Agent skill

Gcloud

by einverne in einverne/dotfiles

Guide for implementing Google Cloud SDK (gcloud CLI) - a command-line tool for managing Google Cloud resources.

GPL-3.0Auto-check: notesDevOps & Cloud

Install Gcloud

skills CLI
$ npx skills add einverne/dotfiles --skill gcloud -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install einverne/dotfiles gcloud --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/einverne/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude/skills/gcloud .claude/skills/gcloud && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gcloud
GitHub stars
121
Token cost
~5.6k tokens
SKILL.md length
797 words
Files
2 (incl. references)
Skills in repo
39
Repo updated
First seen
Licence
GPL-3.0

At a glance

Guide for implementing Google Cloud SDK (gcloud CLI) - a command-line tool for managing Google Cloud resources.

  • Works in 4 steps: User Account (OAuth 2.0) → Service Account → Application Default Credentials (ADC) → …
  • Installing/configuring gcloud
  • SKILL.md covers When to Use This Skill, Core Concepts, I. INSTALLATION & SETUP and II. AUTHENTICATION &…, plus 3 more sections
  • Calls gcloud, gsutil and curl; reaches cloud.google.com and dl.google.com; needs GCP_SA_KEY and GOOGLE_APPLICATION_CREDENTIALS

What it does

Gcloud is an agent skill from einverne/dotfiles. Guide for implementing Google Cloud SDK (gcloud CLI) - a command-line tool for managing Google Cloud resources. Use when installing/configuring gcloud, authenticating with Google Cloud, managing projects/configurations, deploying applications, working with Compute Engine/GKE/App Engine/Cloud Storage, scripting gcloud operations, implementing CI/CD pipelines, or troubleshooting Google Cloud deployments.

Its SKILL.md is about 5.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/detailed-guides.md`).

It sits in DevOps & Cloud, covering Deployment and CI/CD. It works with Google Cloud and Google Kubernetes Engine. The repository describes itself as: my personal dotfiles managed by dotbot, zinit. The licence is GPL-3.0.

When your agent uses it

  • Installing/configuring gcloud
  • Authenticating with Google Cloud
  • Managing projects/configurations
  • Deploying applications

Example prompts

  • “/gcloud”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. User Account (OAuth 2.0)
  2. Service Account
  3. Application Default Credentials (ADC)
  4. Service Account Impersonation (Recommended for Production)

What it can do on your machine

Read from SKILL.md and the folder at commit c6c0686. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud
    • gsutil
    • curl
    • apt-get

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cloud.google.com
    • dl.google.com
    • packages.cloud.google.com

    Also links to:

    • console.cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GCP_SA_KEY
    • GOOGLE_APPLICATION_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gcloud loads about 5.6k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 797 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~5.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:89
    s.cloud.google.com/apt cloud-sdk main" | sudo tee -a /etc/apt/sources.list.d/google-cloud-sdk.list
  • NoteRuns commands with sudoSKILL.md:92
    s.cloud.google.com/apt/doc/apt-key.gpg | sudo apt-key --keyring /usr/share/keyrings/cloud.google.gpg add -
  • NoteRuns commands with sudoSKILL.md:95
    sudo apt-get update && sudo apt-get install google-cloud-cli

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from einverne/dotfiles at commit c6c0686, republished under its GPL-3.0 licence (© einverne). 797 words, ~5,593 tokens.

Download SKILL.mdSave it as .claude/skills/gcloud/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
gcloud
description
Guide for implementing Google Cloud SDK (gcloud CLI) - a command-line tool for managing Google Cloud resources. Use when installing/configuring gcloud, authenticating with Google Cloud, managing projects/configurations, deploying applications, working with Compute Engine/GKE/App Engine/Cloud Storage, scripting gcloud operations, implementing CI/CD pipelines, or troubleshooting Google Cloud deployments.

Google Cloud SDK (gcloud) Skill

Comprehensive guide for working with the Google Cloud SDK (gcloud CLI) - the primary command-line interface for interacting with Google Cloud Platform services, managing resources, and automating cloud operations.

When to Use This Skill

Use this skill when you need to:

  • Install and configure the Google Cloud SDK
  • Authenticate with Google Cloud (user accounts, service accounts, ADC)
  • Initialize gcloud and set up projects/configurations
  • Manage multiple Google Cloud projects and environments
  • Deploy applications to GCP (Compute Engine, GKE, App Engine, Cloud Run)
  • Work with Cloud Storage, databases, and other GCP services
  • Script gcloud commands for automation and CI/CD pipelines
  • Troubleshoot authentication, authorization, or deployment issues
  • Optimize gcloud command performance and output formatting
  • Implement security best practices for cloud operations

Core Concepts

The gcloud CLI

Architecture:

  • Command Structure: gcloud + [release-level] + component + entity + operation + [args] + [flags]
  • Release Levels: alpha, beta, GA (general availability)
  • Components: compute, container, app, sql, iam, config, auth, storage, etc.
  • Global Flags: --project, --format, --filter, --quiet, --verbosity

Key Features:

  • Unified CLI for 100+ Google Cloud services
  • Consistent command patterns across all services
  • Rich output formatting (JSON, YAML, CSV, table)
  • Built-in filtering and server-side query optimization
  • Interactive and non-interactive modes for automation
Authentication vs Authorization

Authentication (Who you are):

  • User accounts (developers, admins)
  • Service accounts (applications, automation)
  • Application Default Credentials (ADC)
  • OAuth 2.0, API keys, workload/workforce identity federation

Authorization (What you can do):

  • IAM roles and permissions
  • Service account impersonation
  • Resource-level access control
Configuration Management

Named Configurations:

  • Multiple configuration profiles for different environments
  • Each configuration stores: account, project, region, zone, and other properties
  • Switch between configurations instantly

Properties:

  • 50+ configurable properties across 7 categories
  • Precedence: CLI flags > env vars > config files > defaults

I. INSTALLATION & SETUP

A. Installation Methods
Linux (Archive Installation)
bash
# Download (choose architecture)
curl -O https://dl.google.com/dl/cloudsdk/channels/rapid/downloads/google-cloud-cli-linux-x86_64.tar.gz

# Extract
tar -xf google-cloud-cli-linux-x86_64.tar.gz

# Install
./google-cloud-sdk/install.sh

# Initialize
./google-cloud-sdk/bin/gcloud init
Debian/Ubuntu (Package Manager)
bash
# Add repo
echo "deb [signed-by=/usr/share/keyrings/cloud.google.gpg] https://packages.cloud.google.com/apt cloud-sdk main" | sudo tee -a /etc/apt/sources.list.d/google-cloud-sdk.list

# Import key
curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo apt-key --keyring /usr/share/keyrings/cloud.google.gpg add -

# Install
sudo apt-get update && sudo apt-get install google-cloud-cli
macOS
bash
# Download installer
curl -O https://dl.google.com/dl/cloudsdk/channels/rapid/downloads/google-cloud-cli-darwin-arm.tar.gz

# Extract and install
tar -xf google-cloud-cli-darwin-arm.tar.gz
./google-cloud-sdk/install.sh
Windows
powershell
# Download installer from https://cloud.google.com/sdk/docs/install
# Run GoogleCloudSDKInstaller.exe
# Follow installation wizard
B. Initialization
bash
# Interactive setup (recommended for first-time)
gcloud init

# What it does:
# 1. Opens browser for OAuth authentication
# 2. Selects or creates a project
# 3. Sets default configuration (region, zone)
# 4. Stores credentials

# Non-interactive (CI/CD environments)
gcloud auth activate-service-account --key-file=key.json
gcloud config set project PROJECT_ID
gcloud config set compute/region us-central1
gcloud config set compute/zone us-central1-a
C. Components
bash
# List available components
gcloud components list

# Install additional components
gcloud components install kubectl        # Kubernetes CLI
gcloud components install app-engine-python  # App Engine
gcloud components install cloud-sql-proxy    # Cloud SQL Proxy
gcloud components install pubsub-emulator    # Pub/Sub emulator

# Update all components
gcloud components update

# Remove component
gcloud components remove COMPONENT_ID

Core Components (installed by default):

  • gcloud - Main CLI
  • gsutil - Cloud Storage utility
  • bq - BigQuery CLI
  • core - Core libraries

II. AUTHENTICATION & AUTHORIZATION

A. Authentication Methods
1. User Account (OAuth 2.0)
bash
# Login with browser
gcloud auth login

# Login without browser (remote/headless)
gcloud auth login --no-browser

# Login with specific account
gcloud auth login user@example.com

# List authenticated accounts
gcloud auth list

# Switch active account
gcloud config set account user@example.com

# Revoke credentials
gcloud auth revoke user@example.com
2. Service Account
bash
# Activate service account with key file
gcloud auth activate-service-account SA_EMAIL --key-file=path/to/key.json

# Create service account
gcloud iam service-accounts create SA_NAME \
  --display-name="Service Account Display Name"

# Create and download key
gcloud iam service-accounts keys create key.json \
  --iam-account=SA_EMAIL

# Grant IAM role
gcloud projects add-iam-policy-binding PROJECT_ID \
  --member="serviceAccount:SA_EMAIL" \
  --role="roles/compute.admin"
3. Application Default Credentials (ADC)
bash
# Setup ADC for client libraries
gcloud auth application-default login

# Setup ADC with service account impersonation
gcloud auth application-default login \
  --impersonate-service-account=SA_EMAIL

# Revoke ADC
gcloud auth application-default revoke

# ADC Search Order:
# 1. GOOGLE_APPLICATION_CREDENTIALS environment variable
# 2. ~/.config/gcloud/application_default_credentials.json
# 3. Metadata server (on GCP resources)
bash
# Impersonate for single command
gcloud compute instances list \
  --impersonate-service-account=SA_EMAIL

# Set default impersonation
gcloud config set auth/impersonate_service_account SA_EMAIL

# Verify impersonation
gcloud config get-value auth/impersonate_service_account

# Clear impersonation
gcloud config unset auth/impersonate_service_account

Why Impersonation?

  • Short-lived temporary credentials (no persistent key risk)
  • No need to distribute service account keys
  • Centralized permission management
  • Easy to audit and rotate
B. Configuration Profiles
Create and Manage Configurations
bash
# Create new configuration
gcloud config configurations create dev

# List all configurations
gcloud config configurations list

# Activate configuration
gcloud config configurations activate dev

# Switch configuration for single command
gcloud compute instances list --configuration=prod

# Set properties
gcloud config set project my-project-dev
gcloud config set compute/region us-central1
gcloud config set compute/zone us-central1-a

# View all properties
gcloud config list

# Unset property
gcloud config unset compute/zone

# Delete configuration
gcloud config configurations delete dev
Multi-Environment Pattern
bash
# Development environment
gcloud config configurations create dev
gcloud config set project my-project-dev
gcloud config set account dev@example.com
gcloud config set compute/region us-central1

# Staging environment
gcloud config configurations create staging
gcloud config set project my-project-staging
gcloud config set auth/impersonate_service_account staging-sa@project.iam.gserviceaccount.com

# Production environment
gcloud config configurations create prod
gcloud config set project my-project-prod
gcloud config set auth/impersonate_service_account prod-sa@project.iam.gserviceaccount.com

# Switch environments
gcloud config configurations activate dev
gcloud config configurations activate prod

III. COMMON WORKFLOWS

A. Project Management
bash
# List projects
gcloud projects list

# Create project
gcloud projects create PROJECT_ID --name="Project Name"

# Set active project
gcloud config set project PROJECT_ID

# Get current project
gcloud config get-value project

# Enable API
gcloud services enable compute.googleapis.com
gcloud services enable container.googleapis.com

# List enabled APIs
gcloud services list

# Describe project
gcloud projects describe PROJECT_ID
B. Compute Engine
bash
# List instances
gcloud compute instances list

# Create instance
gcloud compute instances create my-instance \
  --zone=us-central1-a \
  --machine-type=e2-medium \
  --image-family=debian-11 \
  --image-project=debian-cloud \
  --boot-disk-size=10GB

# SSH into instance
gcloud compute ssh my-instance --zone=us-central1-a

# Copy files
gcloud compute scp local-file.txt my-instance:~/remote-file.txt \
  --zone=us-central1-a

# Stop instance
gcloud compute instances stop my-instance --zone=us-central1-a

# Delete instance
gcloud compute instances delete my-instance --zone=us-central1-a
C. Google Kubernetes Engine (GKE)
bash
# Create cluster
gcloud container clusters create my-cluster \
  --zone=us-central1-a \
  --num-nodes=3 \
  --machine-type=e2-medium

# Get cluster credentials
gcloud container clusters get-credentials my-cluster --zone=us-central1-a

# List clusters
gcloud container clusters list

# Resize cluster
gcloud container clusters resize my-cluster \
  --num-nodes=5 \
  --zone=us-central1-a

# Delete cluster
gcloud container clusters delete my-cluster --zone=us-central1-a
D. Cloud Storage
bash
# Create bucket
gsutil mb gs://my-bucket-name

# Upload file
gsutil cp local-file.txt gs://my-bucket-name/

# Download file
gsutil cp gs://my-bucket-name/file.txt ./

# List bucket contents
gsutil ls gs://my-bucket-name/

# Sync directory
gsutil rsync -r ./local-dir gs://my-bucket-name/remote-dir

# Set bucket permissions
gsutil iam ch user:user@example.com:objectViewer gs://my-bucket-name

# Delete bucket
gsutil rm -r gs://my-bucket-name
E. App Engine
bash
# Deploy application
gcloud app deploy app.yaml

# View application
gcloud app browse

# View logs
gcloud app logs tail

# List versions
gcloud app versions list

# Delete version
gcloud app versions delete VERSION_ID

# Set traffic split
gcloud app services set-traffic SERVICE \
  --splits v1=0.5,v2=0.5
F. Cloud Run
bash
# Deploy container
gcloud run deploy my-service \
  --image=gcr.io/PROJECT_ID/my-image:tag \
  --platform=managed \
  --region=us-central1 \
  --allow-unauthenticated

# List services
gcloud run services list

# Describe service
gcloud run services describe my-service --region=us-central1

# Delete service
gcloud run services delete my-service --region=us-central1

IV. SCRIPTING & AUTOMATION

A. Output Formats
bash
# JSON (recommended for scripting)
gcloud compute instances list --format=json

# YAML
gcloud compute instances list --format=yaml

# CSV
gcloud compute instances list --format="csv(name,zone,status)"

# Table (default)
gcloud compute instances list --format=table

# Value (single field extraction)
gcloud config get-value project --format="value()"

# Custom format
gcloud compute instances list \
  --format="table(name,zone,machineType,status)"
B. Filtering
bash
# Server-side filtering (more efficient)
gcloud compute instances list --filter="zone:us-central1-a"
gcloud compute instances list --filter="status=RUNNING"
gcloud compute instances list --filter="name~^web-.*"

# Multiple conditions
gcloud compute instances list \
  --filter="zone:us-central1 AND status=RUNNING"

# Negation
gcloud compute instances list --filter="NOT status=TERMINATED"

# Complex expressions
gcloud compute instances list \
  --filter="(status=RUNNING OR status=STOPPING) AND zone:us-central1"
C. Error Handling
bash
#!/bin/bash

# Simple error check
if ! gcloud compute instances create my-instance; then
  echo "Failed to create instance"
  exit 1
fi

# Capture exit code
gcloud compute instances describe my-instance
EXIT_CODE=$?
if [ $EXIT_CODE -ne 0 ]; then
  echo "Instance not found or error occurred"
  exit $EXIT_CODE
fi

# Capture stderr
ERROR_OUTPUT=$(gcloud compute instances create my-instance 2>&1)
if [ $? -ne 0 ]; then
  echo "Error: $ERROR_OUTPUT"
  exit 1
fi

# Validate before create (idempotent pattern)
if ! gcloud compute instances describe my-instance &>/dev/null; then
  gcloud compute instances create my-instance
else
  echo "Instance already exists, skipping creation"
fi
D. Retry Logic
bash
#!/bin/bash

MAX_RETRIES=5
RETRY_DELAY=5

for i in $(seq 1 $MAX_RETRIES); do
  if gcloud compute instances create my-instance; then
    echo "Instance created successfully"
    exit 0
  else
    echo "Attempt $i failed, retrying in ${RETRY_DELAY}s..."
    sleep $RETRY_DELAY
    RETRY_DELAY=$((RETRY_DELAY * 2))  # Exponential backoff
  fi
done

echo "Failed after $MAX_RETRIES attempts"
exit 1
E. Batch Operations
bash
#!/bin/bash

# Parallel instance creation
INSTANCES=("web-1" "web-2" "web-3")

for instance in "${INSTANCES[@]}"; do
  gcloud compute instances create "$instance" \
    --zone=us-central1-a \
    --machine-type=e2-medium \
    --async  # Run in background
done

# Wait for all operations to complete
gcloud compute operations list --filter="status=RUNNING" \
  --format="value(name)" | while read op; do
  gcloud compute operations wait "$op" --zone=us-central1-a
done

echo "All instances created"
F. CI/CD Integration
GitHub Actions
yaml
name: Deploy to GCP

on:
  push:
    branches: [main]

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3

      - id: auth
        uses: google-github-actions/auth@v1
        with:
          credentials_json: ${{ secrets.GCP_SA_KEY }}

      - name: Set up Cloud SDK
        uses: google-github-actions/setup-gcloud@v1

      - name: Deploy to Cloud Run
        run: |
          gcloud run deploy my-service \
            --image=gcr.io/${{ secrets.GCP_PROJECT_ID }}/my-image:${{ github.sha }} \
            --region=us-central1 \
            --platform=managed
GitLab CI
yaml
deploy:
  image: google/cloud-sdk:alpine
  script:
    - echo $GCP_SA_KEY | base64 -d > key.json
    - gcloud auth activate-service-account --key-file=key.json
    - gcloud config set project $GCP_PROJECT_ID
    - gcloud app deploy
  only:
    - main

V. BEST PRACTICES

A. Security

1. Never Commit Credentials

bash
# Add to .gitignore
echo "key.json" >> .gitignore
echo ".config/gcloud/" >> .gitignore
echo "application_default_credentials.json" >> .gitignore

2. Use Service Account Impersonation

bash
# Prefer impersonation over key files
gcloud config set auth/impersonate_service_account SA_EMAIL

# NOT: gcloud auth activate-service-account --key-file=key.json

3. Principle of Least Privilege

bash
# Grant minimal required roles
gcloud projects add-iam-policy-binding PROJECT_ID \
  --member="serviceAccount:SA_EMAIL" \
  --role="roles/compute.instanceAdmin.v1"  # Specific role, not "owner"

4. Rotate Keys Regularly

bash
# Create new key
gcloud iam service-accounts keys create new-key.json \
  --iam-account=SA_EMAIL

# Delete old key
gcloud iam service-accounts keys delete KEY_ID \
  --iam-account=SA_EMAIL
B. Performance

1. Use Server-Side Filtering

bash
# Good: Filter on server
gcloud compute instances list --filter="zone:us-central1"

# Bad: Filter locally with grep
gcloud compute instances list | grep us-central1

2. Limit Output

bash
# Only fetch what you need
gcloud compute instances list --limit=10

# Project only needed fields
gcloud compute instances list --format="value(name,zone)"

3. Batch Operations

bash
# Use --async for parallel operations
gcloud compute instances create instance-1 --async
gcloud compute instances create instance-2 --async
gcloud compute instances create instance-3 --async
C. Maintainability

1. Use Named Configurations

bash
# Separate dev/staging/prod configurations
gcloud config configurations create dev
gcloud config configurations create prod

2. Document Commands

bash
#!/bin/bash
# Purpose: Deploy application to Cloud Run
# Usage: ./deploy.sh [environment]
# Example: ./deploy.sh production

ENV=${1:-staging}
gcloud config configurations activate "$ENV"
gcloud run deploy my-service --image=gcr.io/project/image:latest

3. Use Environment Variables

bash
# Make scripts portable
PROJECT_ID=${GCP_PROJECT_ID:-default-project}
REGION=${GCP_REGION:-us-central1}

gcloud config set project "$PROJECT_ID"
gcloud config set compute/region "$REGION"
D. Monitoring & Logging
bash
# Enable audit logging
gcloud logging read "resource.type=gce_instance" \
  --limit=10 \
  --format=json

# Track command history
gcloud info --show-log

# Verbose output for debugging
gcloud compute instances create my-instance --verbosity=debug

VI. TROUBLESHOOTING

Show full SKILL.md (327 more words)Show less
Common Issues

1. Authentication Failures

bash
# Check current authentication
gcloud auth list

# Verify credentials
gcloud auth application-default print-access-token

# Re-authenticate
gcloud auth login
gcloud auth application-default login

2. Permission Denied

bash
# Check IAM permissions
gcloud projects get-iam-policy PROJECT_ID \
  --flatten="bindings[].members" \
  --filter="bindings.members:user@example.com"

# Check service account permissions
gcloud iam service-accounts get-iam-policy SA_EMAIL

3. Quota Exceeded

bash
# Check quota usage
gcloud compute project-info describe --project=PROJECT_ID

# Request quota increase via Cloud Console

4. Network Issues

bash
# Check connectivity
gcloud info

# Use proxy
gcloud config set proxy/type http
gcloud config set proxy/address PROXY_HOST
gcloud config set proxy/port PROXY_PORT

5. Configuration Issues

bash
# View current configuration
gcloud config list

# Reset configuration
gcloud config configurations delete default
gcloud init

VII. QUICK REFERENCE

Essential Commands
TaskCommand
Initialize gcloudgcloud init
Logingcloud auth login
Set projectgcloud config set project PROJECT_ID
List resourcesgcloud [SERVICE] list
Describe resourcegcloud [SERVICE] describe RESOURCE
Create resourcegcloud [SERVICE] create RESOURCE
Delete resourcegcloud [SERVICE] delete RESOURCE
Get helpgcloud [SERVICE] --help
View configurationsgcloud config configurations list
Switch configurationgcloud config configurations activate CONFIG
Global Flags
FlagPurposeExample
--projectOverride project--project=my-project
--formatOutput format--format=json
--filterServer-side filter--filter="status=RUNNING"
--limitLimit results--limit=10
--quietSuppress prompts--quiet
--verbosityLog level--verbosity=debug
--asyncDon't wait--async
Common Properties
bash
# Core
gcloud config set project PROJECT_ID
gcloud config set account EMAIL
gcloud config set disable_usage_reporting true

