Repository navigation
GCPハンズオンガイドのNext.js移植推進・新規課題ガイド追加およびアクセシビリティ・セキュリティ強化 - #116
Conversation
|
Warning Review limit reached
Next review available in: 31 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (5)
📝 WalkthroughSummary by CodeRabbit
Walkthrough変更概要Terraform、GKE、WordPress、Gemini API、Cymbal Directを対象とする日本語ハンズオンガイドを追加しました。Reactページ、HTML・Markdown資料、Mermaid図、ナビゲーション、レスポンシブ表示、描画テスト、移行記録を含みます。 ChangesTerraform Challenge Labガイド
GKEプライベートクラスタセキュリティガイド
Griffin WordPress/GKEガイド
GKE Challenge Labガイド
Gemini APIとCymbal Directガイド
Mermaid表示とプロジェクト記録
Estimated code review effort: 5 (Critical) | ~120 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
✅ Deploy Preview for cloud-infrastructure-studies ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
There was a problem hiding this comment.
Actionable comments posted: 7
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Griffin-wordpress-gke-guide.html`:
- Around line 7-10:
CDN読み込みのtabler-icons、highlight.js、mermaid.jsに、各固定バージョンの正しいSRI
integrityハッシュとcrossorigin="anonymous"属性を追加してください。対象のすべての外部script/link要素で適用し、既存の読み込み元と動作は維持してください。
- Around line 697-701:
Task1〜9の各タスクカード内にある「手順」見出しを、見出し階層に沿うよう<h4>から<h3>へ統一してください。対象は同じパターンで記述されたすべての「手順」見出しとし、見出しテキストや周辺のコードブロック構造は変更しないでください。
- Around line 470-478: Update the responsive navigation behavior around the
.sidebar media query and the IntersectionObserver active-link logic: keep the
table of contents accessible at widths up to 900px by adding an appropriate
mobile navigation mechanism instead of permanently hiding it, and synchronize
the active TOC link with an aria-current attribute when its .active class
changes, removing it from inactive links.
- Around line 1035-1038:
SQLセットアップ例のユーザー名・パスワード引用符と、「つまずきやすいポイント」の説明を、実際のコードに一致するよう統一してください。HTML版で単一引用符を使うなら、注意書きから二重引用符に関する古い説明を更新し、Markdown版の同じSQL例も同じ引用符形式に揃えてください。対象のSQLブロック(CREATE
USER、GRANT)と対応する注意書きの両方を修正してください。
In `@Griffin-wordpress-gke-guide.md`:
- Around line 1-2:
ファイル全体のMarkdown整形を修正し、すべての見出し(MD022)とフェンスコードブロック(MD031)の前後に空白行を追加してください。見出し階層は連続させ、冒頭の「###
VPC / 踏み台ホスト...」をh2に変更して「# Team
Griffin...」から一段ずつ進む構成にしてください。既存の本文内容は変更せず、markdownlint-cli2 --fix相当の修正に限定してください。
In `@Terrafor-gcp-challenge-lab-guide.html`:
- Around line 7-11: Terrafor-gcp-challenge-lab-guide.html の pre.code-block >
code が構文ハイライトされていないため、既存の Ccna-automation-cisco-platforms-and-development.html
と同じ方式で highlight.js を導入してください。HCL/bash の各コード要素に適切な language-*
クラスを付与し、hljs.highlightElement を実行する初期化処理を追加して、対象範囲のコードがハイライト表示されるようにしてください。
In `@Terrafor-gcp-challenge-lab-guide.md`:
- Around line 380-384: Update the code fence around the backend state-copy
prompt to specify the text language, using the existing prompt content
unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: b8d2f125-6d4a-4486-a3c5-eaa61ae5a6c2
📒 Files selected for processing (4)
Griffin-wordpress-gke-guide.htmlGriffin-wordpress-gke-guide.mdTerrafor-gcp-challenge-lab-guide.htmlTerrafor-gcp-challenge-lab-guide.md
There was a problem hiding this comment.
