gcp-specialist
kaiohenricunha/dotbabel/skills/gcp-specialist/SKILL.md
Deep-dive Google Cloud architecture review, debugging, and service design. Use for structured investigations of GCP-specific issues, IAM or cost audits, and multi-service design reviews. Triggers on: "GCP audit", "GCP design review", "Workload Identity debug", "IAM review GCP", "review my GKE", "GCP troubleshooting", "Cloud Run deep-dive".
Skill0 starsChanged 9 days ago
What's in it
- GCP Specialist
- Arguments
- Phase 1: Context Gathering
- Phase 2: Diagnosis
- Phase 3: Design / Root-Cause Analysis
- Phase 4: Recommendations
- Phase 5: Verification
- Reference Docs
Tools it asks for
- Read
- Grep
- Glob
- Bash
--- id: gcp-specialist name: gcp-specialist type: skill version: 1.0.0 domain: [infra] platform: [gcp] task: [debugging, review] maturity: validated owner: "@kaiohenricunha" created: 2025-01-01 updated: 2026-04-17 description: > Deep-dive Google Cloud architecture review, debugging, and service design. Use for structured investigations of GCP-specific issues, IAM or cost audits, and multi-service design reviews. Triggers on: "GCP audit", "GCP design review", "Workload Identity debug", "IAM review GCP", "review my GKE", "GCP troubleshooting", "Cloud Run deep-dive". argument-hint: "<project context, service, or problem description>" tools: Read, Grep, Glob, Bash allowed-tools: Read Grep Glob Bash effort: max model: opus --- # GCP Specialist Structured investigation for Google Cloud workloads. Five phases: gather context, diagnose, design, recommend, verify. ## Arguments - `$0` — project context, service scope, or problem description. Required. --- ## Phase 1: Context Gathering 1. Identify the organization, folders, project(s), and services in scope. 2. Glob for IaC in the working directory: `**/*.tf`, `**/*.yaml` (Config Connector), `**/*.jinja` (Deployment Manager legacy). 3. If gcloud CLI access is available: ```bash gcloud config list gcloud projects list gcloud auth list ``` 4. List enabled APIs in the current project: ```bash gcloud services list --enabled --format="value(config.name)" ``` --- ## Phase 2: Diagnosis **Compute / containers:** ```bash gcloud compute instances list gcloud container clusters list gcloud run services list ``` **IAM / identity:** ```bash gcloud projects get-iam-policy <project> gcloud iam service-accounts list gcloud iam workload-identity-pools list --location=global ``` **Networking:** ```bash gcloud compute networks list gcloud compute firewall-rules list gcloud compute routers list ``` **Serverless / events:** ```bash gcloud functions list gcloud pubsub topics list gcloud pubsub subscriptions list ``` **Cost / quotas:** ```bash gcloud compute project-info describe --format="yaml(quotas)" gcloud logging read 'resource.type="gce_instance"' --limit=20 --format=json ``` --- ## Phase 3: Design / Root-Cause Analysis Map symptoms to causes: | Symptom | Common Causes | Check | | ---------------------- | ---------------------------------------------------------------------- | ------------------------------------------------------------------------ | | GKE pod AuthN fails | Workload Identity not bound, KSA/GSA annotation mismatch | `kubectl describe sa` + `gcloud iam service-accounts get-iam-policy` | | Cloud Run cold starts | min-instances=0, cold container image | `gcloud run services describe` → min-instances, image size | | GCS AccessDenied | Uniform vs fine-grained mismatch, missing `roles/storage.objectViewer` | `gsutil iam get` + project-level IAM | | Pub/Sub messages stuck | Subscription ack deadline too short, consumer crashed | `gcloud pubsub subscriptions describe` + dead-letter config | | BigQuery slow query | Missing clustering/partitioning, full table scan | Query plan review, DRY_RUN pricing | | VPC connectivity fail | Firewall default-deny, missing Private Google Access | `gcloud compute firewall-rules list` + subnet Private Google Access flag | Cite