All skills
google avatar

/workload-manager-basics

@becc4b8
by googlegoogle/skills21k stars
1,698

Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API. Use when you need to inspect workload best-practice rules, create and run evaluations for Google Cloud general best practices, SAP, SQL Server, or custom organizational rules, review violations, export results to BigQuery, or automate Workload Manager through client libraries because no service-specific public CLI or MCP server is available. Don't use for general Google Compute Engine instance management, VPC configuration, or standard IAM auditing.

Use this Skill: https://skilld.dev/gh/google/skills/workload-manager-basics

This session only. Nothing lands on disk.

referencesiam-security.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workload Manager IAM and Security

Use least privilege and start read-only. Evaluation creation and runs can scan resource metadata across a project, folder, or organization, so scope and role choice matter.

Common Roles

Role Use
roles/workloadmanager.viewer Read Workload Manager resources.
roles/workloadmanager.evaluationViewer Read evaluation resources and
: : results. :
roles/workloadmanager.evaluationAdmin Create, update, run, and delete
: : evaluations and executions. :
roles/workloadmanager.admin Full Workload Manager
: : administration. :
roles/workloadmanager.deploymentViewer Read deployment resources exposed
: : by the REST API. :
roles/workloadmanager.deploymentAdmin Manage deployment resources
: : exposed by the REST API. :
roles/workloadmanager.insightWriter Write or delete Workload Manager
: : insights exposed by the REST API. :
roles/workloadmanager.workloadViewer View workload resources and
: : metadata. :
roles/workloadmanager.worker Worker execution role for
: : service-managed operations. :
roles/workloadmanager.serviceAgent Service agent role; do not grant
: : to humans or general automation :
: : identities. :

Role Selection

  • Listing rules, evaluations, executions, results, and scanned resources: roles/workloadmanager.viewer or roles/workloadmanager.evaluationViewer.
  • Creating or updating evaluations: roles/workloadmanager.evaluationAdmin.
  • Running evaluations: roles/workloadmanager.evaluationAdmin.
  • Full administration across Workload Manager resources: roles/workloadmanager.admin.
  • Folder or organization scope: grant roles at that scope only when project scope cannot answer the request.

Data Handling

  • Results can include resource names, service accounts, labels, observed settings, violation messages, remediation commands, and documentation URLs.
  • BigQuery export datasets should have restricted dataset-level IAM.
  • Logs and client library debug output can include request metadata. Do not persist debug logs in broad-access locations.
  • Use a dedicated automation service account instead of user credentials for recurring evaluations.

Workload Manager Service Agent & Service Account

To evaluate workloads or perform deployments, Workload Manager requires service identities with appropriate metadata reading and resource actuation roles:

1. Google-Managed Service Agent (Evaluation/Validation)

When evaluations are executed, the Workload Manager Google-managed service agent (service-PROJECT_NUMBER@gcp-sa-workloadmanager.iam.gserviceaccount.com) scans GCP resources in the defined evaluation scope.

  • Required Permissions: The service agent must be granted roles that allow it to read resource configurations.
  • Roles to Grant:
    • roles/viewer or roles/browser at the project, folder, or organization level of the evaluation scope to allow metadata scanning of Compute Engine, Cloud SQL, GKE, and other resources.
    • For detailed role mappings, refer to the Workload Manager Evaluation Roles documentation.

2. Deployment Service Account (Actuation/Deployments)

If you are using Workload Manager to automate deployments (e.g., deploying the SAP agent or other enterprise software):

  • You must create a dedicated, customer-managed deployment Service Account in your project.
  • Required Permissions: The deployment service account requires permissions to write metadata and deploy agents on Compute Engine VM instances.
  • For setup steps, refer to the Workload Manager Deployment Service Account Prerequisites.

CMEK

Evaluation.kms_key accepts a key in this format:

projects/PROJECT_ID/locations/LOCATION/keyRings/KEY_RING/cryptoKeys/KEY

Make sure the Workload Manager service agent has the needed KMS permissions before creating a CMEK-backed evaluation.

Deletion and Idempotency

  • Use request_id for create, update, run, and delete requests when available.
  • Use force=true on evaluation deletion only when child executions should be deleted as part of the same request.
  • Before deleting, list executions and confirm whether any results need to be retained or exported.

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides comprehensive instructions for managing Google Cloud Workload Manager using official client libraries and REST APIs. It includes some security considerations regarding the ingestion of external data and the use of command-line tools for setup. While these are standard for cloud management tasks, they should be used with appropriate security practices. See the detailed analysis for context.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "CloudObservabilityAndMonitoring"
}

README badge

README badge for google/skills/workload-manager-basics