Actionable comments posted: 4
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (4)
Terrafor-gcp-challenge-lab-guide.html (1)
1334-1353: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win子モジュールで root の
module.vpcを参照しないようにしてください。
module "instances"は root から./modules/instancesを読み込むため、root のmodule "vpc"はこのモジュール内部では参照できません。この例のままだとterraform planが失敗します。VPC の出力は root で受け取り、instancesモジュールへの input variable として渡し、子モジュール側はvar.*に参照し直してください。
Terrafor-gcp-challenge-lab-guide.html#L820-L828: root のmodule "instances"にnetwork_name/ subnet 名を渡す。Terrafor-gcp-challenge-lab-guide.html#L1339/1348:module.vpc.network_nameと固定 subnet 名を子モジュールの input variables に置き換える。- 対応する
modules/instances/variables.tfも同じ変数を追加してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Terrafor-gcp-challenge-lab-guide.html` around lines 1334 - 1353, 子モジュール内で root の module.vpc や固定 subnet 名を参照しているため、module "instances" の構成と instances モジュールの入力変数を更新してください。Terrafor-gcp-challenge-lab-guide.html の 820-828 行では VPC の network_name と各 subnet 名を instances に渡し、1334-1353 行では network_interface の参照を対応する var.* に置き換えてください。Terrafor-gcp-challenge-lab-guide.html の 698-717 行は関連する VPC 出力・構成として整合性を確認し、対応する modules/instances/variables.tf に同じ入力変数を追加してください。Griffin-wordpress-gke-guide.html (1)
2159-2177: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win複数セクションが交差した場合のactiveリンク選択を決定論的にしてください。
entries.forEach内で毎回すべてのリンクを解除するため、Observerの帯域内に複数のsectionが入ると、entriesの処理順で最後に処理されたセクションがactiveになります。現在位置ではなく配列順に依存するため、セクション境界で目次表示が不正確になり得ます。交差中セクションを保持し、最上部またはObserver帯域に最も近いものを1つ選んでから、aria-currentを一度だけ更新してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Griffin-wordpress-gke-guide.html` around lines 2159 - 2177, Update the IntersectionObserver callback around observer and entries.forEach to track all currently intersecting sections, then deterministically select the section nearest the top of the viewport or observer band before updating navigation. Clear and set the active link and aria-current exactly once per observer callback, rather than inside each entry iteration, while preserving the existing active-link selector.Griffin-wordpress-gke-guide.md (2)
437-441: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winUptime Check作成コマンドに
project_idを追加してください。
uptime-urlのリソースラベルにはhostだけでなくproject_idも必須です。現状だとgcloud monitoring uptime createが失敗するため、以下の形で指定してください。- --resource-labels=host=<WORDPRESSの外部IP> \ + --resource-labels="host=<WORDPRESSの外部IP>,project_id=${GOOGLE_CLOUD_PROJECT}" \🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Griffin-wordpress-gke-guide.md` around lines 437 - 441, Update the gcloud monitoring uptime create command in the WordPress uptime-check instructions to include the required project_id resource label alongside host, using the appropriate project ID placeholder and preserving the existing command options.Source: MCP tools
348-354: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winJSONキーの発行を推奨手順から外してください。
gcloud iam service-accounts keys create key.jsonは漏えい時に該当サービスアカウントとして認証できる長期資格情報になります。362-364ではWIFを推奨しながら主手順ではキー方式を利用するため、READMEの348-354の手法に合わせて矛盾しています。キー作成手順はラボ専用・代替手順に下げ、主手順はWIF構成に統一してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Griffin-wordpress-gke-guide.md` around lines 348 - 354, 主手順からサービスアカウントのJSONキー作成とkey.jsonを使ったSecret登録を削除し、Workload Identity Federation(WIF)構成に統一してください。cloudsql-instance-credentials周辺の手順は、必要な場合のみラボ専用または代替手順として明示的に分離してください。Source: MCP tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Griffin-wordpress-gke-guide.html`:
- Around line 477-484:
モバイル目次の開閉処理と.sidebar.is-openを、aria-hiddenおよびinertと同期して閉じた目次をTab順・アクセシビリティツリーから除外してください。リンク選択またはEscapeで閉じる際は目次を非表示にする前にトグルへフォーカスを戻し、再度開いた場合のみ目次を操作可能にするよう、対応するJavaScriptのトグル処理とCSS状態を更新してください。
In `@Griffin-wordpress-gke-guide.md`:
- Line 214: マルチNIC
VMをVPC間の中継に使用する手順を追記し、ゲストOSでIP転送を有効化する設定(GCE作成時のcanIpForward相当)、各VPC宛てのルート追加、および中継に必要なファイアウォール許可を明記してください。既存の管理接続手順と区別し、両NIC間でトラフィックを転送できる構成として説明してください。
- Around line 121-122: Griffin-wordpress-gke-guide.md
のカスタムモードVPC説明で、10.128.0.0/9 と 192.168.16.0/20
が競合するという記述を削除または修正してください。カスタムモードを選ぶ理由は、サブネットの自動生成を避け、要件に指定されたCIDRだけを明示的に管理できる点として説明してください。
In `@Terrafor-gcp-challenge-lab-guide.html`:
- Line 1732: Terrafor-gcp-challenge-lab-guide.html の highlight.js 外部アセットに SRI
を追加する。7-10 行の highlight.js CSS と 1732 行の highlight.js JavaScript
の両方へ、各配布内容に対応する検証済みの integrity="sha384-..." と crossorigin="anonymous" を設定する。
---
Outside diff comments:
In `@Griffin-wordpress-gke-guide.html`:
- Around line 2159-2177: Update the IntersectionObserver callback around
observer and entries.forEach to track all currently intersecting sections, then
deterministically select the section nearest the top of the viewport or observer
band before updating navigation. Clear and set the active link and aria-current
exactly once per observer callback, rather than inside each entry iteration,
while preserving the existing active-link selector.
In `@Griffin-wordpress-gke-guide.md`:
- Around line 437-441: Update the gcloud monitoring uptime create command in the
WordPress uptime-check instructions to include the required project_id resource
label alongside host, using the appropriate project ID placeholder and
preserving the existing command options.
- Around line 348-354: 主手順からサービスアカウントのJSONキー作成とkey.jsonを使ったSecret登録を削除し、Workload
Identity
Federation(WIF)構成に統一してください。cloudsql-instance-credentials周辺の手順は、必要な場合のみラボ専用または代替手順として明示的に分離してください。
In `@Terrafor-gcp-challenge-lab-guide.html`:
- Around line 1334-1353: 子モジュール内で root の module.vpc や固定 subnet 名を参照しているため、module
"instances" の構成と instances
モジュールの入力変数を更新してください。Terrafor-gcp-challenge-lab-guide.html の 820-828 行では VPC の
network_name と各 subnet 名を instances に渡し、1334-1353 行では network_interface の参照を対応する
var.* に置き換えてください。Terrafor-gcp-challenge-lab-guide.html の 698-717 行は関連する VPC
出力・構成として整合性を確認し、対応する modules/instances/variables.tf に同じ入力変数を追加してください。
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 83977510-84f5-4ca4-a37e-3f8728167cb8
📒 Files selected for processing (4)
Griffin-wordpress-gke-guide.htmlGriffin-wordpress-gke-guide.mdTerrafor-gcp-challenge-lab-guide.htmlTerrafor-gcp-challenge-lab-guide.md
…ets in Terrafor guide
…e references in Terrafor guide
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 5
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
Griffin-wordpress-gke-guide.md (1)
331-331: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winデータベースパスワードを固定値で文書化しないでください。
stormwind_rulesはそのまま利用可能な認証情報であり、後続のSecretにも複製されます。プレースホルダーまたは生成した値を使い、ラボ指定の固定値である場合も「ラボ専用・終了後に変更」と明記してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Griffin-wordpress-gke-guide.md` at line 331, Replace the hardcoded database password in the CREATE USER example with a clearly marked placeholder or generated-value reference, and ensure any corresponding Secret example uses the same non-sensitive value. If the lab requires this fixed credential, explicitly label it as lab-only and instruct users to change it after completion.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Gcp-bastion-iap-firewall-best-practices.html`:
- Around line 1381-1382: Update the SSH flow in the Admin-to-Juice sequence
diagram so the connection to the juice-shop internal IP originates from Bastion
rather than Admin, matching the permitted flow described near the existing
diagram. Keep the established SSH command and shell-session outcome unchanged
while correcting the sender and receiver labels as needed.
In `@Griffin-wordpress-gke-guide.md`:
- Line 537: Update the command’s host value in the bash example to remove angle
brackets from the shell placeholder, using a safe identifier such as
WORDPRESS_EXTERNAL_IP or an equivalent quoted variable reference. Preserve the
existing Uptime Check host label format and project_id argument.
- Around line 221-222: Update the production-side route definitions in the guide
to use next-hop-address with the reserved internal IP of the production VPC NIC,
rather than next-hop-instance. Ensure prod-to-dev-* routes reference
production-side NIC IPs and dev-to-prod-* routes reference development-side NIC
IPs, matching each route’s corresponding NIC.
In `@Terrafor-gcp-challenge-lab-guide.html`:
- Around line 2356-2426: Replace the custom HL_PATTERNS/highlight implementation
and its target.innerHTML assignment with the shared hljs flow used by the other
guide: set the target language as needed and call hljs.highlightElement(target)
for each code-src target. Ensure the highlight.js dependency is loaded before
this initialization, and register a separate HCL/Terraform language definition
when required because core hljs does not provide HCL.
- Around line 2433-2452: Update the MERMAID_CDNS configuration and loadScript
function to associate each CDN URL with its verified SHA384 SRI hash, then set
the generated script element’s integrity and crossOrigin properties before
appending it. Preserve the existing fallback loading and error behavior while
ensuring every configured Mermaid CDN uses cross-origin SRI validation.
---
Outside diff comments:
In `@Griffin-wordpress-gke-guide.md`:
- Line 331: Replace the hardcoded database password in the CREATE USER example
with a clearly marked placeholder or generated-value reference, and ensure any
corresponding Secret example uses the same non-sensitive value. If the lab
requires this fixed credential, explicitly label it as lab-only and instruct
users to change it after completion.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 8fcba270-89dc-4631-95c4-4faf29cda6e1
📒 Files selected for processing (4)
Gcp-bastion-iap-firewall-best-practices.htmlGriffin-wordpress-gke-guide.htmlGriffin-wordpress-gke-guide.mdTerrafor-gcp-challenge-lab-guide.html
…tion and enforce SHA384 SRI on Mermaid CDNs
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Griffin-wordpress-gke-guide.md`:
- Around line 531-535: 公開形式間でUptime Checkコマンドのホスト指定を統一してください。Markdownのgcloud
monitoring uptime
create例は、外部IP取得後に設定されるWORDPRESS_EXTERNAL_IP変数を使用する手順と整合させ、HTML側のhost指定もシェルで実行可能な形式または同じ変数形式に変更してください。
In `@Terrafor-gcp-challenge-lab-guide.html`:
- Around line 2358-2362: Terrafor-gcp-challenge-lab-guide.html の highlight.js と
Mermaid CDN script 要素の integrity 属性を実際の SHA-384 ダイジェストに更新してください。highlight.js
は指定された
`sha384-F_bZzf7p3Joyp5psL90p/p89AZJsndkSoGwRpXcZhleCWhd8SnRuoYo4d0yirjJp`、Mermaid
の各 CDN は指定された
`sha384-o-g_BxPwhi0C3RK7oQBxQuNimeafQ3GE_ST4iT2BxVI4Wzt60SH4pq9iXVYujjaS`
を使用し、2358-2362 と 2434-2466 の全対象箇所を修正してください。
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 7894aa1c-5620-4efe-9f3f-8ca1f7dbfcb4
📒 Files selected for processing (3)
Gcp-bastion-iap-firewall-best-practices.htmlGriffin-wordpress-gke-guide.mdTerrafor-gcp-challenge-lab-guide.html
…into routing and update docs
…ster security guide html and md files
…ting, and 1rem diagram scaling
…, and protect 1rem diagram text size
…syntax highlighting steps
…uting and update docs
…ss gke guide files
There was a problem hiding this comment.
Actionable comments posted: 16
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@__tests__/gcl/hands-on/gke-private-cluster-security-guide/page.test.tsx`:
- Around line 112-124:
ページテストにNavBarのアクセシビリティ検証を追加し、目次ナビゲーションのaria-labelが「ページ内目次」であること、リンクが9個存在すること、アクティブ項目にaria-currentが設定されていることを確認してください。既存のレイアウトおよびコードブロック検証は変更しないでください。
- Around line 102-110: Update the MermaidDiagram test to compare each rendered
diagram against an explicit DIAGRAMS key sequence rather than
Object.values(DIAGRAMS)[index]. Use the key to retrieve the expected chart while
retaining the existing count, preserveNaturalScale, and aria-label assertions.
In
`@app/gcl/hands-on/gke-private-cluster-security-guide/GkePrivateClusterSecurityGuide.tsx`:
- Line 232:
集約する6つの根拠行要素について、インラインのfontSize指定を削除し、page.cssの.source-noteクラスへ移行してください。GkePrivateClusterSecurityGuide.tsxの各該当要素にclassName="source-note"を付与し、page.cssで13.5pxのフォントサイズを定義してください。
- Around line 688-690:
GkePrivateClusterSecurityGuide.tsxの移行内容を元Markdownと一致させ、情報を省略せず補足説明とコマンドを復元する。445-446行では完全なgcloud
IAM確認コマンドを、575-581行では実際のクラスタ名への置換注記とRegion/Zone説明を、688-690行ではkubectl get
deploymentsの併記とLoadBalancer
Service公開が必須でない注記を、755-756行ではSAへの誤ったロール付与例を、779行では「/32以外を指定」の原因例を追加する。
In `@app/gcl/hands-on/gke-private-cluster-security-guide/page.css`:
- Around line 91-97: Update the .gke-security-guide-page .main styles to remove
the full-width behavior from max-width: 100% and width: auto, set an appropriate
readable max-width, and center the content within the available layout while
preserving the existing sidebar offset and padding.
In `@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/constants.ts`:
- Around line 105-120: Add an explicit shared type annotation to
NAVIGATION_ITEMS that supports both regular navigation entries and divider
entries, with icon, label, and isDivider represented as optional properties
where appropriate. Ensure NavBar.tsx can safely access item.icon, item.label,
and item.isDivider under the inferred item type.
In
`@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx`:
- Around line 41-44: Add aria-hidden="true" to every decorative <i> Tabler icon
in TerraformGcpChallengeLabGuide, including the hero-eyebrow, hero-meta, h3,
callout-title, and all other listed icon elements, while leaving meaningful text
to provide accessible names.
- Around line 145-147:
「根拠」引用ブロックの重複したインラインスタイルを共通化してください。TerraformGcpChallengeLabGuide
の8箇所すべてで、段落とアイコンの style 属性を削除して source-note クラスを適用し、page.css に
.terraform-lab-guide-page .source-note とその配下の i
用スタイルを追加してください。アイコン色は既存の淡色テキストと命名を合わせ、var(--color-guide-foreground-faint)
を使用してください。
In `@Griffin-wordpress-gke-guide.html`:
- Line 1543: Uptime Check のリソースラベル設定を更新し、既存の host="$WORDPRESS_EXTERNAL_IP" に加えて
project_id="$PROJECT_ID" を含めてください。あわせて、ガイド内で $PROJECT_ID に対象の Cloud
プロジェクトIDを設定する手順または値を明示し、--resource-type=uptime-url の識別に両方のラベルが使われる状態にしてください。
In `@Manage-Kubernetes-in-Google-Cloud.html`:
- Around line 427-435: Update the responsive layout around the .sidebar rule so
the table of contents remains accessible at widths of 900px and below. Add a
collapsible in-content TOC using details/summary or an equivalent toggle, ensure
it contains the same navigation entries as the sidebar, and place it near the
beginning of .content while retaining the desktop sidebar behavior.
- Around line 834-836: Escape the raw greater-than character in the
`pod-image-errors` command’s `severity>=ERROR` filter within the `gcloud logging
metrics create` example, replacing it with the HTML entity `>` while
preserving the displayed command and filter semantics.
- Around line 440-455: Update the nested navigation structure around the sidebar
so the inner nav element identified by id="toc" has a descriptive aria-label,
while keeping the outer sidebar nav unchanged. Ensure the opening and closing
markup remains properly matched.
- Around line 1546-1597: Update the Mermaid rendering flow around mermaid.run so
both CDN absence and rendering exceptions populate each corresponding
div.mermaid with the source text from its script.mermaid-src element wrapped in
a pre element. Keep successful Mermaid rendering unchanged, and ensure the
fallback runs when mermaid is unavailable or mermaid.run rejects or throws.
- Around line 1542-1545: Manage-Kubernetes-in-Google-Cloud.html の外部 cdnjs
スクリプト(highlight.min.js、bash.min.js、yaml.min.js、mermaid.min.js)に、それぞれ対応する正確な SRI
integrity 値と crossorigin="anonymous" を追加してください。既存の CDN
呼び出しのみを対象にし、スクリプトの構成や読み込み数は変更しないでください。
In `@Manage-Kubernetes-in-Google-Cloud.md`:
- Line 337: Task 6 の確認内容を、図および main.go
の変更手順で示される期待表示と一致するよう統一してください。該当チェックリストの「Version: 2.0.0」と「Hello,
world!」のどちらを検証するか決定し、Line 23・Line 268 の図とチェックリストの記載を同じ文字列に更新してください。
- Around line 1-2: Markdown の各見出しについて、見出しの直前と直後に空行を追加し、MD022
違反を解消してください。対象は冒頭の見出しと、Line 72、117、152、213、252、319 付近の見出しです。
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: d43619bf-c9da-40e1-a515-efaebc6d7bff
📒 Files selected for processing (20)
GEMINI.mdGriffin-wordpress-gke-guide.htmlMIGRATION_PROGRESS.mdManage-Kubernetes-in-Google-Cloud.htmlManage-Kubernetes-in-Google-Cloud.md__tests__/gcl/hands-on/gke-private-cluster-security-guide/page.test.tsx__tests__/gcl/hands-on/terraform-gcp-challenge-lab-guide/page.test.tsxapp/constants.tsapp/gcl/hands-on/gke-private-cluster-security-guide/GkePrivateClusterSecurityGuide.tsxapp/gcl/hands-on/gke-private-cluster-security-guide/NavBar.tsxapp/gcl/hands-on/gke-private-cluster-security-guide/constants.tsapp/gcl/hands-on/gke-private-cluster-security-guide/page.cssapp/gcl/hands-on/gke-private-cluster-security-guide/page.tsxapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/NavBar.tsxapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsxapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/constants.tsapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/page.cssapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/page.tsxarchive/Gcl_Archive/Hands-on/html/Gke-private-cluster-security-guide.htmlarchive/Gcl_Archive/Hands-on/md/Gke-private-cluster-security-guide.md
There was a problem hiding this comment.
Actionable comments posted: 6
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (4)
app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx (4)
9-32: 📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick win
IntersectionObserverの意図を JSDoc に記録してください。コンポーネント宣言の直前に JSDoc を追加してください。
activeIdが表示中の section に応じて NavBar を更新することを記録してください。As per coding guidelines: 「コンポーネントとユーティリティ関数にはJSDocを追加する。」
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx` around lines 9 - 32, Add a JSDoc comment immediately before the TerraformGcpChallengeLabGuide component declaration documenting that its IntersectionObserver tracks the currently visible section and updates the NavBar through activeId.Source: Coding guidelines
491-512: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winHTTP 許可の対象 VM を限定してください。
google_compute_firewall.tf-firewallはtarget_tagsとtarget_service_accountsを指定しておらず、source_ranges = ["0.0.0.0/0"]の TCP/80 がこの VPC 内の全 VM に適用されます。HTTP を受ける VM だけに网络 tag を付け、target_tagsで限定してください。0.0.0.0/0の公開が Lab の要件である場合は、その例外を明記してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx` around lines 491 - 512, HTTP 許可の対象を限定するため、Terraform の google_compute_instance "instance-name" に HTTP 用のネットワークタグを付与し、対応する google_compute_firewall.tf-firewall の target_tags で同じタグを指定してください。source_ranges の公開範囲は変更せず、Lab 要件として 0.0.0.0/0 が必要な場合はその例外を明記してください。
261-269: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winVPC 入力を
instancesmodule に渡す構成にしてください。
main.tfではmodule "instances"に対し network inputs を渡しておらず、modules/instances/instances.tf内では未宣言のmodule.vpcを参照しています。兄弟 module は直接参照できないため、root module 側でterraform-google-modules/network/googlev10.0.0 の VPC/SUBNET outputs を input variable に渡し、child module ではvar.*を参照してください。network用にはnetwork_self_linkを渡すのが推奨です。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx` around lines 261 - 269, Update the main.tf example for module "instances" to pass the VPC and subnet outputs from the terraform-google-modules/network/google v10.0.0 root module, using network_self_link for the network input and the corresponding subnet value for the subnet input. Ensure the child modules/instances/instances.tf implementation consumes these values through its declared var.* inputs instead of referencing the sibling module.vpc directly.
382-387: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winstate バケットの破壊を防ぎ、オブジェクトの版管理を有効にしてください。
このバケットは gcs backend が state を保持します。
force_destroy = trueはバケット削除時に格納オブジェクトも削除します。versioningがないため、誤削除または誤上書きから復旧できません。
force_destroyをfalseにし、versioning { enabled = true }を追加してください。Challenge Lab の後片付けだけでforce_destroyが必要な場合は、本番向けの構成例と分離してください。HashiCorp は GCS backend の state 回復のため Object Versioning を推奨しています。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx` around lines 382 - 387, Update the displayed google_storage_bucket "default" example to set force_destroy to false and add a versioning block with enabled set to true, preserving the existing bucket attributes and formatting.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In
`@app/gcl/hands-on/gke-private-cluster-security-guide/GkePrivateClusterSecurityGuide.tsx`:
- Around line 585-589: Update the GKE command examples in
GkePrivateClusterSecurityGuide so --region and --zone are mutually exclusive:
use only --region for regional clusters and only --zone for zonal clusters
across create, update, and get-credentials commands. In particular, correct the
regional get-credentials example to use --region instead of --zone.
In `@app/gcl/hands-on/griffin-wordpress-gke-guide/GriffinWordPressGkeGuide.tsx`:
- Around line 947-1043: Task 8のgcloud uptime check作成例で、`--resource-labels`
に対象プロジェクトを示す `project_id` も指定してください。既存の `host="$WORDPRESS_EXTERNAL_IP"` は維持し、現在の
`gcloud monitoring uptime create` コマンドが必要な両方のリソースラベルを含む形に更新してください。
In `@app/gcl/hands-on/griffin-wordpress-gke-guide/NavBar.tsx`:
- Around line 25-79:
NavBarのasideとhandleClickを更新し、モバイル幅で目次が閉じている間はaria-hiddenとinertを有効化してTab順および支援技術ツリーから除外してください。isOpen状態だけでなく既存のモバイル幅判定と連動させ、デスクトップでは常に利用可能な状態を維持します。リンククリック後に目次を閉じる場合は、GriffinWordPressGkeGuide.tsxのtoc-toggleボタンへフォーカスを戻してください。
In `@app/gcl/hands-on/griffin-wordpress-gke-guide/page.css`:
- Around line 3-39: Replace the new custom properties in
.griffin-wordpress-gke-guide-page with matching established three-layer tokens
from the global design system wherever available. If a complete replacement is
not safe in this change, retain only the necessary scoped variables and add a
clear TODO comment identifying the required follow-up migration.
In `@CLAUDE.md`:
- Around line 133-138: CLAUDE.md の GriffinWordPressGkeGuide ディレクトリ案内を、実装および
app/constants.ts の登録先と一致する app/gcl/hands-on/griffin-wordpress-gke-guide/
に修正してください。
In `@Manage-Kubernetes-in-Google-Cloud.html`:
- Around line 879-881: Update the pod-image-errors metric definition in the
corresponding Markdown and HTML documentation to filter Kubernetes Pod events
using log_id("events"), resource.type="k8s_pod", and a failed-related error
condition, replacing the current k8s_container filter while preserving the
metric name and alert usage.
---
Outside diff comments:
In
`@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx`:
- Around line 9-32: Add a JSDoc comment immediately before the
TerraformGcpChallengeLabGuide component declaration documenting that its
IntersectionObserver tracks the currently visible section and updates the NavBar
through activeId.
- Around line 491-512: HTTP 許可の対象を限定するため、Terraform の google_compute_instance
"instance-name" に HTTP 用のネットワークタグを付与し、対応する google_compute_firewall.tf-firewall の
target_tags で同じタグを指定してください。source_ranges の公開範囲は変更せず、Lab 要件として 0.0.0.0/0
が必要な場合はその例外を明記してください。
- Around line 261-269: Update the main.tf example for module "instances" to pass
the VPC and subnet outputs from the terraform-google-modules/network/google
v10.0.0 root module, using network_self_link for the network input and the
corresponding subnet value for the subnet input. Ensure the child
modules/instances/instances.tf implementation consumes these values through its
declared var.* inputs instead of referencing the sibling module.vpc directly.
- Around line 382-387: Update the displayed google_storage_bucket "default"
example to set force_destroy to false and add a versioning block with enabled
set to true, preserving the existing bucket attributes and formatting.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: b556418b-c2c7-4046-a9d3-af62b84946d5
📒 Files selected for processing (20)
CLAUDE.mdGEMINI.mdMIGRATION_PROGRESS.mdManage-Kubernetes-in-Google-Cloud.htmlManage-Kubernetes-in-Google-Cloud.md__tests__/gcl/hands-on/gke-private-cluster-security-guide/page.test.tsx__tests__/gcl/hands-on/griffin-wordpress-gke-guide/page.test.tsxapp/constants.tsapp/gcl/hands-on/gke-private-cluster-security-guide/GkePrivateClusterSecurityGuide.tsxapp/gcl/hands-on/gke-private-cluster-security-guide/page.cssapp/gcl/hands-on/griffin-wordpress-gke-guide/GriffinWordPressGkeGuide.tsxapp/gcl/hands-on/griffin-wordpress-gke-guide/NavBar.tsxapp/gcl/hands-on/griffin-wordpress-gke-guide/constants.tsapp/gcl/hands-on/griffin-wordpress-gke-guide/page.cssapp/gcl/hands-on/griffin-wordpress-gke-guide/page.tsxapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsxapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/constants.tsapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/page.cssarchive/Gcl_Archive/Hands-on/html/Griffin-wordpress-gke-guide.htmlarchive/Gcl_Archive/Hands-on/md/Griffin-wordpress-gke-guide.md
There was a problem hiding this comment.
Actionable comments posted: 4
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx (1)
648-707: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win
module.vpc.subnets_namesの位置インデックス参照は名前順に依存します。665〜666行目は
module.vpc.subnets_names[0]と[1]でサブネット名を取得しています。terraform-google-modules/network/googleのsubnets_names出力はsubnetsマップ(キーはregion/name)をfor式で走査して生成されるため、要素の並び順はキーのアルファベット順になります。本ガイドのsubnet-01/subnet-02という命名では偶然アルファベット順と入力順が一致するため動作しますが、読者が別の命名規則(例: 名前が入力順と逆順にソートされるケース)でこのパターンを応用すると、誤ったサブネットがtf-instance-1/tf-instance-2に割り当てられる可能性があります。
module.vpc.subnets["<REGION>/subnet-01"].self_linkのように、名前をキーにした明示的な参照に置き換えるほうが安全です。♻️ 提案する修正例
<div className="code-line"> <span className="tok-comment"># terraform-google-modules/network/google v10.0.0 の output を渡す</span></div> - <div className="code-line"> <span className="tok-attr">network</span> = <span className="tok-variable">module.vpc.network_self_link</span></div> - <div className="code-line"> <span className="tok-attr">subnet_01</span> = <span className="tok-variable">module.vpc.subnets_names</span>[<span className="tok-number">0</span>]</div> - <div className="code-line"> <span className="tok-attr">subnet_02</span> = <span className="tok-variable">module.vpc.subnets_names</span>[<span className="tok-number">1</span>]</div> + <div className="code-line"> <span className="tok-attr">network</span> = <span className="tok-variable">module.vpc.network_self_link</span></div> + <div className="code-line"> <span className="tok-attr">subnet_01</span> = <span className="tok-variable">module.vpc.subnets_names</span>[<span className="tok-string">"subnet-01"</span>]</div> + <div className="code-line"> <span className="tok-attr">subnet_02</span> = <span className="tok-variable">module.vpc.subnets_names</span>[<span className="tok-string">"subnet-02"</span>]</div>
subnets_namesがリスト出力の場合はマップではなく[for s in module.vpc.subnets : s.name if strcontains(s.self_link, "subnet-01")][0]のような名前ベースの絞り込みに置き換える方法も検討してください。実際の出力構造はモジュールのバージョンで確認してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx` around lines 648 - 707, Update the root module’s subnet arguments in the “main.tf” example to select each subnet by its explicit region/name key rather than positional indexes into module.vpc.subnets_names. Use the module.vpc.subnets map and each subnet’s self_link, preserving subnet-01 for subnet_01 and subnet-02 for subnet_02; verify the referenced output shape for the documented module version.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Cymbal-direct-agent-platform-prompt-design-guide.html`:
- Around line 1439-1492: Update every checkbox in the checklist under <ul
class="checklist"> to associate its descriptive text with a label by wrapping
each disabled input and its full item text in a <label> element. Apply this
consistently to all 13 checklist entries while preserving their existing
Japanese and English text.
In `@Cymbal-direct-agent-platform-prompt-design-guide.md`:
- Around line 1-2:
修正対象は両Markdownガイドの見出し階層です。Cymbal-direct-agent-platform-prompt-design-guide.mdの1-2行目では、h1直後の副題をh2へ変更するか通常テキストにし、Gemini-api-challenge-lab-best-practices.mdの1-3行目でも同じ対応を行って、h1からh3へ飛ぶ構造をなくしてください。
- Around line 24-33: このガイド冒頭の2つの独立したブロッククォートの間にある空行を修正してください。Line 28-29 と Line
31-32 の間の空行に `>` プレフィックスを追加し、markdownlint の MD028 違反を解消してください。
In `@Gemini-api-challenge-lab-best-practices.md`:
- Around line 85-87: Add a language identifier such as text to the fenced code
block containing the Vertex AI endpoint, preserving the endpoint content
unchanged.
