All skills
google avatar

/google-agents-cli-deploy

@2c39459
by googlegoogle/agents-cli6k stars
686

This skill should be used when the user wants to "deploy an agent", "deploy my ADK agent", "set up CI/CD", "configure secrets", "troubleshoot a deployment", or needs guidance on Agent Runtime, Cloud Run, or GKE deployment targets, or binding an agent to an Agent Gateway. Covers deployment workflows, service accounts, rollback, and production infrastructure. Applies to any framework agents-cli deploys (ADK, LangChain, ...). Part of the agents-cli skills suite. Do NOT use for agent API code patterns (ADK: use google-agents-cli-adk-code), evaluation (use google-agents-cli-eval), or project scaffolding (use google-agents-cli-scaffold).

Use this Skill: https://skilld.dev/gh/google/agents-cli/google-agents-cli-deploy

This session only. Nothing lands on disk.

referencescicd-pipeline.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Production Deployment — CI/CD Pipeline

Best for: Production applications, teams requiring staging → production promotion.

Prerequisites:

  1. Project must NOT be in a gitignored folder
  2. User must provide staging and production GCP project IDs
  3. GitHub repository name and owner

Steps:

  1. If prototype, first add Terraform/CI-CD files using the Agents CLI (see /google-agents-cli-scaffold for full options):

    agents-cli scaffold enhance . --cicd-runner github_actions
  2. Ensure you're logged in to GitHub CLI:

    gh auth login  # (skip if already authenticated)
  3. Run infra cicd:

    agents-cli infra cicd \
      --staging-project YOUR_STAGING_PROJECT \
      --prod-project YOUR_PROD_PROJECT \
      --repository-name YOUR_REPO_NAME \
      --create
  4. Push code to trigger deployments

Key infra cicd Flags

Flag Required Description
--staging-project Yes GCP project ID for staging environment
--prod-project Yes GCP project ID for production environment
--repository-name Yes GitHub repository name
--create No Create a new GitHub repository. Omit to use an existing one (the command verifies the repository exists either way)
--repository-owner No GitHub repo owner. Defaults to your gh CLI user — set this when creating under (or pointing to) a GitHub organization or another user's account
--cicd-project No Separate GCP project for CI/CD infrastructure. Defaults to prod project
--region No GCP region. Auto-detected or defaults to us-east1
--local-state No Store Terraform state locally instead of in GCS (see references/terraform-patterns.md)

Run agents-cli infra cicd --help for the full flag reference (Cloud Build options, dev project, region, etc.).

Choosing a CI/CD Runner

Runner Pros Cons
github_actions (Default) No PAT needed, uses gh auth, WIF-based, fully automated Requires GitHub CLI authentication
google_cloud_build Native GCP integration Requires --github-pat and --github-app-installation-id in programmatic mode (or -i for interactive OAuth flow)

Cloud Build Example

agents-cli infra cicd \
  --staging-project YOUR_STAGING_PROJECT \
  --prod-project YOUR_PROD_PROJECT \
  --repository-name YOUR_REPO_NAME \
  --create \
  --github-pat YOUR_PAT \
  --github-app-installation-id YOUR_APP_ID

How Authentication Works (WIF)

Both runners use Workload Identity Federation (WIF) — GitHub/Cloud Build OIDC tokens are trusted by a GCP Workload Identity Pool, which grants cicd_runner_sa impersonation. No long-lived service account keys needed. Terraform in infra cicd creates the pool, provider, and SA bindings automatically. If auth fails, re-run terraform apply in the CI/CD Terraform directory.

CI/CD Pipeline Stages

The pipeline has three stages:

  1. CI (PR checks) — Triggered on pull request. Runs unit and integration tests.
  2. Staging CD — Triggered on merge to main. Builds container, deploys to staging, runs load tests.

    Path filter: Staging CD only triggers when relevant paths change. The filter differs by language:

    • Python: the agent directory (app/** by default), tests/**, deployment/**, uv.lock.
    • Go: the agent directory, e2e/**, deployment/**, go.mod, go.sum, main.go, Dockerfile. The first push after infra cicd won't trigger staging CD unless one of these changes. If nothing happens after pushing, this is why.
  3. Production CD — Triggered after successful staging deploy via workflow_run. Might require manual approval before deploying to production.

    Approving: Go to GitHub Actions → the production workflow run → click "Review deployments" → approve the pending production environment. This is GitHub's environment protection rules, not a custom mechanism.

IMPORTANT: infra cicd creates infrastructure but doesn't deploy automatically. Terraform configures all required GitHub secrets and variables (WIF credentials, project IDs, service accounts). Push code to trigger the pipeline:

git add . && git commit -m "Initial agent implementation"
git push origin main

To approve production deployment:

# GitHub Actions: Approve via repository Actions tab (environment protection rules)

# Cloud Build: Find pending build and approve
gcloud builds list --project=PROD_PROJECT --region=REGION --filter="status=PENDING"
gcloud builds approve BUILD_ID --project=PROD_PROJECT

Non-GitHub Providers (GitLab, Bitbucket, etc.)

The agents-cli infra cicd command only supports GitHub. It requires the gh CLI, uses the Terraform github provider, and both CI/CD runners (GitHub Actions, Cloud Build) assume a GitHub source repo.

For other git providers, use the scaffolded Terraform as a starting point:

  1. Run agents-cli scaffold enhance to generate the Terraform and CI/CD files
  2. Replace the github provider and resources in deployment/terraform/cicd/ with your provider's equivalents
  3. Adapt the CI/CD pipeline files (e.g., replace .github/workflows/ with .gitlab-ci.yml)
  4. Run terraform apply directly instead of agents-cli infra cicd

Source: SKILL.md on GitHub

No alertstoday3 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    This skill provides guidance and automation for deploying AI agents to Google Cloud platforms like Agent Runtime, Cloud Run, and GKE. It utilizes the `agents-cli` tool for managing infrastructure via Terraform and handles sensitive information using Google Cloud Secret Manager. While the skill facilitates the creation of event-driven trigger endpoints which represent a potential data ingestion surface, these are implemented following standard architectural patterns for agent deployment.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

Signed by skilld at 2c39459. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 days ago
Other metadata
metadata
{
  "author": "Google",
  "license": "Apache-2.0",
  "version": "1.8.0",
  "requires": {
    "bins": [
      "agents-cli"
    ],
    "install": "uv tool install google-agents-cli"
  }
}

README badge

README badge for google/agents-cli/google-agents-cli-deploy