Skip to content

feat(gemini-enterprise): relocate blueprint and add multi-regime compliance support - #279

Open
aghassemlouei wants to merge 1 commit into
mainfrom
feat/gemini-enterprise-multi-regime
Open

aghassemlouei wants to merge 1 commit into
mainfrom
feat/gemini-enterprise-multi-regime

Conversation

@aghassemlouei

@aghassemlouei aghassemlouei commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

This pull request relocates the gemini-enterprise blueprint out of blueprints/fedramp-high/gemini-enterprise to blueprints/gemini-enterprise and updates its Terraform configuration (gemini-stage-0), interactive deployment script (deploy.sh), and onboarding CLI (gem4gov-cli) to support the target Assured Workloads compliance regimes (FEDRAMP_MODERATE, FEDRAMP_HIGH, IL4, and IL5, as well as NONE for non-regulated commercial deployments).

Changes Made

  • Relocated blueprints/fedramp-high/gemini-enterprise to blueprints/gemini-enterprise and updated path references in .github/workflows/ci.yml, docs/tdd.md, blueprints/gemini-enterprise/README.md, blueprints/gemini-enterprise/analytics/README.md, and tests/.
  • Updated var.compliance_regime validation in blueprints/gemini-enterprise/gemini-stage-0/variables.tf to allow FEDRAMP_MODERATE, FEDRAMP_HIGH, IL4, IL5, and NONE.
  • Updated blueprints/gemini-enterprise/gemini-stage-0/main.tf and model_armor.tf to gate restricted_services (beyondcorp.googleapis.com, certificatemanager.googleapis.com, modelarmor.googleapis.com) and Model Armor template provisioning using !contains(["IL4", "IL5"], var.compliance_regime).
  • Updated blueprints/gemini-enterprise/deploy.sh to support selecting FEDRAMP_HIGH, FEDRAMP_MODERATE, IL4, IL5, and NONE, configure KMS key protection levels (software for FEDRAMP_MODERATE, hsm for FEDRAMP_HIGH, IL4, and IL5), and apply compliance controls across the supported regulated boundaries.
  • Updated blueprints/gemini-enterprise/gem4gov-cli/gem4gov.py and README.md so gem4gov onboard, gem4gov app create, and gem4gov app update-compliance accept FEDRAMP_MODERATE, FEDRAMP_HIGH, IL4, and IL5.
  • Added unit tests in tests/tools/test_gemini_enterprise_fixes.py verifying the blueprint relocation and target compliance regime support.

Related Issues

Closes #99
Closes #102
Closes #18
Closes #30

@aghassemlouei aghassemlouei added Documentation Improvements or additions to documentation Enhancement New feature or request Framework - FedRAMP Moderate FedRAMP Moderate compliance regime and controls Framework - FedRAMP High FedRAMP High compliance regime and controls Framework - IL4 DoD Impact Level 4 (IL4) compliance regime and controls Framework - IL5 DoD Impact Level 5 (IL5) compliance regime and controls Gemini - Enterprise Gemini Enterprise (GE) related Gemini - Government Gemini for Government (G4G) related Scope - Blueprint Related to solution blueprints in the blueprints directory labels Oct 5, 2026
@aghassemlouei
aghassemlouei enabled auto-merge (squash) October 5, 2026 20:31
@aghassemlouei
aghassemlouei force-pushed the feat/gemini-enterprise-multi-regime branch from ae61ab0 to bc8ec84 Compare October 5, 2026 20:40
@aghassemlouei
aghassemlouei force-pushed the feat/gemini-enterprise-multi-regime branch from bc8ec84 to 8a60459 Compare October 5, 2026 22:05
…liance support

- Relocate `blueprints/fedramp-high/gemini-enterprise` to `blueprints/gemini-enterprise` (#99)
- Scope `gemini-stage-0`, `deploy.sh`, and `gem4gov-cli` compliance support to `FEDRAMP_MODERATE`, `FEDRAMP_HIGH`, `IL4`, `IL5`, and `NONE` (#102, #18, #30)
- Update CI workflows, test paths, and documentation references
@aghassemlouei
aghassemlouei force-pushed the feat/gemini-enterprise-multi-regime branch from 8a60459 to 6c43d76 Compare October 6, 2026 03:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Documentation Improvements or additions to documentation Enhancement New feature or request Framework - FedRAMP High FedRAMP High compliance regime and controls Framework - FedRAMP Moderate FedRAMP Moderate compliance regime and controls Framework - IL4 DoD Impact Level 4 (IL4) compliance regime and controls Framework - IL5 DoD Impact Level 5 (IL5) compliance regime and controls Gemini - Enterprise Gemini Enterprise (GE) related Gemini - Government Gemini for Government (G4G) related Scope - Blueprint Related to solution blueprints in the blueprints directory

Projects

None yet

1 participant