All skills
google avatar

/google-cloud-global-frontend-configuration

@becc4b8
by googlegoogle/skills21k stars
1,698

Guides agents through a 6-step discovery process to design and deploy Google Cloud global external Application Load Balancers with Cloud CDN, Cloud Armor, and Service Extensions, mapping workload requirements to best-practice configurations. Use when: - Designing, configuring, or deploying a Google Cloud global external Application Load Balancer, Cloud CDN, Cloud Armor WAF, or Service Extensions. - Discovering existing Google Cloud resources (Cloud Storage, MIGs, GKE, Cloud Run) to use as backends. - Generating production-grade Terraform HCL or gcloud CLI scripts for global external Application Load Balancers. - Actuating deployments via Infrastructure Manager or bash scripts, including IAM pre-checks. - Detecting, analyzing, or reconciling configuration drift on deployed global external Application Load Balancers. Don't use for: - Non-Google Cloud load balancing or security configurations. - Purely regional or internal load balancing setups (unless part of a hybrid/failover global design).

Use this Skill: https://skilld.dev/gh/google/skills/google-cloud-global-frontend-configuration

This session only. Nothing lands on disk.

referencesdrift-detection.md

≈756 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Google Cloud global external Application Load Balancer Drift Detection Guidelines

This reference document details how to detect, analyze, and reconcile configuration drift in Google Cloud global external Application Load Balancer infrastructure using Infrastructure Manager previews.


Core Directives - Behavioral Rules

  1. Safety First: Never modify production infrastructure directly during drift detection. Always generate a preview first to safely inspect differences.
  2. Reconciliation Options: When drift is detected, always present the user with a clear, two-choice decision path:
    • Option A (Reconcile to Code): Overwrite manual changes by re-applying the Terraform configuration.
    • Option B (Backport to Code): Update the Terraform HCL code to match the manual changes made in the Google Cloud console.

The Drift Detection Flow

Step 1: Generate Infrastructure Preview

Create a preview using Infrastructure Manager to compare the deployed infrastructure against the local Terraform code.

  • Run the preview command, passing the existing deployment name and the path to the local Terraform directory:
    gcloud infra-manager previews create {preview_name} \
        --location={region} \
        --local-source={path_to_tf_dir} \
        --service-account={service_account_email} \
        --deployment="projects/{project_id}/locations/{region}/deployments/{deployment_name}"
  • Wait for the preview creation to complete successfully.

Step 2: List Detected Drifts

Query the generated preview to identify specific resources that have drifted.

  • Run the command to list resource drifts:
    gcloud infra-manager resource-drifts list \
        --preview="projects/{project_id}/locations/{region}/previews/{preview_name}"
  • Present the output list of drifted resources to the user in a clean, readable table format, detailing:
    • Resource Name & Type
    • Action (e.g., UPDATE, DELETE)
    • Drift Status (e.g., DRIFTED)

Step 3: Present Reconciliation Paths

Analyze the list from Step 2 and present the two reconciliation options:

  • Option A: Overwrite and Re-align to Code
    • Explain that this will revert all manual Google Cloud console changes and re-apply the local Terraform state.
    • Provide the command to re-apply the deployment (referencing references/managed-deployment.md):
      gcloud infra-manager deployments apply projects/{project_id}/locations/{region}/deployments/{deployment_name} \
          --local-source={path_to_tf_dir} \
          --service-account={service_account_email} \
          --import-existing-resources
  • Option B: Backport Console Changes to Code
    • Explain that this will update their local Terraform files to reflect the manual changes made in the Google Cloud console, preserving them.
    • Detail the exact HCL changes they need to make to their main.tf based on the drift output.

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill facilitates the design and deployment of Google Cloud infrastructure by guiding the configuration of Application Load Balancers. It includes considerations such as automated resource discovery and deployment script generation, which are standard practices for cloud infrastructure management. See the detailed analysis for context on these operations.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "Networking"
}

README badge

README badge for google/skills/google-cloud-global-frontend-configuration