Repository navigation
GCP / Cisco 学習ガイドの拡充、Mermaid 描画・アクセシビリティ強化、および全幅サイドバーレイアウトの標準化 - #120
Conversation
✅ Deploy Preview for cloud-infrastructure-studies ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
📝 WalkthroughSummary by CodeRabbit
WalkthroughBigQuery、GKE、IAM、ネットワーク、Workspace、Knowledge Catalog、ML API、Cloud Storageの学習ガイドを追加しました。CCNA Automationページ、Mermaid表示基盤、HTML移行規約、レイアウト検証、開発手順を更新しました。 Changesクラウド学習ガイド
CCNA Automation移行
Mermaid表示と開発規約
既存ガイド整理
Estimated code review effort: 5 (Critical) | ~120 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 32
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Bigquery-appsscript-connectedsheets-guide.html`:
- Around line 522-524: diagram-caption
のキャプションから「クリックで拡大されません。」という否定表現を削除し、「4タスクの全体アーキテクチャ」と図の内容だけを示す文言に更新してください。
- Around line 1011-1019: 「task4」の見出しと手順の不整合を解消し、Apps
Scriptで新規ワークシートを作成する内容に合わせて手順1〜3へSpreadsheetAppを使う操作またはコード例を追加してください。HTMLと対応するMarkdownのtask4記述を同じ内容に更新し、手動入力だけの手順にならないようにしてください。
In `@Bigquery-appsscript-connectedsheets-guide.md`:
- Around line 1-2:
見出し階層と空行のMarkdownlint警告を解消するため、Bigquery-appsscript-connectedsheets-guide.mdのh1直後の副題を空行を挟んだ強調段落または##見出しに変更し、Ml-api-challenge-lab-guide.mdの同じ位置にある副題にも同じ変更を適用してください。
In `@Bigquery-covid19-challenge-lab-guide.md`:
- Around line 170-182: Update the Task 2 explanation around subregion1_name IS
NOT NULL to state that it excludes country-level rows but still allows
county-level rows, which can be double-counted with state rows in
SUM(cumulative_deceased). Add the same county-level caveat and required
filtering guidance to the corresponding Task 3 explanation around line 206.
- Line 372: Task 7 and Task 8 must use placeholders for participant-specific
dates and thresholds instead of fixed values. Update the date literals near the
Task 7 query and the date/50000 threshold near Task 8 to match the existing
placeholder format used by other tasks; also replace Task 9’s lab-dependent
2020-01-24 value with the corresponding placeholder.
- Around line 505-513: Update the summary CTE around summary to remove LIMIT 1
and retain only the row where last_day_cases IS NOT NULL, ensuring the first-day
row is selected; also update the third step in the processing-flow explanation
to describe this filtering instead of LIMIT 1.
- Around line 244-247: Update the processing-flow explanation to state that date
BETWEEN 初日 AND 末日 selects every day in the target month and SUM aggregates those
daily cumulative values, rather than describing the result as month-end
cumulative values. Clarify that total_confirmed_cases and total_deaths are
monthly sums of daily cumulative values and do not represent month-end figures.
In `@Bigquery-data-sharing-challenge-lab-guide.html`:
- Around line 1517-1519: Update renderDiagrams to guard document.fonts.ready
with the same document.fonts existence check used by the referenced guide
implementations, then isolate each mermaid.render operation in its own try/catch
so one diagram failure does not stop subsequent diagrams. Display the failure
reason in the affected diagram and ensure renderDiagrams does not produce
unhandled promise rejections.
- Around line 797-804: Update the SQL examples using `Partner Project
ID.demo_dataset.Partner authorized view` to clearly label the project ID and
view name as placeholders and instruct readers to replace them with the actual
names specified by the lab; apply this consistently in the nearby HTML example
and the corresponding Markdown examples.
- Around line 1465-1467: Update the Mermaid and highlight.js CDN references in
the document, including the imports near the top and the script tags around the
visible Mermaid/highlight.js symbols, to safe patched versions that address
their known vulnerabilities. Keep the existing SQL language import and Tabler
Icons version unchanged.
In `@Bigquery-data-sharing-challenge-lab-guide.md`:
- Around line 44-45: Reverse the PV-to-CT arrow in
Bigquery-data-sharing-challenge-lab-guide.md lines 44-45 so it runs from CT to
PV and describes the authorized view reference while retaining the Customer Data
Viewer role context; leave CV-to-LS unchanged. Apply the same PV/CT arrow
reversal in Bigquery-data-sharing-challenge-lab-guide.html lines 1485-1486 so
both diagram definitions match.
- Line 52: Update the chapter references in the two-stage permission explanation
to point to chapters 3 and 5 instead of chapters 4 and 6, matching the
corresponding guidance in Bigquery-data-sharing-challenge-lab-guide.html.
In `@Gcp-service-account-iam-best-practices.html`:
- Around line 96-126: Update the sidebar navigation selectors in the affected
CSS rules to target the .sidebar element itself rather than a descendant nav.
Apply this consistently to the list, list-item, link, hover, and active-link
rules so markers, link layout, and active highlighting work for the actual
sidebar navigation.
- Around line 666-670:
「なりすまし(Impersonation)の管理」の説明で、roles/iam.serviceAccountUserを直接のアクセストークン発行によるなりすましとして扱わないよう修正してください。iam.serviceAccountUserはiam.serviceAccounts.actAsによるサービスアカウントのリソースへのアタッチを許可するロールとして説明し、直接のアクセストークン発行にはroles/iam.serviceAccountTokenCreatorとiam.serviceAccounts.getAccessTokenが必要であることを区別して記載してください。
In `@Gke-managed-prometheus-challenge-lab-guide.html`:
- Around line 1102-1112: Gke-managed-prometheus-challenge-lab-guide.html の
1102-1112、1153-1160、および Gke-managed-prometheus-challenge-lab-guide.md の
194-206、228-236 にある PodMonitoring と target status 手順を、prometheus-engine/v0.2.3
と互換する API・selector・OperatorConfig.features.targetStatus に揃えて修正するか、現行 GMP API
を使う構成として全ての prometheus-engine/v0.2.3 指定と関連手順を対応バージョンへ更新してください。HTML と Markdown
の内容は一致させ、後続の kubectl apply、example-app.yaml、target status
確認が選択したバージョンで実行可能になるようにしてください。
In `@Google-workspace-challenge-lab-guide.html`:
- Around line 865-866: AppSheet Core の説明を、対象が一部の Google Workspace
エディションに限られることが明確になるよう更新してください。あわせて、管理者による AppSheet サービス無効化の可能性を踏まえ、学生アカウントで
AppSheet にログインしてアプリを作成できることを事前に確認する手順を追加してください。
- Around line 7-11: 外部 CDN の tabler-icons.min.css と mermaid.min.js
の読み込みに、検証済みリリースの正しい sha384 整合性ハッシュを integrity 属性として追加し、両方へ
crossorigin="anonymous" を設定してください。
- Around line 1251-1255: mermaid.initialize の securityLevel 設定を 'loose' から
'strict' に変更し、Mermaid の既定の安全な設定に戻してください。
In `@Knowledge-catalog-challenge-lab-best-practices.html`:
- Around line 723-729: Knowledge-catalog-challenge-lab-best-practices.html
の該当リスト項目で、ディスカバリー設定を有効にし、検出可能なデータ構造が存在する場合に限り BigQuery
外部テーブルが自動公開される条件付き表現へ変更する。Knowledge-catalog-challenge-lab-best-practices.md
の該当記述も同じ条件を文頭に追加し、HTML 版と表現をそろえる。
- Around line 1419-1424: Update the mermaid.initialize configuration to set
securityLevel to 'strict' instead of 'loose', leaving the other diagram settings
unchanged.
- Around line 1366-1369: Update the Tabler Icons stylesheet link in the document
head to replace the `@latest` CDN reference with the specific version that was
verified, matching the version-pinning approach used for highlight.js and
mermaid while preserving the existing stylesheet path.
- Around line 388-391: Change the outer `.sidebar` container from a `nav`
element to an `aside`, and update its matching closing tag while preserving the
nested navigation element and existing `.sidebar`/`.sidebar nav a` selectors.
- Around line 1061-1080: Update the `gcloud dataplex entries search` command to
replace `--location=<REGION>` with `--scope=<PROJECT_ID>`, while preserving
`--location=<REGION>` on the `gcloud dataplex entries update-aspects` command.
In `@Knowledge-catalog-challenge-lab-best-practices.md`:
- Around line 1-2: Insert a blank line between the top-level and second-level
headings in the document so each Markdown heading is separated and satisfies
markdownlint MD022.
In `@Ml-api-challenge-lab-guide.html`:
- Around line 525-533: Replace the Vision API “Dense document text detection
tutorial” URL in the ADC/GOOGLE_APPLICATION_CREDENTIALS callout with the
official Google Cloud authentication documentation, and apply the same
correction in Ml-api-challenge-lab-guide.md. Add the authentication
documentation link to the references list near the existing references section
as requested.
- Around line 510-516:
サービスアカウントキー作成手順の直後に、キーの取り扱いに関する注意書きを追加してください。キーファイルをGitリポジトリやバケットへ置かないこと、ラボ終了後にキーを削除すること、実務ではWorkload
Identity連携または接続されたサービスのADCを使用することを明記してください。
- Around line 685-690: Update translate_text to compare the primary language
subtag of source_locale with TARGET_LANGUAGE, so tags such as en-US and zh-Hans
are handled correctly while preserving the existing "und" passthrough behavior.
Apply the same primary-subtag comparison in the corresponding logic in
Ml-api-challenge-lab-guide.md.
In `@Pcne-s4-cdn-dns-ipam.md`:
- Around line 528-537: Update the Mermaid flowchart around Pod, NodeLocal
DNSCache, and the metadata server to show Pods using nameserver 169.254.20.10
and querying NodeLocal DNSCache first. For Cloud DNS for GKE, route only cache
misses from NodeLocal DNSCache to the node metadata server at 169.254.169.254,
then to the Cloud DNS provider; remove the direct Pod-to-metadata-server path
and preserve the kube-dns route as applicable.
- Line 260: 署名検証の説明を、署名検証を有効化したバックエンドではCloud
CDNが無効な署名付きリクエストを403で拒否し、オリジンへ転送しない場合がある内容に更新してください。併せて、未署名リクエストの検証と拒否はオリジン側のWebサーバーが担う必要があることを明記し、Cloud
CDNが署名検証を一切行わないという表現は削除してください。
In `@S3-load-balancing-traffic-management.md`:
- Around line 276-282: Gateway
controllerのHealthCheckPolicyに関する説明を修正し、標準の「/」パスと既定ポリシーが自動作成されるため明示設定は必須ではないと記載してください。追加パス、ヘッダー、タイムアウトなどの既定値を変更する場合にのみHealthCheckPolicyが必要であることを明示し、既存のGatewayClass・Gateway・HTTPRouteの説明は変更しないでください。
In `@S6-network-ops-monitoring.md`:
- Around line 3-9:
見出しとスコープ説明の強調記法が途中で閉じているため、見出しの出題比率を含む範囲と、公式セクション名の引用符までをそれぞれ同じ太字範囲に修正してください。対象は冒頭の見出しと「この記事について(スコープ対応表)」直下の説明文です。
- Line 103: 修正対象の説明文で、Cloud DNS を自動的に Cloud Logging へ書き込む対象から外し、プライベートゾーンは DNS
ポリシー単位、パブリックゾーンは管理対象ゾーン単位で有効化が必要であることを明記してください。あわせて、列挙されているロギング対象コンポーネント数を「8つ」から「9つ」に更新してください。
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 42cbb93d-c314-40c7-90f7-8f25633d9138
📒 Files selected for processing (25)
Bigquery-appsscript-connectedsheets-guide.htmlBigquery-appsscript-connectedsheets-guide.mdBigquery-covid19-challenge-lab-guide.htmlBigquery-covid19-challenge-lab-guide.mdBigquery-data-sharing-challenge-lab-guide.htmlBigquery-data-sharing-challenge-lab-guide.mdCymbal-direct-agent-platform-prompt-design-guide.htmlCymbal-direct-agent-platform-prompt-design-guide.mdGcp-pcne-s5-network-security.htmlGcp-pcne-s5-network-security.mdGcp-service-account-iam-best-practices.htmlGke-managed-prometheus-challenge-lab-guide.htmlGke-managed-prometheus-challenge-lab-guide.mdGoogle-workspace-challenge-lab-guide.htmlGoogle-workspace-challenge-lab-guide.mdKnowledge-catalog-challenge-lab-best-practices.htmlKnowledge-catalog-challenge-lab-best-practices.mdMl-api-challenge-lab-guide.htmlMl-api-challenge-lab-guide.mdPcne-s4-cdn-dns-ipam.htmlPcne-s4-cdn-dns-ipam.mdS3-load-balancing-traffic-management.htmlS3-load-balancing-traffic-management.mdS6-network-ops-monitoring.htmlS6-network-ops-monitoring.md
💤 Files with no reviewable changes (2)
- Cymbal-direct-agent-platform-prompt-design-guide.html
- Cymbal-direct-agent-platform-prompt-design-guide.md
There was a problem hiding this comment.
Actionable comments posted: 5
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Bigquery-covid19-challenge-lab-guide.md`:
- Around line 247-248: Task 4(Bigquery-covid19-challenge-lab-guide.md
247-248)、Task 7(同 369-374)、Task 8(同 422-427)、Task 9(同
492-500)の国レベル集計に、country_name の条件と併せて subregion1_name IS NULL AND
subregion2_name IS NULL を追加してください。Bigquery-covid19-challenge-lab-guide.md
584-584 の Task 1 は採点用の単純合計として扱う場合、その例外をタスク内に明記し、不要な変更は加えないでください。
In `@Gke-managed-prometheus-challenge-lab-guide.html`:
- Around line 1162-1166: After the target status inspection commands in
Gke-managed-prometheus-challenge-lab-guide.html lines 1162-1166 and
Gke-managed-prometheus-challenge-lab-guide.md lines 239-244, add steps to
restore and reapply the original OperatorConfig saved before applying
operator-config-debug.yaml. Ensure both HTML and Markdown document that the
debug targetStatus configuration is temporary and must not remain enabled.
In `@Google-workspace-challenge-lab-guide.html`:
- Around line 855-865: Update the “開始前の利用可否確認” callout so it only instructs
users to sign in to AppSheet with the lab student account and verify that the “+
Create” menu is visible. Remove the instruction to create a blank app and open
App Editor; leave that creation step solely in the subsequent procedure.
In `@Knowledge-catalog-challenge-lab-best-practices.html`:
- Line 1071: Update the --scope argument in the gcloud dataplex entries search
command to use the fully qualified project format projects/<PROJECT_ID> instead
of the bare project placeholder.
In `@Pcne-s4-cdn-dns-ipam.md`:
- Line 260: 署名付きリクエストの説明に、origin 側でも署名付き URL/Cookie を検証することを追記してください。Cloud CDN
が署名情報を origin に渡さない場合や CDN をバイパスできる構成を明記し、Cloud Storage など直接公開可能な origin
では未署名・不正な署名を含むリクエストを origin で検証して HTTP 403 で拒否する旨を示してください。
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: e02ae98f-ddb2-4aad-90e0-aea64fe37165
📒 Files selected for processing (16)
Bigquery-appsscript-connectedsheets-guide.htmlBigquery-appsscript-connectedsheets-guide.mdBigquery-covid19-challenge-lab-guide.mdBigquery-data-sharing-challenge-lab-guide.htmlBigquery-data-sharing-challenge-lab-guide.mdGcp-service-account-iam-best-practices.htmlGke-managed-prometheus-challenge-lab-guide.htmlGke-managed-prometheus-challenge-lab-guide.mdGoogle-workspace-challenge-lab-guide.htmlKnowledge-catalog-challenge-lab-best-practices.htmlKnowledge-catalog-challenge-lab-best-practices.mdMl-api-challenge-lab-guide.htmlMl-api-challenge-lab-guide.mdPcne-s4-cdn-dns-ipam.mdS3-load-balancing-traffic-management.mdS6-network-ops-monitoring.md
…ty guide migration
…e components to pass tests
…e into routing and update docs
…loyment security guide
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 2
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (5)
Gcp-challenge-lab-storage-compute-nginx.md (1)
111-115: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winCLIでもUniform bucket-level accessを明示してください。
Console手順と節の説明ではUniform accessを前提としていますが、
gcloud storage buckets createの--uniform-bucket-level-accessは既定で無効です。CLI経路でもIAM制御のみのバケットを作成するには、--uniform-bucket-level-accessを追加してください。gcloud storage buckets create gs://${PROJECT_ID}-bucket \ --location=US \ - --default-storage-class=STANDARD + --default-storage-class=STANDARD \ + --uniform-bucket-level-access🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcp-challenge-lab-storage-compute-nginx.md` around lines 111 - 115, Update the gcloud storage buckets create command to include the --uniform-bucket-level-access option, ensuring the CLI-created bucket uses uniform bucket-level IAM access consistently with the console procedure.Gcp-challenge-lab-storage-compute-nginx.html (1)
856-862: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winCLIのバケット作成設定に
--uniform-bucket-level-accessを追加してください。
gcloud storage buckets createは既定値では細粒度アクセス制御のままになります。Console手順との整合を保つため、同一の--uniform-bucket-level-accessを追加してください。docs.cloud.google.com🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcp-challenge-lab-storage-compute-nginx.html` around lines 856 - 862, Update the gcloud storage buckets create command in the src-bucket script to include the --uniform-bucket-level-access option, preserving the existing project, location, and storage-class settings.Gcs-json-api-challenge-lab-best-practices.md (1)
173-184: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winオブジェクト名をURLエンコードしてからCloud Storage JSON APIのパスへ渡してください。
copyToと/aclエンドポイントでOBJECT_NAMEを直接埋め込んでいるため、オブジェクト名に/などのURL予約文字が含まれると、オブジェクト名ではなくパスの区切りとして解釈されます。Cloud Storageの公式例では、Object name はURLエンコードして使用してください。
OBJECT_NAME_ENCODEDを作成し、URLパスだけで使用してください。アップロード本文などでは元のOBJECT_NAMEを使用してください。修正例
+OBJECT_NAME_ENCODED="$(jq -rn --arg name "$OBJECT_NAME" '$name | `@uri`')" + curl -X POST \ -H "Authorization: Bearer $(gcloud auth print-access-token)" \ -H "Content-Length: 0" \ - "https://storage.googleapis.com/storage/v1/b/${BUCKET_1}/o/${OBJECT_NAME}/copyTo/b/${BUCKET_2}/o/${OBJECT_NAME}" + "https://storage.googleapis.com/storage/v1/b/${BUCKET_1}/o/${OBJECT_NAME_ENCODED}/copyTo/b/${BUCKET_2}/o/${OBJECT_NAME_ENCODED}"Also applies to: 219-235
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.md` around lines 173 - 184, OBJECT_NAMEをURLパスへ直接埋め込まず、URLエンコードしたOBJECT_NAME_ENCODEDを作成してcopyToおよびaclエンドポイントのパスで使用してください。アップロード本文などURLパス以外では元のOBJECT_NAMEを引き続き使用します。Gcs-json-api-challenge-lab-best-practices.html (2)
1076-1096: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winHTTP エラー時に IAM ポリシー更新を続行しないしてください。
curlの設定はこのコマンドでは HTTP 4xx/5xx を実行を中断しません。GET がエラー本文でも保存し、jqがエラーを渡すこともあれば、PUT に進む場合は現在のbindingsやetagを失う可能性があります。curlGET/PUT を--fail-with-body --silent --show-errorにし、jq後で.bindingsが配列かつ.etagが文字列であることを検知してください。修正例
+set -euo pipefail + -curl -X GET \ +curl --fail-with-body --silent --show-error -X GET \ -H "Authorization: Bearer $(gcloud auth print-access-token)" \ "https://storage.googleapis.com/storage/v1/b/${BUCKET_2}/iam" \ -o iam-policy-current.json + +jq -e 'type == "object" and (.bindings | type == "array") and (.etag | type == "string")' \ + iam-policy-current.json >/dev/null ... -curl -X PUT --data-binary `@iam-policy.json` \ +curl --fail-with-body --silent --show-error -X PUT --data-binary `@iam-policy.json` \🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.html` around lines 1076 - 1096, Update both curl invocations in the IAM policy workflow to use --fail-with-body, --silent, and --show-error so HTTP 4xx/5xx responses stop the update. After jq processes iam-policy-current.json, validate that .bindings is an array and .etag is a string before allowing the PUT to proceed; otherwise terminate without submitting a potentially incomplete policy.
1076-1079: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
optionsRequestedPolicyVersion=3をgetIamPolicyに含めてください。条件付き IAM バインディングがあるバケットでは、
getIamPolicyがoptionsRequestedPolicyVersion=3以上を要求します。このクエリを省略すると条件付きバインディングを持つ対象でポリシー取得ができず、その後setIamPolicyで古いポリシーを上書きする可能性があります。修正例
curl -X GET \ -H "Authorization: Bearer $(gcloud auth print-access-token)" \ - "https://storage.googleapis.com/storage/v1/b/${BUCKET_2}/iam" \ + "https://storage.googleapis.com/storage/v1/b/${BUCKET_2}/iam?optionsRequestedPolicyVersion=3" \ -o iam-policy-current.json🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.html` around lines 1076 - 1079, Update the IAM policy retrieval curl command to include the optionsRequestedPolicyVersion=3 query parameter on the storage API /iam URL, ensuring conditional bindings are returned before the policy is reused by setIamPolicy.
♻️ Duplicate comments (1)
Gcs-json-api-challenge-lab-best-practices.md (1)
252-276: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winIAM更新はGET失敗時に停止してください。
curlは既定ではHTTP 4xx/5xxを失敗終了として扱いません。そのため、GETが失敗してもjqと PUTへ進みます。Cloud StorageのsetIamPolicyは既存ポリシー全体を置換し、etagは任意です。エラー応答から作ったポリシーをPUTすると、既存のbindingsを失う可能性があります。(curl.se)
set -euo pipefail、curl --fail --silent --show-error、bindingsとetagの構造検証を追加してからPUTしてください。修正例
```bash +set -euo pipefail + curl -X GET \ + --fail --silent --show-error \ -H "Authorization: Bearer $(gcloud auth print-access-token)" \ "https://storage.googleapis.com/storage/v1/b/${BUCKET_2}/iam" \ -o iam-policy-current.json +jq -e 'type == "object" and (.bindings | type) == "array" and (.etag | type) == "string"' \ + iam-policy-current.json >/dev/null + -jq ' +jq -e ' ... ' iam-policy-current.json > iam-policy.json -curl -X PUT --data-binary `@iam-policy.json` \ +curl --fail --silent --show-error -X PUT --data-binary `@iam-policy.json` \LGTM!検証スクリプト
#!/usr/bin/env bash set -euo pipefail curl --fail --silent --show-error \ https://docs.cloud.google.com/storage/docs/json_api/v1/buckets/setIamPolicy | rg -n 'replaces any existing IAM policy|etag.*Optional'</review_comment>
</file_review><consolidated_comments>
<consolidated_comment locations="Gcp-challenge-lab-storage-compute-nginx.md#L111-L115,Gcp-challenge-lab-storage-compute-nginx.html#L856-L862">
Cloud Storage CLI手順がUniform bucket-level accessを保証していません。Console手順とCLI手順の設定が一致していません。
gcloud storage buckets createの既定値はUniform bucket-level access無効です。両方のCLI例に明示フラグを追加してください。(docs.cloud.google.com)
Gcp-challenge-lab-storage-compute-nginx.md#L111-L115:--uniform-bucket-level-accessを追加する。Gcp-challenge-lab-storage-compute-nginx.html#L856-L862: Markdown版と同じフラグをsrc-bucketのCLI例へ追加する。</consolidated_comment>
</consolidated_comments>
</review_response>🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.md` around lines 252 - 276, Update both `gcloud storage buckets create` CLI examples to explicitly include `--uniform-bucket-level-access`, including the `src-bucket` example in the HTML version, so the CLI configuration matches the Console setup.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.gemini/skills/md-to-nextjs-migration/SKILL.md:
- Around line 188-190: Replace shell placeholders such as <exam>,
<changed-file-1>, and <refactored-files> in the test, git add, and
assert_staged_scope examples with defined variables like exam, changed_file, and
refactored_files. Quote every resulting path using "${...}" so Bash does not
interpret placeholder brackets as redirection operators, updating all referenced
sections including the flows around the test command and staged-file validation.
In `@package.json`:
- Line 9: Update the docker:rebuild script to remove the dev_next_cache named
volume during teardown, either by adding the Compose volume-removal option to
docker compose down or by explicitly deleting only that volume, so the
development container rebuilds without stale .next contents.
---
Outside diff comments:
In `@Gcp-challenge-lab-storage-compute-nginx.html`:
- Around line 856-862: Update the gcloud storage buckets create command in the
src-bucket script to include the --uniform-bucket-level-access option,
preserving the existing project, location, and storage-class settings.
In `@Gcp-challenge-lab-storage-compute-nginx.md`:
- Around line 111-115: Update the gcloud storage buckets create command to
include the --uniform-bucket-level-access option, ensuring the CLI-created
bucket uses uniform bucket-level IAM access consistently with the console
procedure.
In `@Gcs-json-api-challenge-lab-best-practices.html`:
- Around line 1076-1096: Update both curl invocations in the IAM policy workflow
to use --fail-with-body, --silent, and --show-error so HTTP 4xx/5xx responses
stop the update. After jq processes iam-policy-current.json, validate that
.bindings is an array and .etag is a string before allowing the PUT to proceed;
otherwise terminate without submitting a potentially incomplete policy.
- Around line 1076-1079: Update the IAM policy retrieval curl command to include
the optionsRequestedPolicyVersion=3 query parameter on the storage API /iam URL,
ensuring conditional bindings are returned before the policy is reused by
setIamPolicy.
In `@Gcs-json-api-challenge-lab-best-practices.md`:
- Around line 173-184:
OBJECT_NAMEをURLパスへ直接埋め込まず、URLエンコードしたOBJECT_NAME_ENCODEDを作成してcopyToおよびaclエンドポイントのパスで使用してください。アップロード本文などURLパス以外では元のOBJECT_NAMEを引き続き使用します。
---
Duplicate comments:
In `@Gcs-json-api-challenge-lab-best-practices.md`:
- Around line 252-276: Update both `gcloud storage buckets create` CLI examples
to explicitly include `--uniform-bucket-level-access`, including the
`src-bucket` example in the HTML version, so the CLI configuration matches the
Console setup.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: e4845fa8-f9ce-44b7-86f6-657f6909dd17
📒 Files selected for processing (13)
.agents/rules/css-cache-reset.md.agents/skills/md-to-nextjs-migration/SKILL.md.gemini/rules/css-cache-reset.md.gemini/skills/md-to-nextjs-migration/SKILL.mdCLAUDE.mdGEMINI.mdGcp-challenge-lab-storage-compute-nginx.htmlGcp-challenge-lab-storage-compute-nginx.mdGcs-json-api-challenge-lab-best-practices.htmlGcs-json-api-challenge-lab-best-practices.mdREADME.mdpackage.jsontask.md
There was a problem hiding this comment.
Actionable comments posted: 2
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (8)
.agents/skills/md-to-nextjs-migration/SKILL.md (1)
146-182: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winステージ検査で許可ファイルの実際の差分のみを取り込むようにしてください。
assert_staged_scope()はgit diff --cached --name-onlyの結果を全ファイル名で許可リストと比較していますが、例えばgit add MIGRATION_PROGRESS.md CLAUDE.md GEMINI.mdは許可リスト外を変更しても通過し、未指定の同一ファイル内変更もステージに混入できます。各git addの後に、許可ファイル以外をgit diff --cached --name-onlyで拒否し、許可ファイルについてはステージング対象に含めた差分のみが反映されることを指示してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.agents/skills/md-to-nextjs-migration/SKILL.md around lines 146 - 182, ステージ検査の手順を更新し、assert_staged_scope() で許可ファイル外のステージを拒否するだけでなく、各 git add では許可された対象差分のみを明示的に指定して取り込むよう指示してください。許可ファイル内の未指定変更が混入しないよう、git add -p などで差分単位に選択し、git diff --cached --name-only によるファイル範囲検証も維持してください。Source: Learnings
Gcp-challenge-lab-storage-compute-nginx.md (2)
164-180: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winCLI の Allow HTTP traffic 設定にファイアウォールルールも含めてください。
--tags=http-serverはdefault-allow-http規則の対象にするタグだけなので、ラボネットワークにdefault-allow-httpがない環境では外部 HTTP アクセスがブロックされます。gcloud compute instances createの直後に、対象タグ・ポート・ネットワークを指定したファイアウォール規則の作成または既存規則の確認を追加してください。Markdown とHTML の両方で同一の依存関係を反映してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcp-challenge-lab-storage-compute-nginx.md` around lines 164 - 180, CLI の HTTP 設定を、タグ付与だけでなくファイアウォール規則まで含むよう更新してください。Gcp-challenge-lab-storage-compute-nginx.md の 164-180 行では、gcloud compute instances create の直後に、対象ネットワーク・http-server タグ・TCP ポート 80 を指定した規則の作成または既存の default-allow-http 規則確認を追加し、Gcp-challenge-lab-storage-compute-nginx.html の 986-999 行にも同じ依存関係を反映してください。
259-274: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winSSH 接続手順と VM 内操作を別ブロックとしてください。
gcloud compute ssh my-instance --zone="$ZONE"は対話型 SSH 接続で終わり、以降のsudo apt-get update/nginxインストール /curlは同じコードブロックに続いています。HTML のコピー対象id="code-nginx"も同じ内容をコピーするため、実行先が手順から保証されません。VM 内処理はgcloud compute ssh my-instance --zone="$ZONE" --command="..."で送受信するか、SSH 接続手順と VM 内実行手順を別ブロックに分割してください。Markdown と HTML の Copy 対象のこの 2 か所で対応が必要です。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcp-challenge-lab-storage-compute-nginx.md` around lines 259 - 274, Gcp-challenge-lab-storage-compute-nginx.md の259-274行と Gcp-challenge-lab-storage-compute-nginx.html の1130-1140行で、対話型の gcloud compute ssh 接続と VM 内操作を別のコピー対象ブロックに分離してください。Markdown のコードブロックと HTML の id="code-nginx" の両方で、apt-get、NGINX 操作、curl が VM 内で実行されることを保証してください。Gcs-json-api-challenge-lab-best-practices.md (1)
146-155: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winエンコード済みのオブジェクト名をアップロード URL に使用してください。
OBJECT_NAME_ENCODEDを作成していますが、Line 155 では raw のOBJECT_NAMEが使われています。Cloud Storage JSON API はnameパラメータで URL エンコードされたオブジェクト名を使用します。/、空白、&などが含まれるオブジェクト名ではリクエストの解釈が変わる可能性があります。ローカルファイル引数も引用してください。修正例
-curl -X POST --data-binary @${OBJECT_NAME} \ +curl -X POST --data-binary @"${OBJECT_NAME}" \ -H "Authorization: Bearer $(gcloud auth print-access-token)" \ -H "Content-Type: image/png" \ - "https://storage.googleapis.com/upload/storage/v1/b/${BUCKET_1}/o?uploadType=media&name=${OBJECT_NAME}" + "https://storage.googleapis.com/upload/storage/v1/b/${BUCKET_1}/o?uploadType=media&name=${OBJECT_NAME_ENCODED}"🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.md` around lines 146 - 155, Update the upload curl command to use OBJECT_NAME_ENCODED for the URL name parameter, while retaining OBJECT_NAME for the local file input. Quote the local file argument so object names containing spaces or shell-special characters are handled safely.Gcs-json-api-challenge-lab-best-practices.html (4)
1784-1787: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win
DIAGRAMSの固定入力制約を明示してください。Mermaidの
renderDiagrams()はDIAGRAMSをmermaid.render()に渡し、DOMにinnerHTMLで挿入しています。DIAGRAMSがリポジトリ内固定の図定義だけなら、その不変条件をコードコメントやテストで固定してください。外部入力があり得る場合はsecurityLevelをstrict/sandboxに変更するか、DOM挿入前に適切にサニタイズしてください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.html` around lines 1784 - 1787, renderDiagrams() に渡される DIAGRAMS がリポジトリ内で定義された固定の図データのみである不変条件を、近接するコードコメントまたはテストで明示的に固定してください。外部入力が入り得る場合は、window.mermaid.initialize の securityLevel を strict または sandbox に変更するか、innerHTML 挿入前に適切なサニタイズを追加してください。Sources: Coding guidelines, Linters/SAST tools
1084-1093: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winバケット全体の公開を個別オブジェクトの公開として扱わないでください。
この手順は
BUCKET_2のバケット IAM にroles/storage.objectViewerのallUsersを追加しています。このロールにはstorage.objects.listも含まれるため、OBJECT_NAME限定ではありえず、バケット内の全オブジェクト一覧と閲覧が公開されます。個別公開が要件なら、signed URL、専用公開バケット、storage.objects.getとresource.name条件の組み合わせを使うなど、一覧権限を排除してください。バケット全体を公開する手順なら、見出しと警告をその範囲に修正してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.html` around lines 1084 - 1093, Revise the IAM update around the jq policy transformation so it does not grant bucket-wide roles/storage.objectViewer with allUsers when the requirement is OBJECT_NAME-only access. Use an approach that excludes storage.objects.list, such as a resource.name-conditioned get permission, signed URL, or dedicated public bucket; alternatively, explicitly update the section heading and warning to describe full-bucket public listing and access.
1062-1067: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win組織ポリシーの有無だけでACL/IAMを分岐しないでください。
constraints/storage.uniformBucketLevelAccessは既存の Fine-grained バケットへ遡及してenabledを変更しません。組織ポリシーが設定されていることを理由に IAM 方式へ進める説明は不正確です。iamConfiguration.uniformBucketLevelAccess.enabledの実値で方式を選択し、組織ポリシーは新規作成または無効化時の制約として別に説明してください。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.html` around lines 1062 - 1067, Update the Task4 guidance to select ACL or IAM solely from the target bucket’s actual iamConfiguration.uniformBucketLevelAccess.enabled value: use ACL when false or unset and IAM when true. Remove the statement that an organization policy alone triggers IAM, and describe constraints/storage.uniformBucketLevelAccess separately as a restriction on new bucket creation or disabling uniform access.
1242-1244: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick winSoft Deleteが
0は管理者確認または条件付き手順としてください。
softDeletePolicy.retentionDurationSecondsを"0"に設定することは、組織ポリシーconstraints/storage.softDeletePolicySecondsによって許可されない場合、バケット作成または更新が失敗します。0を事前確認できない場合は、「管理者に許可値を確認してから設定してください」という手順にしてください。(docs.cloud.google.com/storage/docs/org-policy-constraints)🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Gcs-json-api-challenge-lab-best-practices.html` around lines 1242 - 1244, バケット作成手順のsoftDeletePolicy.retentionDurationSecondsを常に"0"に設定する記述を、組織ポリシーconstraints/storage.softDeletePolicySecondsで許可されている場合に限る条件付き手順へ更新してください。許可値を事前確認できない場合は、管理者に確認してから設定するよう案内し、設定不可時に作成・更新が失敗することも明記してください。
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.agents/skills/md-to-nextjs-migration/SKILL.md:
- Around line 196-198: Red
判定のエラー文字列検索を、追加したテストだけを対象にするテスト名フィルタ付き実行へ変更してください。対象テスト固有の期待失敗メッセージを検証し、AssertionError
などの一般的なエラー名だけで成功判定しないようにしてください。失敗確認後にのみ test: コミットへ進み、Green
実装とは別コミットになる既存フローを維持してください。
In `@Gcp-challenge-lab-storage-compute-nginx.md`:
- Around line 201-213: Gcp-challenge-lab-storage-compute-nginx.md
のディスク作成(201-213)、SSH(259-274)、ディスク describe(311-320)の各コピー可能ブロック先頭に export
ZONE="YOUR_ZONE" を追加してください。同じ変更を Gcp-challenge-lab-storage-compute-nginx.html
の対応ブロック(1016-1026、1130-1140、1312-1315)にも反映し、各スニペットを単独実行できるようにしてください。
---
Outside diff comments:
In @.agents/skills/md-to-nextjs-migration/SKILL.md:
- Around line 146-182: ステージ検査の手順を更新し、assert_staged_scope()
で許可ファイル外のステージを拒否するだけでなく、各 git add
では許可された対象差分のみを明示的に指定して取り込むよう指示してください。許可ファイル内の未指定変更が混入しないよう、git add -p
などで差分単位に選択し、git diff --cached --name-only によるファイル範囲検証も維持してください。
In `@Gcp-challenge-lab-storage-compute-nginx.md`:
- Around line 164-180: CLI の HTTP
設定を、タグ付与だけでなくファイアウォール規則まで含むよう更新してください。Gcp-challenge-lab-storage-compute-nginx.md
の 164-180 行では、gcloud compute instances create の直後に、対象ネットワーク・http-server タグ・TCP
ポート 80 を指定した規則の作成または既存の default-allow-http
規則確認を追加し、Gcp-challenge-lab-storage-compute-nginx.html の 986-999
行にも同じ依存関係を反映してください。
- Around line 259-274: Gcp-challenge-lab-storage-compute-nginx.md の259-274行と
Gcp-challenge-lab-storage-compute-nginx.html の1130-1140行で、対話型の gcloud compute
ssh 接続と VM 内操作を別のコピー対象ブロックに分離してください。Markdown のコードブロックと HTML の id="code-nginx"
の両方で、apt-get、NGINX 操作、curl が VM 内で実行されることを保証してください。
In `@Gcs-json-api-challenge-lab-best-practices.html`:
- Around line 1784-1787: renderDiagrams() に渡される DIAGRAMS
がリポジトリ内で定義された固定の図データのみである不変条件を、近接するコードコメントまたはテストで明示的に固定してください。外部入力が入り得る場合は、window.mermaid.initialize
の securityLevel を strict または sandbox に変更するか、innerHTML 挿入前に適切なサニタイズを追加してください。
- Around line 1084-1093: Revise the IAM update around the jq policy
transformation so it does not grant bucket-wide roles/storage.objectViewer with
allUsers when the requirement is OBJECT_NAME-only access. Use an approach that
excludes storage.objects.list, such as a resource.name-conditioned get
permission, signed URL, or dedicated public bucket; alternatively, explicitly
update the section heading and warning to describe full-bucket public listing
and access.
- Around line 1062-1067: Update the Task4 guidance to select ACL or IAM solely
from the target bucket’s actual
iamConfiguration.uniformBucketLevelAccess.enabled value: use ACL when false or
unset and IAM when true. Remove the statement that an organization policy alone
triggers IAM, and describe constraints/storage.uniformBucketLevelAccess
separately as a restriction on new bucket creation or disabling uniform access.
- Around line 1242-1244:
バケット作成手順のsoftDeletePolicy.retentionDurationSecondsを常に"0"に設定する記述を、組織ポリシーconstraints/storage.softDeletePolicySecondsで許可されている場合に限る条件付き手順へ更新してください。許可値を事前確認できない場合は、管理者に確認してから設定するよう案内し、設定不可時に作成・更新が失敗することも明記してください。
In `@Gcs-json-api-challenge-lab-best-practices.md`:
- Around line 146-155: Update the upload curl command to use OBJECT_NAME_ENCODED
for the URL name parameter, while retaining OBJECT_NAME for the local file
input. Quote the local file argument so object names containing spaces or
shell-special characters are handled safely.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: e58bc9f0-5fd9-4ba2-a6f9-5f314a958b00
📒 Files selected for processing (13)
.agents/rules/css-cache-reset.md.agents/skills/md-to-nextjs-migration/SKILL.md.gemini/rules/css-cache-reset.md.gemini/skills/md-to-nextjs-migration/SKILL.mdCLAUDE.mdGEMINI.mdGcp-challenge-lab-storage-compute-nginx.htmlGcp-challenge-lab-storage-compute-nginx.mdGcs-json-api-challenge-lab-best-practices.htmlGcs-json-api-challenge-lab-best-practices.mdREADME.mdpackage.jsontask.md
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.agents/skills/md-to-nextjs-migration/SKILL.md:
- Around line 162-163: ステージング手順の説明に、新規ファイルを扱う手順を追加してください。対象ファイルごとに git status
--short と assert_clean_stage の後、git add -N -- <new-file> を実行してから git add -p --
<new-file> で必要な差分だけを選択する流れを明記し、既存の許可ファイル限定および部分ステージングの要件を維持してください。
In `@Gcp-challenge-lab-storage-compute-nginx.md`:
- Around line 181-191: Replace the name-only existence check around the firewall
rule creation logic with validation of network, direction, sourceRanges,
allowed, targetTags, and disabled; update the rule or exit with an error when
any value differs. Apply the same validation behavior at
Gcp-challenge-lab-storage-compute-nginx.md lines 181-191 and
Gcp-challenge-lab-storage-compute-nginx.html lines 997-1007, keeping both
representations synchronized.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 4c35d138-1bdb-4455-b139-a7efa0aed67f
📒 Files selected for processing (6)
.agents/skills/md-to-nextjs-migration/SKILL.mdGcp-challenge-lab-storage-compute-nginx.htmlGcp-challenge-lab-storage-compute-nginx.mdGcs-json-api-challenge-lab-best-practices.htmlGcs-json-api-challenge-lab-best-practices.md__tests__/cisco/ccna/automation-cisco-platforms-and-development/page.test.tsx
|
@coderabbitai review |
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.agents/skills/md-to-nextjs-migration/SKILL.md:
- Around line 186-191: 新規ファイルの選択的ステージング処理で、対象ファイルの実質的な差分がない状態を成功扱いしないようにする。`git
add -p -- <new-file>` と `assert_staged_scope <new-file>` の間、またはコミット前に、`git diff
--cached --name-only -- <new-file>` などで対象ファイルがステージ済みであることを検証し、intent-to-add
だけの場合は失敗させる。
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: e21fa5bb-1135-4dc4-8139-29540b41d6bf
📒 Files selected for processing (3)
.agents/skills/md-to-nextjs-migration/SKILL.mdGcp-challenge-lab-storage-compute-nginx.htmlGcp-challenge-lab-storage-compute-nginx.md
| # 新規ファイルごとに状態を確認し、intent-to-add の後で必要な差分だけを選択する | ||
| git status --short -- <new-file> | ||
| assert_clean_stage || exit 1 | ||
| git add -N -- <new-file> || exit 1 | ||
| git add -p -- <new-file> || exit 1 | ||
| assert_staged_scope <new-file> || exit 1 |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
対象ファイルが空のステージでも成功扱いになります。
Line [190] の git add -p ですべての hunk を選択しない場合、git add -N の intent-to-add だけが残ります。assert_staged_scope <new-file> は許可外ファイルの有無だけを確認するため、対象ファイルが未ステージでも成功します。
git commit の前に、git diff --cached --name-only -- <new-file> などで対象ファイルの差分が存在することを検証してください。
修正例
git add -p -- <new-file> || exit 1
assert_staged_scope <new-file> || exit 1
+if ! git diff --cached --name-only -- <new-file> | grep -Fqx -- '<new-file>'; then
+ echo "対象ファイルの差分がステージされていません" >&2
+ exit 1
+fi📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| # 新規ファイルごとに状態を確認し、intent-to-add の後で必要な差分だけを選択する | |
| git status --short -- <new-file> | |
| assert_clean_stage || exit 1 | |
| git add -N -- <new-file> || exit 1 | |
| git add -p -- <new-file> || exit 1 | |
| assert_staged_scope <new-file> || exit 1 | |
| # 新規ファイルごとに状態を確認し、intent-to-add の後で必要な差分だけを選択する | |
| git status --short -- <new-file> | |
| assert_clean_stage || exit 1 | |
| git add -N -- <new-file> || exit 1 | |
| git add -p -- <new-file> || exit 1 | |
| assert_staged_scope <new-file> || exit 1 | |
| if ! git diff --cached --name-only -- <new-file> | grep -Fqx -- '<new-file>'; then | |
| echo "対象ファイルの差分がステージされていません" >&2 | |
| exit 1 | |
| fi |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.agents/skills/md-to-nextjs-migration/SKILL.md around lines 186 - 191,
新規ファイルの選択的ステージング処理で、対象ファイルの実質的な差分がない状態を成功扱いしないようにする。`git add -p -- <new-file>` と
`assert_staged_scope <new-file>` の間、またはコミット前に、`git diff --cached --name-only --
<new-file>` などで対象ファイルがステージ済みであることを検証し、intent-to-add だけの場合は失敗させる。
「学習コンテンツ(GCP/Cisco)の追加・移行」、「ダイアグラム描画(Mermaid)の高品質化」、「全幅サイドバーデザインシステムの標準化と自動テスト強化」の3軸を中心に実施されています。
1. Cisco CCNA ガイドの移植とレイアウト最適化
Cisco Platforms and Development完全解説ガイドApplication Deployment and Security完全ガイドarchive/Cisco/html/およびarchive/Cisco/md/へ正しく移転・整理。2. GCP / AGWA / PCNE ハンズオン・対策コンテンツの拡充
3. Mermaid ダイアグラム描画・パーサー・コントラストの強化
#ffe08a等)で文字が見えにくくなる問題を解決するため、黒文字 (#000000) 転換ルールを追加・適用。natural scale)、レスポンシブな枠外はみ出し防止、左切れ防止 (justify-content: safe center) の最適化。fix-mermaidスキル、JavaScript ソースパーサー / レキサーの堅牢化とリグレッションテストの追加。4. 全幅サイドバーデザインシステムの標準化と自動テスト
280px固定+メイン領域全領域使用(calc(100% - 280px))の全幅仕様を標準化。__tests__/guide-content-widths.test.ts等) を導入。5. AI エージェントルール・CI/CD・依存関係の調整
.claude内のルール・スキルを.agentsディレクトリへ統合・集約し、TDD / デザイン移行 / アーカイブ保存規約を強化。tsconfig.jsonのターゲットをES2024へアップデート。markdownlintのプロジェクト内ピン留め、Docker リビルドプロセスの堅牢化。