Skip to content

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit - #213

Open
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency
Open

fix(0-bootstrap): declare billing_override, fix the assured_workload output, align the prefix limit#213
scottonix wants to merge 1 commit into
google:mainfrom
scottonix:fix/0-bootstrap-consistency

Conversation

@scottonix

Copy link
Copy Markdown

Description

Three small consistency fixes in fast/stages-aw/0-bootstrap, each found while deploying the stage:

  1. billing_override is referenced but never declared. templates/providers.tf.tpl renders four references to var.billing_override into every generated providers file, including 0-bootstrap-providers.tf, but stage 0 has no variable "billing_override" (stages 1, 2 and 3 declare it). Terraform only rejects the reference once a resource uses the google.billing alias, so the stage works today by accident; the moment anyone adds a resource on that alias in stage 0, init/plan fail with Reference to undeclared input variable. Declare the variable with the same shape and default as the other stages.
  2. output "assured_workload" produced folders/folders/NNN when assured_workloads.regime is COMPLIANCE_REGIME_UNSPECIFIED: it wrapped module.no-compliance-folder[0].folder.id in "folders/", but google_folder.id already carries that prefix. organization.tf uses the bare id for the same folder (the Common Services folder's parent). The output now uses the folder module's fully qualified id.
  3. The prefix limit said 9, the validation says 7. var.prefix is validated to length <= 7, while its description, terraform.tfvars.sample and the README all told the user 9 characters or fewer; a prefix of 8 or 9 characters fails on the first plan. The validation is the behaviour (main.tf builds <prefix>-prod from it), so the text now matches it.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: none affected.

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

Terraform 1.10.5.

  • terraform validate on 0-bootstrap passes with the change.
  • (1) was characterised with a minimal reproduction: a configuration whose google.billing alias provider block contains try(var.billing_override.project, "x") validates and plans while no resource uses the alias, and fails with Reference to undeclared input variable on all four references as soon as one does. Stage 0 currently has no resource on that alias, which is why the rendered 0-bootstrap-providers.tf has not broken anyone yet.
  • (2) was observed on a live deployment with the regime unspecified: terraform output assured_workload returned folders/folders/<id>; the generated 0-bootstrap.auto.tfvars.json that stage 1 consumes was correct, because it is built from organization.tf's bare id.
  • (3) is a documentation change; the validation block is unchanged.

…output, align the prefix limit

Three small consistency fixes in the bootstrap stage:

- templates/providers.tf.tpl renders four references to var.billing_override
  into every generated providers file, including 0-bootstrap-providers.tf, but
  stage 0 never declared the variable (stages 1, 2 and 3 do). Terraform only
  rejects the reference once a resource uses the google.billing alias, so the
  stage works today by accident; declare the variable with the same shape and
  default as the other stages so the generated file is self-consistent.
- output assured_workload wrapped module.no-compliance-folder[0].folder.id in
  "folders/" although google_folder.id already carries that prefix, producing
  "folders/folders/NNN" whenever assured_workloads.regime is
  COMPLIANCE_REGIME_UNSPECIFIED. organization.tf uses the bare id for the same
  folder; the output now uses the module's fully qualified id.
- var.prefix is validated to 7 characters or fewer, but its description, the
  tfvars sample and the README all said 9. The validation is the behaviour;
  the text now matches it.

Signed-off-by: Scott McDonald <scott.mcdonald@onixnet.com>
@aghassemlouei aghassemlouei added bug Something isn't working Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete labels Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete Priority - Medium Standard features and non-blocking bugs; important for the current milestone but not urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants