deploying the stage:

  1. billing_override is referenced but never declared.templates/providers.tf.tpl renders four references to var.billing_override into every generated providers file, including 0-bootstrap-providers.tf, but stage 0 has no variable "billing_override" (stages 1, 2 and 3 declare it). Terraform only rejects the reference once a resource uses the google.billing alias, so the stage works today by accident; the moment anyone adds a resource on that alias in stage 0, init/plan fail with Reference to undeclared input variable. Declare the variable with the same shape and default as the other stages.
  2. output "assured_workload" produced folders/folders/NNN when assured_workloads.regime is COMPLIANCE_REGIME_UNSPECIFIED: it wrapped module.no-compliance-folder[0].folder.id in "folders/", but google_folder.id already carries that prefix. organization.tf uses the bare id for the same folder (the Common Services folder's parent). The output now uses the folder module's fully qualified id.
  3. The prefix limit said 9, the validation says 7.var.prefix is validated to length <= 7, while its description, terraform.tfvars.sample and the README all told the user 9 characters or fewer; a prefix of 8 or 9 characters fails on the first plan. The validation is the behaviour (main.tf builds <prefix>-prod from it), so the text now matches it.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: none affected.

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

Terraform 1.10.5.

  • terraform validate on 0-bootstrap passes with the change.
  • (1) was characterised with a minimal reproduction: a configuration whose google.billing alias provider block contains try(var.billing_override.project, "x") validates and plans while no resource uses the alias, and fails with Reference to undeclared input variable on all four references as soon as one does. Stage 0 currently has no resource on that alias, which is why the rendered 0-bootstrap-providers.tf has not broken anyone yet.
  • (2) was observed on a live deployment with the regime unspecified: terraform output assured_workload returned folders/folders/<id>; the generated 0-bootstrap.auto.tfvars.json that stage 1 consumes was correct, because it is built from organization.tf's bare id.
  • (3) is a documentation change; the validation block is unchanged.

…output, align the prefix limit
Three small consistency fixes in the bootstrap stage:
- templates/providers.tf.tpl renders four references to var.billing_override
into every generated providers file, including 0-bootstrap-providers.tf, but
stage 0 never declared the variable (stages 1, 2 and 3 do). Terraform only
rejects the reference once a resource uses the google.billing alias, so the
stage works today by accident; declare the variable with the same shape and
default as the other stages so the generated file is self-consistent.
- output assured_workload wrapped module.no-compliance-folder[0].folder.id in
"folders/" although google_folder.id already carries that prefix, producing
"folders/folders/NNN" whenever assured_workloads.regime is
COMPLIANCE_REGIME_UNSPECIFIED. organization.tf uses the bare id for the same
folder; the output now uses the module's fully qualified id.
- var.prefix is validated to 7 characters or fewer, but its description, the
tfvars sample and the README all said 9. The validation is the behaviour;
the text now matches it.
Signed-off-by: Scott McDonald <scott.mcdonald@onixnet.com>
@aghassemloueiaghassemlouei added bug Something isn't working Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete labels Aug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't workingLevel of Effort - LowQuick, well-defined tasks with no unknowns; takes a few hours up to one day to completePriority - MediumStandard features and non-blocking bugs; important for the current milestone but not urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@scottonix@aghassemlouei
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit by scottonix · Pull Request #213 · google/stellar-engine · GitHub
Skip to content

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit - #213

Open
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency
Open

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit#213
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency

Conversation

@scottonix

Copy link
Copy Markdown

Description

Three small consistency fixes in fast/stages-aw/0-bootstrap, each found while deploying the stage:

  1. billing_override is referenced but never declared.templates/providers.tf.tpl renders four references to var.billing_override into every generated providers file, including 0-bootstrap-providers.tf, but stage 0 has no variable "billing_override" (stages 1, 2 and 3 declare it). Terraform only rejects the reference once a resource uses the google.billing alias, so the stage works today by accident; the moment anyone adds a resource on that alias in stage 0, init/plan fail with Reference to undeclared input variable. Declare the variable with the same shape and default as the other stages.
  2. output "assured_workload" produced folders/folders/NNN when assured_workloads.regime is COMPLIANCE_REGIME_UNSPECIFIED: it wrapped module.no-compliance-folder[0].folder.id in "folders/", but google_folder.id already carries that prefix. organization.tf uses the bare id for the same folder (the Common Services folder's parent). The output now uses the folder module's fully qualified id.
  3. The prefix limit said 9, the validation says 7.var.prefix is validated to length <= 7, while its description, terraform.tfvars.sample and the README all told the user 9 characters or fewer; a prefix of 8 or 9 characters fails on the first plan. The validation is the behaviour (main.tf builds <prefix>-prod from it), so the text now matches it.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: none affected.

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

Terraform 1.10.5.

  • terraform validate on 0-bootstrap passes with the change.
  • (1) was characterised with a minimal reproduction: a configuration whose google.billing alias provider block contains try(var.billing_override.project, "x") validates and plans while no resource uses the alias, and fails with Reference to undeclared input variable on all four references as soon as one does. Stage 0 currently has no resource on that alias, which is why the rendered 0-bootstrap-providers.tf has not broken anyone yet.
  • (2) was observed on a live deployment with the regime unspecified: terraform output assured_workload returned folders/folders/<id>; the generated 0-bootstrap.auto.tfvars.json that stage 1 consumes was correct, because it is built from organization.tf's bare id.
  • (3) is a documentation change; the validation block is unchanged.

…output, align the prefix limit
Three small consistency fixes in the bootstrap stage:
- templates/providers.tf.tpl renders four references to var.billing_override
into every generated providers file, including 0-bootstrap-providers.tf, but
stage 0 never declared the variable (stages 1, 2 and 3 do). Terraform only
rejects the reference once a resource uses the google.billing alias, so the
stage works today by accident; declare the variable with the same shape and
default as the other stages so the generated file is self-consistent.
- output assured_workload wrapped module.no-compliance-folder[0].folder.id in
"folders/" although google_folder.id already carries that prefix, producing
"folders/folders/NNN" whenever assured_workloads.regime is
COMPLIANCE_REGIME_UNSPECIFIED. organization.tf uses the bare id for the same
folder; the output now uses the module's fully qualified id.
- var.prefix is validated to 7 characters or fewer, but its description, the
tfvars sample and the README all said 9. The validation is the behaviour;
the text now matches it.
Signed-off-by: Scott McDonald <scott.mcdonald@onixnet.com>
@aghassemloueiaghassemlouei added bug Something isn't working Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete labels Aug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't workingLevel of Effort - LowQuick, well-defined tasks with no unknowns; takes a few hours up to one day to completePriority - MediumStandard features and non-blocking bugs; important for the current milestone but not urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@scottonix@aghassemlouei
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit by scottonix · Pull Request #213 · google/stellar-engine · GitHub
Skip to content

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit - #213

Open
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency
Open

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit#213
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency

Conversation

@scottonix

Copy link
Copy Markdown

Description

Three small consistency fixes in fast/stages-aw/0-bootstrap, each found while deploying the stage:

  1. billing_override is referenced but never declared.templates/providers.tf.tpl renders four references to var.billing_override into every generated providers file, including 0-bootstrap-providers.tf, but stage 0 has no variable "billing_override" (stages 1, 2 and 3 declare it). Terraform only rejects the reference once a resource uses the google.billing alias, so the stage works today by accident; the moment anyone adds a resource on that alias in stage 0, init/plan fail with Reference to undeclared input variable. Declare the variable with the same shape and default as the other stages.
  2. output "assured_workload" produced folders/folders/NNN when assured_workloads.regime is COMPLIANCE_REGIME_UNSPECIFIED: it wrapped module.no-compliance-folder[0].folder.id in "folders/", but google_folder.id already carries that prefix. organization.tf uses the bare id for the same folder (the Common Services folder's parent). The output now uses the folder module's fully qualified id.
  3. The prefix limit said 9, the validation says 7.var.prefix is validated to length <= 7, while its description, terraform.tfvars.sample and the README all told the user 9 characters or fewer; a prefix of 8 or 9 characters fails on the first plan. The validation is the behaviour (main.tf builds <prefix>-prod from it), so the text now matches it.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: none affected.

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

Terraform 1.10.5.

  • terraform validate on 0-bootstrap passes with the change.
  • (1) was characterised with a minimal reproduction: a configuration whose google.billing alias provider block contains try(var.billing_override.project, "x") validates and plans while no resource uses the alias, and fails with Reference to undeclared input variable on all four references as soon as one does. Stage 0 currently has no resource on that alias, which is why the rendered 0-bootstrap-providers.tf has not broken anyone yet.
  • (2) was observed on a live deployment with the regime unspecified: terraform output assured_workload returned folders/folders/<id>; the generated 0-bootstrap.auto.tfvars.json that stage 1 consumes was correct, because it is built from organization.tf's bare id.
  • (3) is a documentation change; the validation block is unchanged.

…output, align the prefix limit
Three small consistency fixes in the bootstrap stage:
- templates/providers.tf.tpl renders four references to var.billing_override
into every generated providers file, including 0-bootstrap-providers.tf, but
stage 0 never declared the variable (stages 1, 2 and 3 do). Terraform only
rejects the reference once a resource uses the google.billing alias, so the
stage works today by accident; declare the variable with the same shape and
default as the other stages so the generated file is self-consistent.
- output assured_workload wrapped module.no-compliance-folder[0].folder.id in
"folders/" although google_folder.id already carries that prefix, producing
"folders/folders/NNN" whenever assured_workloads.regime is
COMPLIANCE_REGIME_UNSPECIFIED. organization.tf uses the bare id for the same
folder; the output now uses the module's fully qualified id.
- var.prefix is validated to 7 characters or fewer, but its description, the
tfvars sample and the README all said 9. The validation is the behaviour;
the text now matches it.
Signed-off-by: Scott McDonald <scott.mcdonald@onixnet.com>
@aghassemloueiaghassemlouei added bug Something isn't working Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete labels Aug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't workingLevel of Effort - LowQuick, well-defined tasks with no unknowns; takes a few hours up to one day to completePriority - MediumStandard features and non-blocking bugs; important for the current milestone but not urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@scottonix@aghassemlouei
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit by scottonix · Pull Request #213 · google/stellar-engine · GitHub
Skip to content

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit - #213

Open
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency
Open

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit#213
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency

Conversation

@scottonix

Copy link
Copy Markdown

Description

Three small consistency fixes in fast/stages-aw/0-bootstrap, each found while deploying the stage:

  1. billing_override is referenced but never declared.templates/providers.tf.tpl renders four references to var.billing_override into every generated providers file, including 0-bootstrap-providers.tf, but stage 0 has no variable "billing_override" (stages 1, 2 and 3 declare it). Terraform only rejects the reference once a resource uses the google.billing alias, so the stage works today by accident; the moment anyone adds a resource on that alias in stage 0, init/plan fail with Reference to undeclared input variable. Declare the variable with the same shape and default as the other stages.
  2. output "assured_workload" produced folders/folders/NNN when assured_workloads.regime is COMPLIANCE_REGIME_UNSPECIFIED: it wrapped module.no-compliance-folder[0].folder.id in "folders/", but google_folder.id already carries that prefix. organization.tf uses the bare id for the same folder (the Common Services folder's parent). The output now uses the folder module's fully qualified id.
  3. The prefix limit said 9, the validation says 7.var.prefix is validated to length <= 7, while its description, terraform.tfvars.sample and the README all told the user 9 characters or fewer; a prefix of 8 or 9 characters fails on the first plan. The validation is the behaviour (main.tf builds <prefix>-prod from it), so the text now matches it.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: none affected.

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

Terraform 1.10.5.

  • terraform validate on 0-bootstrap passes with the change.
  • (1) was characterised with a minimal reproduction: a configuration whose google.billing alias provider block contains try(var.billing_override.project, "x") validates and plans while no resource uses the alias, and fails with Reference to undeclared input variable on all four references as soon as one does. Stage 0 currently has no resource on that alias, which is why the rendered 0-bootstrap-providers.tf has not broken anyone yet.
  • (2) was observed on a live deployment with the regime unspecified: terraform output assured_workload returned folders/folders/<id>; the generated 0-bootstrap.auto.tfvars.json that stage 1 consumes was correct, because it is built from organization.tf's bare id.
  • (3) is a documentation change; the validation block is unchanged.

…output, align the prefix limit
Three small consistency fixes in the bootstrap stage:
- templates/providers.tf.tpl renders four references to var.billing_override
into every generated providers file, including 0-bootstrap-providers.tf, but
stage 0 never declared the variable (stages 1, 2 and 3 do). Terraform only
rejects the reference once a resource uses the google.billing alias, so the
stage works today by accident; declare the variable with the same shape and
default as the other stages so the generated file is self-consistent.
- output assured_workload wrapped module.no-compliance-folder[0].folder.id in
"folders/" although google_folder.id already carries that prefix, producing
"folders/folders/NNN" whenever assured_workloads.regime is
COMPLIANCE_REGIME_UNSPECIFIED. organization.tf uses the bare id for the same
folder; the output now uses the module's fully qualified id.
- var.prefix is validated to 7 characters or fewer, but its description, the
tfvars sample and the README all said 9. The validation is the behaviour;
the text now matches it.
Signed-off-by: Scott McDonald <scott.mcdonald@onixnet.com>
@aghassemloueiaghassemlouei added bug Something isn't working Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete labels Aug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't workingLevel of Effort - LowQuick, well-defined tasks with no unknowns; takes a few hours up to one day to completePriority - MediumStandard features and non-blocking bugs; important for the current milestone but not urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@scottonix@aghassemlouei