Skip to content

fix(security): harden IAM conditions, FAST stages, repository tools, and blueprints - #274

Open
aghassemlouei wants to merge 5 commits into
mainfrom
fix/fortify-security-remediation
Open

aghassemlouei wants to merge 5 commits into
mainfrom
fix/fortify-security-remediation

Conversation

@aghassemlouei

@aghassemlouei aghassemlouei commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Description

This pull request bundles non-breaking security hardening and correctness fixes across repository tooling, FAST foundation stages (0-bootstrap, 1-resman, 2-networking, 3-security), and compliance blueprints (fedramp-high and il5).

Shared Terraform module changes originally developed alongside this branch have been split out into #275 (Stellar Engine custom modules), #276 (modules already fixed in upstream Cloud Foundation Fabric), and upstream Cloud Foundation Fabric pull requests (GoogleCloudPlatform/cloud-foundation-fabric #4198-#4232).

Repository Tooling

  • Guard tools/validate_metadata.py, tools/check_documentation.py, tools/check_links.py, and tools/tfdoc.py against symlink traversal, path escape, and malformed Markdown heading ASTs.
  • Use csv.writer in tools/state_iam.py to prevent CSV injection and fix the IAM resource regular expression so service-specific IAM resources are matched accurately.
  • Enforce HTTP request timeouts and reject private, loopback, and link-local IP targets in tools/check_links.py to prevent SSRF during external link validation.
  • Update tools/pre-commit-tfdoc.sh and tools/DuplicateFileFinder.py to safely handle file paths containing whitespace or special characters.

FAST Stages (0-bootstrap, 1-resman, 2-networking, 3-security)

  • Guard delegated IAM role grant CEL conditions in fast/stages-aw/0-bootstrap/organization.tf and fast/stages-aw/3-security/main.tf with api.getAttribute('iam.googleapis.com/modifiedGrantsByRole', []).size() > 0 so hasOnly() cannot evaluate vacuously true when non-listed roles are modified.
  • Scope roles/iam.serviceAccountAdmin and roles/iam.serviceAccountTokenCreator in fast/stages-aw/0-bootstrap/automation.tf with CEL conditions that exclude the Stage 0 bootstrap automation service accounts (bootstrap_0 and bootstrap_r_0), preventing cross-stage privilege escalation from Stage 1 resource management or gcp-devops.
  • Fix fast/stages-aw/0-bootstrap/checklist.tf and fast/stages-aw/1-resman/checklist.tf to convert numeric organization IDs via tostring() before comparison and guard bucket substring checks when var.prefix is null.
  • Restrict generated local provider and variable files to 0600 permissions across Stage 0 and Stage 1, and remove world-writable 0777 directory permissions in Stage 2 NGFW outputs.
  • Anchor Cloud Source Repositories trigger branch regular expressions (^...$) across Stage 1 CI/CD configurations so prefix or substring branch names cannot inadvertently trigger production pipelines.
  • Remove unused service account keys in Stage 2 networking (nva.tf), remove the overprivileged default Compute Engine service account from the NGFW bootstrap bucket binding (ngfw.tf), pass NGFW passwords to openssl passwd via -stdin (openssl-helper.sh), and quote variable expansions in Stage 0 and Stage 3 helper scripts.

Compliance Blueprints

  • Change the rule_3 Cloud Armor WAF action in blueprints/fedramp-high/gemini-enterprise/gemini-stage-0/cloudarmor.tf from allow to deny(403).
  • Pass bearer tokens to curl via standard input (-H @-) in blueprints/fedramp-high/gemini-enterprise/gem4gov-cli/gem4gov.py and deploy.sh so access tokens are not exposed in process argument lists, and replace random.choices with secrets.choice in data_stores.py.
  • Run the analytics container in blueprints/fedramp-high/gemini-enterprise/analytics/Dockerfile as a non-root user and escape user identity strings before rendering HTML (main.py).
  • Scope VPC Service Controls perimeter access levels, CMEK key bindings, least-privilege service account roles, and sample variable definitions (terraform.tfvars.sample) across cnap, cloud-functions, cloud-build, bigquery, gke, secops, vertex-ai, and vision-ai blueprints.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: AC-2 (Account Management), AC-3 (Access Enforcement), AC-6 (Least Privilege), AU-9 (Protection of Audit Information), CM-6 (Configuration Settings), IA-5 (Authenticator Management), SC-7 (Boundary Protection), SC-28 (Protection of Information at Rest), SI-10 (Information Input Validation).

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

  • Expanded existing domain and structural test suites (tests/tools/test_blueprint_and_module_validations.py, tests/tools/test_bootstrap_logging_order.py, tests/tools/test_check_boilerplate.py, tests/tools/test_gemini_enterprise_fixes.py, tests/tools/test_stage2_networking.py, tests/tools/test_state_iam.py, tests/tools/test_tfdoc.py) and verified all Python unit tests, shell syntax checks, shell unit tests, and Python AST checks pass.
  • Verified HCL reference integrity (var.*, local.*, module.*, google_* resources, variable type definitions, and blueprint terraform.tfvars.sample variable parity) across all Terraform directories under fast/ and blueprints/.
  • Executed live terraform init and terraform plan against an Argolis validation organization across all 5 FAST stages (0-bootstrap, 1-resman, 2-networking-a-fedramp, 2-networking-b-il5-ngfw, 3-security) and all 36 modified blueprint directories.

@aghassemlouei aghassemlouei added Bug Something isn't working Documentation Improvements or additions to documentation Framework - FedRAMP High FedRAMP High compliance regime and controls Framework - FedRAMP Moderate FedRAMP Moderate compliance regime and controls Framework - IL4 DoD Impact Level 4 (IL4) compliance regime and controls Framework - IL5 DoD Impact Level 5 (IL5) compliance regime and controls Gemini - Enterprise Gemini Enterprise (GE) related Gemini - Government Gemini for Government (G4G) related Level of Effort - High Complex task taking a week or more; consider breaking this down into smaller issues. Priority - High Critical issues blocking development or users; urgent bugs or core features for release Scope - Blueprint Related to solution blueprints in the blueprints directory Scope - Fast Related to Fabric FAST deployment stages in the fast directory Scope - Modules Scope - Stage 0 Scope - Stage 2 Security Something is insecure or can be secured labels Sep 28, 2026
@aghassemlouei
aghassemlouei marked this pull request as ready for review September 28, 2026 19:40
@aghassemlouei
aghassemlouei enabled auto-merge (squash) September 28, 2026 19:40
@aghassemlouei
aghassemlouei force-pushed the fix/fortify-security-remediation branch 4 times, most recently from 0988fd4 to 70b33ff Compare September 29, 2026 18:18
@aghassemlouei
aghassemlouei force-pushed the fix/fortify-security-remediation branch from 70b33ff to caffde5 Compare October 1, 2026 00:53
@aghassemlouei

Copy link
Copy Markdown
Member Author

Spoke with @Calvin-Cheng1 and he mentioned that we should shift any relevant files for anything within modules to the upstream CFF repository.

@aghassemlouei
aghassemlouei force-pushed the fix/fortify-security-remediation branch from caffde5 to 7472a15 Compare October 1, 2026 17:33
@aghassemlouei aghassemlouei changed the title fix(security): harden IAM conditions, Terraform modules, FAST stages, and blueprints fix(security): harden IAM conditions, FAST stages, repository tools, and blueprints Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Bug Something isn't working Documentation Improvements or additions to documentation Framework - FedRAMP High FedRAMP High compliance regime and controls Framework - FedRAMP Moderate FedRAMP Moderate compliance regime and controls Framework - IL4 DoD Impact Level 4 (IL4) compliance regime and controls Framework - IL5 DoD Impact Level 5 (IL5) compliance regime and controls Gemini - Enterprise Gemini Enterprise (GE) related Gemini - Government Gemini for Government (G4G) related Level of Effort - High Complex task taking a week or more; consider breaking this down into smaller issues. Priority - High Critical issues blocking development or users; urgent bugs or core features for release Scope - Blueprint Related to solution blueprints in the blueprints directory Scope - Fast Related to Fabric FAST deployment stages in the fast directory Scope - Modules Scope - Stage 0 Scope - Stage 2 Security Something is insecure or can be secured

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants