All skills
google avatar

/google-cloud-networking-observability

@b6a171a
by googlegoogle/skills21k stars
1,698

Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics. Use when investigating dropped network traffic, packet drops, drop reasons, VPC Flow Logs (including Private Service Connect / PSC, serverless / App Engine Direct VPC, and cost estimation), NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics. Don't use for generic VM management or non-observability tasks.

Use this Skill: https://skilld.dev/gh/google/skills/google-cloud-networking-observability

This session only. Nothing lands on disk.

referencesmetrics-analysis.md

≈770 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Networking Metrics Reference

Common Troubleshooting Metrics

  • RTT (Latency): networking.googleapis.com/cloud_netslo/active_probing/rtt
  • Packet Loss: networking.googleapis.com/cloud_netslo/active_probing/probe_count
  • VM Throughput: compute.googleapis.com/instance/network/received_bytes_count
  • VM Sent Packets: compute.googleapis.com/instance/network/sent_packets_count
  • VM Received Packets: compute.googleapis.com/instance/network/received_packets_count
  • NAT Port Exhaustion: compute.googleapis.com/nat/dropped_sent_packets_count
  • NAT Sent Packets: compute.googleapis.com/nat/sent_packets_count
  • VPN Dropped Received Packets: vpn.googleapis.com/network/dropped_received_packets_count
  • VPN Dropped Sent Packets: vpn.googleapis.com/network/dropped_sent_packets_count
  • Internal Latency (RTT): networking.googleapis.com/vm_flow/rtt. Measures internal VM-to-VM traffic within Google Cloud.
  • External Latency (RTT): networking.googleapis.com/vm_flow/external_rtt. Measures traffic to and from the internet.

Distribution Parsing Standard

When querying metrics of type DISTRIBUTION (like RTT), align the data with ALIGN_PERCENTILE_50 to ensure the output can be parsed as a simple numeric value.

Dynamic Discovery

  • Primary (Cloud Monitoring MCP): Use list_metric_descriptors with a filter.

    • Prefix: Filter by prefix, using starts_with(). Common prefixes:
      • metric.type = starts_with("networking.googleapis.com/")
      • metric.type = starts_with("router.googleapis.com/")
      • metric.type = starts_with("vpn.googleapis.com/")
      • metric.type = starts_with("compute.googleapis.com/")
    • Substring: metric.type = has_substring("network") OR metric.type = has_substring("packet") OR metric.type = has_substring("nat")
  • Fallback (CLI/CURL): If MCP tools not available, use gcloud or curl.

    curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)"
    "https://monitoring.googleapis.com/v3/projects/{project_id}/metricDescriptors?filter=metric.type=starts_with(%22{prefix}%22)"
    | jq -r '.metricDescriptors[] | "\(.type): \(.description)"'
    
    curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)" \
    "https://monitoring.googleapis.com/v3/projects/{project_id}/timeSeries?" \
    "filter=metric.type%3D%22{metric_name}%22&" \
    "interval.startTime={start_time}&" \
    "interval.endTime={end_time}&" \
    "aggregation.alignmentPeriod=3600s&" \
    "aggregation.perSeriesAligner=ALIGN_PERCENTILE_50" \
    | jq '.timeSeries[] | {metric: .metric.type, points: .points[:5]}'
  • Detailed Schema: ALWAYS query the full descriptor for a specific metric before use to identify available labels. Metric types like vm_flow/rtt often use resource.labels.zone for the local zone and metric.labels.remote_zone for the peer.

Source: SKILL.md on GitHub

No alertstoday3 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    This skill facilitates Google Cloud networking observability by interacting with official Google Cloud APIs and command-line tools. It contains patterns for executing cloud CLI commands and performing in-memory data processing, which are standard for its intended diagnostic and estimation purposes.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

Signed by skilld at b6a171a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 days ago
metadata
{
  "version": "1.0.3",
  "category": "Compute"
}

README badge

README badge for google/skills/google-cloud-networking-observability