resource self-link or `file:line` for every finding. --- ## Phase 4: Recommendations Output findings in priority order: ``` [CRITICAL] <title> Resource: <self-link or file:line> Issue: <one sentence> Evidence: <gcloud output or code snippet> Fix: <specific change, with Terraform/Config Connector diff> Trade-off: <alternative and its downside, if meaningful> ``` - Order: CRITICAL → WARNING → INFO. - For IaC fixes, show the exact Terraform or Config Connector diff. - Reference relevant docs in `references/` where applicable. --- ## Phase 5: Verification After fixes are applied: 1. Re-run the diagnostic command that surfaced the issue. 2. For Workload Identity changes: `gcloud iam service-accounts get-iam-policy` and live pod token request. 3. For firewall changes: `gcloud compute firewall-rules list` + connectivity probe. 4. For IAM changes: `gcloud projects get-iam-policy --flatten="bindings[].members"` to see effective membership. 5. Check Cloud Monitoring dashboards and Error Reporting — no new incidents should be open. --- ## Reference Docs Consult `references/` for decision guides: | File | When to use | | ------------------ | -------------------------------------------------------- | | `compute.md` | GKE, Cloud Run, GCE selection and sizing | | `serverless.md` | Cloud Functions, Pub/Sub, Cloud Tasks, Eventarc | | `storage.md` | GCS, Filestore, BigQuery, Cloud SQL, Spanner | | `networking.md` | VPC, Cloud Load Balancing, Cloud Armor, Cloud CDN | | `iam.md` | IAM hierarchy, Workload Identity, Service Accounts | | `observability.md` | Cloud Monitoring, Logging, Trace, Error Reporting | | `iac-patterns.md` | Terraform, Config Connector, Deployment Manager patterns |
More agent context in kaiohenricunha/dotbabel
48 other files this repository gives its agents.
AGENTS.md
CLAUDE.md
Copilot instructions
Skill
- changelog.agents/skills/changelog/SKILL.md
- dependabot-sweep.agents/skills/dependabot-sweep/SKILL.md
- markdown.agents/skills/markdown/SKILL.md
- merge-pr.agents/skills/merge-pr/SKILL.md
- pre-pr.agents/skills/pre-pr/SKILL.md
- pr-tldr.agents/skills/pr-tldr/SKILL.md
- tldr.agents/skills/tldr/SKILL.md
- agents-searchskills/agents-search/SKILL.md
- audit-and-fixskills/audit-and-fix/SKILL.md
- aws-specialistskills/aws-specialist/SKILL.md
- azure-specialistskills/azure-specialist/SKILL.md
- code-simplifierskills/code-simplifier/SKILL.md
- create-assessmentskills/create-assessment/SKILL.md
- create-auditskills/create-audit/SKILL.md
- create-experimentskills/create-experiment/SKILL.md
- create-inspectionskills/create-inspection/SKILL.md
- crossplane-specialistskills/crossplane-specialist/SKILL.md
- deploy-statusskills/deploy-status/SKILL.md
- detect-flakyskills/detect-flaky/SKILL.md
- fix-with-evidenceskills/fix-with-evidence/SKILL.md
- flyctlskills/flyctl/SKILL.md
- gitskills/git/SKILL.md
- ground-firstskills/ground-first/SKILL.md
- handoffskills/handoff/SKILL.md
- kubernetes-specialistskills/kubernetes-specialist/SKILL.md
- local-attestskills/local-attest/SKILL.md
- plan-graderskills/plan-grader/SKILL.md
- post-pr-reviewskills/post-pr-review/SKILL.md
- pr-conductorskills/pr-conductor/SKILL.md
- project-syncskills/project-sync/SKILL.md
- pulumi-specialistskills/pulumi-specialist/SKILL.md
- quality-reviewskills/quality-review/SKILL.md
- release-conductorskills/release-conductor/SKILL.md
- reproduce-bugskills/reproduce-bug/SKILL.md
- review-prskills/review-pr/SKILL.md
- review-prsskills/review-prs/SKILL.md
- rollback-prodskills/rollback-prod/SKILL.md
- security-auditskills/security-audit/SKILL.md
- security-reviewskills/security-review/SKILL.md
- smoke-testskills/smoke-test/SKILL.md
- specskills/spec/SKILL.md
- terraform-specialistskills/terraform-specialist/SKILL.md
- terragrunt-specialistskills/terragrunt-specialist/SKILL.md
- validate-specskills/validate-spec/SKILL.md
- veracity-auditskills/veracity-audit/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

