Skip to content

fix(modules): sync folder, net-lb-int, net-lb-proxy-int, spanner-instance, and cloud-run-v2 from upstream CFF - #276

Draft
aghassemlouei wants to merge 1 commit into
mainfrom
fix/sync-upstream-cff-modules
Draft

aghassemlouei wants to merge 1 commit into
mainfrom
fix/sync-upstream-cff-modules

Conversation

@aghassemlouei

@aghassemlouei aghassemlouei commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Description

Syncs the five modules whose remediation fixes already exist in upstream Cloud Foundation Fabric (GoogleCloudPlatform/cloud-foundation-fabric master), split out from #274:

  • modules/folder: Pulls upstream CFF master updates, including splitting "CA_PROTECTED_B, IL5, HIPAA, HITRUST" into separate list items in assured_workload_config.compliance_regime validation.
  • modules/net-lb-int: Pulls upstream CFF master updates, including fixing http2_health_check (local.hc.http2.*) and ssl_health_check (local.hc.ssl.*) attribute references.
  • modules/net-lb-proxy-int: Pulls upstream CFF master updates, removing broken ar.backend_service_config and local.bs_conntrack references in backend-service.tf and guarding var.backend_service_config.backends == null in variables.tf.
  • modules/spanner-instance: Pulls upstream CFF master updates, including dynamic condition blocks on google_spanner_instance_iam_binding.
  • modules/cloud-run-v2: Pulls upstream CFF master updates and removes the deprecated unreferenced modules/cloud-run (v1) directory.
  • Preserves Stellar Engine versions.tf provider constraints (>= 6.21.0, < 7.0.0) across the synced modules to avoid provider version conflicts with FAST stages and blueprints.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Deployment & Compliance Impact

  • Applicable Regimes:
    • US Region Restricted (e.g., Access Policy constraint)
    • FedRAMP Moderate
    • FedRAMP High
    • DoD IL4
    • DoD IL5
    • General / All
  • NIST 800-53r5 Controls: AC-3 (Access Enforcement), AC-6 (Least Privilege), CM-6 (Configuration Settings), SI-10 (Information Input Validation).

Checklist

Code Quality & Reusability

  • My code adheres to the Maximize Reusability principle. I have not redefined common elements and have reused existing base configurations and modules where possible.
  • I have checked that no existing module or configuration in modules/ or fast/ can be leveraged for this change.
  • My code follows the established naming conventions outlined in documentation/naming-convention.md.

Documentation

  • I have updated the README.md of the modified module or blueprint.
  • I have added/updated documentation for inputs (variables) and outputs.

Security

  • My change adheres to GCP security best practices and the principle of least privilege.
  • I have ensured compliance with the targeted regime (FedRAMP Moderate, FedRAMP High, IL5, etc.).

Testing

  • I have tested my changes locally.
  • I have included details of my testing in this PR.

Testing Performed

  • Executed hclfmt and regenerated README.md documentation with tools/tfdoc.py across all synced modules.
  • Executed python3 -m unittest discover -s tests/tools (35/35 unit tests passing, including test_synced_upstream_cff_modules_fixes).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants