Skip to content

fix(modules): fix IAM key delimiters, log filters, and conditions in custom modules - #275

Merged
aghassemlouei merged 1 commit into
mainfrom
fix/custom-modules-remediation
Oct 2, 2026
Merged

aghassemlouei merged 1 commit into
mainfrom
fix/custom-modules-remediation

Conversation

@aghassemlouei

@aghassemlouei aghassemlouei commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Description

Fixes logic defects, IAM key delimiter collisions, and conditional binding support across Stellar Engine custom modules (modules/cis-log-alerts, modules/cis-log-metrics, modules/intrusion-detection-system, modules/organization-se, and modules/spanner-instance-se), split out from #274:

  • modules/cis-log-alerts: Exposes var.notification_channels and concatenates additional channels with the default email notification channel; uses each.key instead of the literal string "each.key" for alert condition display names.
  • modules/cis-log-metrics: Fixes operator precedence parentheses in the project-owner-log CIS log filter expression.
  • modules/intrusion-detection-system: Fixes inverted ternary (var.create_service_networking_connection ? 1 : 0) on google_service_networking_connection.private_vpc_connection.
  • modules/organization-se: Uses // delimiter in iam-bpa:${principal}//${role} keys, wraps the comprehension in merge([...]) so empty maps do not fail, and anchors the organization_id validation regular expression (^organizations/[0-9]+$).
  • modules/spanner-instance-se: Adds condition support to var.iam_bindings and google_spanner_instance_iam_binding.authoritative.
  • tests/tools/test_blueprint_and_module_validations.py: Adds unit tests covering all five custom Stellar Engine modules.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: AC-3 (Access Enforcement), AC-6 (Least Privilege), AU-6 (Audit Record Review, Analysis, and Reporting), SI-4 (System Monitoring), SI-10 (Information Input Validation).

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

  • Executed hclfmt across all five custom Stellar Engine modules.
  • Executed python3 -m unittest discover -s tests/tools (35/35 unit tests passing, including test_custom_stellar_engine_modules_validations).

@aghassemlouei aghassemlouei added Bug Something isn't working Security Something is insecure or can be secured labels Oct 1, 2026
@aghassemlouei
aghassemlouei marked this pull request as ready for review October 2, 2026 15:55
@aghassemlouei
aghassemlouei enabled auto-merge (squash) October 2, 2026 15:55

@Calvin-Cheng1 Calvin-Cheng1 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@aghassemlouei
aghassemlouei merged commit c4f60fb into main Oct 2, 2026
20 checks passed
@aghassemlouei
aghassemlouei deleted the fix/custom-modules-remediation branch October 2, 2026 17:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Bug Something isn't working Scope - Modules Security Something is insecure or can be secured

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants