All skills
davila7 avatar

/google-cloud-networking-observability

@82b0fb3

Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Use when investigating VPC Flow Logs, NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics.

Use this Skill: https://skilld.dev/gh/davila7/claude-code-templates/google-cloud-networking-observability

This session only. Nothing lands on disk.

referencescloud-nat-analysis.md

≈692 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cloud NAT Analysis Reference

Use Cloud NAT logs (compute.googleapis.com/nat_flows) to audit traffic going through NAT gateways or troubleshoot port exhaustion.

🤖 Agent / Gemini CLI Instructions (MCP)

You should use Cloud Logging MCP for exploratory analysis or BigQuery MCP for high-volume trends. Fallback to the CLI if the MCP tools are not available.

1. View Logs (Cloud Logging MCP)

Tool: list_log_entries

Filter:

resource.type="nat_gateway"
logName="projects/{project_id}/logs/compute.googleapis.com%2Fnat_flows"

Filter for dropped packets (potential port exhaustion):

jsonPayload.allocation_status="DROPPED"

2. Aggregate Trends (BigQuery MCP)

Tool: execute_sql_readonly

SQL Pattern:

SELECT
JSON_VALUE(json_payload.gateway_details.internal_ip) AS internal_ip, COUNT(*) AS
drop_count FROM `{project_id}.{dataset_id}._AllLogs` WHERE log_name LIKE
'%nat_flows%' AND JSON_VALUE(json_payload.allocation_status) = 'DROPPED' GROUP BY
1 ORDER BY drop_count DESC LIMIT 10

3. CLI Fallback

If MCP tools are unavailable, use the following gcloud and bq commands:

View Logs (gcloud)

gcloud logging read 'resource.type="nat_gateway" AND logName="projects/{project_id}/logs/compute.googleapis.com%2Fnat_flows"' --project {project_id} --limit 10 --format json --quiet

To filter for dropped packets:

gcloud logging read 'resource.type="nat_gateway" AND logName="projects/{project_id}/logs/compute.googleapis.com%2Fnat_flows" AND jsonPayload.allocation_status="DROPPED"' --project {project_id} --limit 10 --format json --quiet

Aggregate Trends (bq)

bq query --use_legacy_sql=false --project_id {project_id} '
SELECT
  JSON_VALUE(json_payload.gateway_details.internal_ip) AS internal_ip,
  COUNT(*) AS drop_count
FROM `{project_id}.{dataset_id}._AllLogs`
WHERE
  log_name LIKE "%nat_flows%"
  AND JSON_VALUE(json_payload.allocation_status) = "DROPPED"
GROUP BY 1
ORDER BY drop_count DESC
LIMIT 10
'

gcloud

To get the status of the router used by the NAT gateway:

gcloud compute
routers get-status {router_name} --region {region} --quiet

Key Fields

  • jsonPayload.gateway_details.external_ip / external_port: NAT exit point.
  • jsonPayload.gateway_details.internal_ip / internal_port: Source VM.
  • jsonPayload.allocation_status: DROPPED indicates failure to allocate a NAT port.

Scenarios

  • Audit Traffic: Link internal sources to external destinations.
  • Port Exhaustion: Use jsonPayload.allocation_status="DROPPED" to identify impacted VMs.

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill is a diagnostic tool designed for Google Cloud networking observability. It provides structured procedures for querying logs, metrics, and connectivity diagnostics using official Google Cloud tools (gcloud, bq, and MCP servers). It follows security best practices by explicitly forbidding the creation of local scripts and requiring the cleanup of diagnostic resources.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 82b0fb3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 19 hours ago.

Activeupdated 5 months ago
source
google/skills (Apache 2.0)

README badge

README badge for davila7/claude-code-templates/google-cloud-networking-observability