All skills
google avatar

/workload-manager-basics

@becc4b8
by googlegoogle/skills21k stars
1,698

Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API. Use when you need to inspect workload best-practice rules, create and run evaluations for Google Cloud general best practices, SAP, SQL Server, or custom organizational rules, review violations, export results to BigQuery, or automate Workload Manager through client libraries because no service-specific public CLI or MCP server is available. Don't use for general Google Compute Engine instance management, VPC configuration, or standard IAM auditing.

Use this Skill: https://skilld.dev/gh/google/skills/workload-manager-basics

This session only. Nothing lands on disk.

referencespublic-cli-status.md

≈503 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workload Manager Public CLI Status

Public documentation does not currently describe a dedicated gcloud workload-manager command group. Do not write examples that imply Workload Manager evaluations, executions, rules, deployments, or actuations can be managed through a service-specific gcloud command.

Use gcloud only for adjacent Google Cloud setup tasks: project configuration, authentication, IAM, service enablement, and access tokens. Use public client libraries or the REST API for Workload Manager resources.

Enable the API

gcloud services enable workloadmanager.googleapis.com --quiet

Set Project and Location Defaults

gcloud config set project PROJECT_ID
export PROJECT_ID="$(gcloud config get-value project)"
export LOCATION="LOCATION"

Authenticate for Local Client Library Usage

gcloud auth application-default login

Authenticate for REST Usage

export TOKEN="$(gcloud auth print-access-token)"

Grant a Workload Manager Role

gcloud projects add-iam-policy-binding PROJECT_ID \
  --member="user:USER_EMAIL" \
  --role="roles/workloadmanager.evaluationAdmin" \
  --quiet

Use roles/workloadmanager.viewer when read-only access is enough.

REST Bridge

curl -sS \
  -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  "https://workloadmanager.googleapis.com/v1/projects/PROJECT_ID/locations/LOCATION/evaluations"

Operational Notes

  • Do not invent service-specific CLI commands unless they appear in current public gcloud documentation.
  • Do not describe gcloud as a Workload Manager management surface.
  • gcloud services, gcloud auth, gcloud projects add-iam-policy-binding, and gcloud logging remain useful around the Workload Manager API.
  • Enabling the API has no direct charge by itself. Evaluations can create logs, scan resource metadata, and optionally export detailed results to BigQuery, which can incur normal service charges.

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides comprehensive instructions for managing Google Cloud Workload Manager using official client libraries and REST APIs. It includes some security considerations regarding the ingestion of external data and the use of command-line tools for setup. While these are standard for cloud management tasks, they should be used with appropriate security practices. See the detailed analysis for context.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "CloudObservabilityAndMonitoring"
}

README badge

README badge for google/skills/workload-manager-basics