All skills
google avatar

/workload-manager-basics

@becc4b8
by googlegoogle/skills21k stars
1,698

Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API. Use when you need to inspect workload best-practice rules, create and run evaluations for Google Cloud general best practices, SAP, SQL Server, or custom organizational rules, review violations, export results to BigQuery, or automate Workload Manager through client libraries because no service-specific public CLI or MCP server is available. Don't use for general Google Compute Engine instance management, VPC configuration, or standard IAM auditing.

Use this Skill: https://skilld.dev/gh/google/skills/workload-manager-basics

This session only. Nothing lands on disk.

referencessetup-prerequisites.md

≈781 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workload Manager Setup Prerequisites

This file is not Workload Manager infrastructure-as-code support. Public Terraform examples here cover only adjacent prerequisites around Workload Manager: API enablement, IAM, BigQuery export datasets, and KMS keys.

Do not write examples that imply Terraform can manage Workload Manager evaluations, executions, rules, deployments, actuations, or insights unless a current provider reference explicitly documents those resources. Manage Workload Manager resources through public client libraries or the REST API.

Terraform: Enable API

resource "google_project_service" "workload_manager" {
  project            = var.project_id
  service            = "workloadmanager.googleapis.com"
  disable_on_destroy = false
}

resource "google_project_service" "service_usage" {
  project            = var.project_id
  service            = "serviceusage.googleapis.com"
  disable_on_destroy = false
}

resource "google_project_service" "monitoring" {
  project            = var.project_id
  service            = "monitoring.googleapis.com"
  disable_on_destroy = false
}

The Service Usage and Cloud Monitoring APIs are required when creating and running custom-rule evaluations.

Terraform: Grant Evaluation Admin

resource "google_project_iam_member" "workload_manager_evaluation_admin" {
  project = var.project_id
  role    = "roles/workloadmanager.evaluationAdmin"
  member  = "serviceAccount:${google_service_account.automation.email}"
}

Terraform: BigQuery Export Dataset

resource "google_bigquery_dataset" "workload_manager_results" {
  project    = var.project_id
  dataset_id = "workload_manager_results"
  location   = var.location
}

Reference this dataset from the client libraries or REST API with Evaluation.big_query_destination.destination_dataset. Use a regional dataset in the same region as the evaluation data; multi-region datasets are not supported for Workload Manager result exports.

Terraform: CMEK Prerequisites

resource "google_kms_key_ring" "workload_manager" {
  project  = var.project_id
  name     = "workload-manager"
  location = var.location
}

resource "google_kms_crypto_key" "evaluations" {
  name            = "evaluations"
  key_ring        = google_kms_key_ring.workload_manager.id
  rotation_period = "7776000s"
}

Reference the key from the client libraries or REST API with Evaluation.kms_key in this format:

projects/PROJECT_ID/locations/LOCATION/keyRings/KEY_RING/cryptoKeys/KEY

Automation Boundary

flowchart LR
    TF["Terraform prerequisites"] --> API["Enable API"]
    TF --> IAM["Grant IAM roles"]
    TF --> BQ["Create BigQuery dataset"]
    TF --> KMS["Create KMS key"]
    ClientLib["Client Libraries or REST"] --> Eval["Create and run evaluations"]
    Eval --> BQ
    Eval --> KMS

Keep prerequisite setup and evaluation execution separate. Evaluation runs are operational actions with long-running operation state, so they fit better in controlled client library or REST API automation than in a Terraform plan.

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides comprehensive instructions for managing Google Cloud Workload Manager using official client libraries and REST APIs. It includes some security considerations regarding the ingestion of external data and the use of command-line tools for setup. While these are standard for cloud management tasks, they should be used with appropriate security practices. See the detailed analysis for context.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "CloudObservabilityAndMonitoring"
}

README badge

README badge for google/skills/workload-manager-basics