---
Outside diff comments:
In
`@app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx`:
- Around line 648-707: Update the root module’s subnet arguments in the
“main.tf” example to select each subnet by its explicit region/name key rather
than positional indexes into module.vpc.subnets_names. Use the
module.vpc.subnets map and each subnet’s self_link, preserving subnet-01 for
subnet_01 and subnet-02 for subnet_02; verify the referenced output shape for
the documented module version.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: af13f6f4-fb92-4995-9ee6-6308afa61462
📒 Files selected for processing (13)
CLAUDE.mdCymbal-direct-agent-platform-prompt-design-guide.htmlCymbal-direct-agent-platform-prompt-design-guide.mdGemini-api-challenge-lab-best-practices.htmlGemini-api-challenge-lab-best-practices.mdManage-Kubernetes-in-Google-Cloud.htmlManage-Kubernetes-in-Google-Cloud.md__tests__/gcl/hands-on/griffin-wordpress-gke-guide/page.test.tsxapp/gcl/hands-on/gke-private-cluster-security-guide/GkePrivateClusterSecurityGuide.tsxapp/gcl/hands-on/griffin-wordpress-gke-guide/GriffinWordPressGkeGuide.tsxapp/gcl/hands-on/griffin-wordpress-gke-guide/NavBar.tsxapp/gcl/hands-on/griffin-wordpress-gke-guide/page.cssapp/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx
|
Note Docstrings generation - SUCCESS |
Docstrings generation was requested by @myoshi2891. The following files were modified: * `app/gcl/hands-on/gke-private-cluster-security-guide/GkePrivateClusterSecurityGuide.tsx` * `app/gcl/hands-on/gke-private-cluster-security-guide/page.tsx` * `app/gcl/hands-on/griffin-wordpress-gke-guide/GriffinWordPressGkeGuide.tsx` * `app/gcl/hands-on/terraform-gcp-challenge-lab-guide/TerraformGcpChallengeLabGuide.tsx` * `app/gcl/hands-on/terraform-gcp-challenge-lab-guide/page.tsx` These files were kept as they were: * `app/gcl/hands-on/griffin-wordpress-gke-guide/page.tsx` These files were ignored: * `__tests__/gcl/hands-on/gke-private-cluster-security-guide/page.test.tsx` * `__tests__/gcl/hands-on/griffin-wordpress-gke-guide/page.test.tsx` * `__tests__/gcl/hands-on/terraform-gcp-challenge-lab-guide/page.test.tsx` These file types are not supported: * `CLAUDE.md` * `Cymbal-direct-agent-platform-prompt-design-guide.html` * `Cymbal-direct-agent-platform-prompt-design-guide.md` * `GEMINI.md` * `Gcp-bastion-iap-firewall-best-practices.html` * `Gemini-api-challenge-lab-best-practices.html` * `Gemini-api-challenge-lab-best-practices.md` * `MIGRATION_PROGRESS.md` * `Manage-Kubernetes-in-Google-Cloud.html` * `Manage-Kubernetes-in-Google-Cloud.md` * `Terrafor-gcp-challenge-lab-guide.md` * `app/gcl/hands-on/gke-private-cluster-security-guide/page.css` * `app/gcl/hands-on/griffin-wordpress-gke-guide/page.css` * `app/gcl/hands-on/terraform-gcp-challenge-lab-guide/page.css` * `archive/Gcl_Archive/Hands-on/html/Gke-private-cluster-security-guide.html` * `archive/Gcl_Archive/Hands-on/html/Griffin-wordpress-gke-guide.html` * `archive/Gcl_Archive/Hands-on/md/Gke-private-cluster-security-guide.md` * `archive/Gcl_Archive/Hands-on/md/Griffin-wordpress-gke-guide.md`
Docstrings generation was requested by @myoshi2891. * #116 (comment) The following files were modified: * `app/gcl/hands-on/griffin-wordpress-gke-guide/GriffinWordPressGkeGuide.tsx`
📝 Add docstrings to `dev`
主に GCPハンズオン実践ガイドの Next.js への TDD 移植、新規ハンズオン課題ガイドの追加、および コードハイライト・アクセシビリティ・セキュリティ対策の強化 で構成されています。
主要な変更内容
1. GCP ハンズオン実践ガイドの Next.js 移植 (
feat/test/refactor)TDD 開発フロー(Step 1: Failテスト作成 ➔ Step 2: 実装 ➔ Step 3: ルーティング統合・リファクタリング・アーカイブ)に基づき、以下のガイドを Next.js App Router コンポーネントに移植・統合しました。
/app/gcl/hands-on/terraform-gcp-challenge-lab-guide)/app/gcl/hands-on/gke-private-cluster-security-guide)/app/gcl/hands-on/griffin-wordpress-gke-guide)2. 学習ガイド・ドキュメントの新規追加・拡充 (
docs)Gemini API challenge lab best practicesガイドCymbal Direct Agent Platform prompt design challenge labガイドManage Kubernetes in Google Cloudガイド(HTML / Markdown)MIGRATION_PROGRESS.mdの進捗状況の更新および旧 HTML 資料のGcl_Archive/へのアーカイブ化。3. UI/UX・アクセシビリティおよびコード品質の強化 (
fix/style/refactor)MermaidDiagramコンポーネントへのariaLabelプロパティ必須化。code-lineラッパーを用いたコードブロック内の改行・インデント保持のリファクタリング。<label>要素適用。crossorigin属性の付与。self_link参照、アップタイムチェックホスト変数、DBパスワード、ルーティング next-hop 設定の記述修正・堅牢化。