# Compute
gcloud config set compute/region us-central1
gcloud config set compute/zone us-central1-a

# Container
gcloud config set container/cluster CLUSTER_NAME

# App Engine
gcloud config set app/cloud_build_timeout 1200

VIII. RESOURCES

Official Documentation
Tools
Best Practices Summary
  1. Authentication: Use service account impersonation instead of key files
  2. Configuration: Use named configurations for multiple environments
  3. Security: Grant minimal IAM permissions, rotate keys regularly
  4. Performance: Use server-side filtering, batch operations with --async
  5. Scripting: Output JSON format, implement error handling and retries
  6. Automation: Use environment variables, validate before operations
  7. Monitoring: Enable Cloud Audit Logs, track command history
  8. Maintenance: Keep SDK updated, document scripts thoroughly

Common Use Cases

Multi-Environment Deployment
  • Separate configurations for dev/staging/prod
  • Service account impersonation for each environment
  • Automated deployments via CI/CD
Infrastructure as Code
  • Create resources with gcloud in shell scripts
  • Export configurations as YAML/JSON
  • Version control infrastructure commands
Data Pipeline Automation
  • Scheduled BigQuery jobs
  • Cloud Storage file transfers
  • Pub/Sub message processing
Security Compliance
  • Audit logging for all operations
  • Encrypted data at rest and in transit
  • Regular key rotation and access reviews

This skill provides comprehensive gcloud CLI knowledge for implementing Google Cloud solutions, from basic authentication to advanced automation workflows. Always refer to official documentation for the latest features and service-specific details.

© einverne, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in claude/skills/gcloud of einverne/dotfiles.

  • SKILL.md
  • references/detailed-guides.md

Open the folder on GitHubat commit c6c0686

Compare with similar skills

Gcloud next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gcloud compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gcloud this skilleinverne/dotfiles121—~5.6kAutomated safety check: NotesGPL-3.0
Apollo Deploy Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~1.8kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Google Agents CLI Scaffoldpifferologo/cloud-agents-cli1291 repos~2.9kAutomated safety check: NotesApache-2.0
Google Agents CLI Deploypifferologo/cloud-agents-cli1291 repos~6kAutomated safety check: PassApache-2.0

Similar skills

  • Apollo Deploy Integration

    jeremylongshore/tons-of-skills-marketplace

    Deploy Apollo.io integrations to production. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Google Agents CLI Scaffold

    pifferologo/cloud-agents-cli

    This skill should be used when the user wants to "create an agent project", "start a new ADK project", "build me a new agent", "add CI/CD to my project", "add deployment", "enhance my project", or…

    129 GitHub starsUsed in 1 repo~2.9k tokens
    DevOps & CloudAuto-check: notes
  • Google Agents CLI Deploy

    pifferologo/cloud-agents-cli

    This skill should be used when the user wants to "deploy an agent", "deploy my ADK agent", "set up CI/CD", "configure secrets", "troubleshoot a deployment", or needs guidance on Agent Runtime, Cloud…

    129 GitHub starsUsed in 1 repo~6k tokens
    DevOps & CloudAuto-check passed
  • Google Agents CLI Publish

    pifferologo/cloud-agents-cli

    This skill should be used when the user wants to "publish an agent", "publish my ADK agent", "register an agent with Gemini Enterprise", "publish to Gemini Enterprise", or needs guidance on the…

    129 GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed

More from einverne/dotfiles

All 39 skills in this repo
  • Chrome Devtools

    einverne/dotfiles

    Browser automation, debugging, and performance analysis using Puppeteer CLI scripts.

    121 GitHub starsUsed in 2 repos~1.6k tokens
    Auto-check: notes
  • DOCX

    einverne/dotfiles

    Comprehensive document creation, editing, and analysis with support for tracked changes, comments, formatting preservation, and text extraction.

    121 GitHub starsUsed in 35 repos~2.5k tokens
    Auto-check: notes
  • PDF

    einverne/dotfiles

    Comprehensive PDF manipulation toolkit for extracting text and tables, creating new PDFs, merging/splitting documents, and handling forms.

    121 GitHub starsUsed in 47 repos~1.8k tokens
    Auto-check passed
  • Gemini Audio

    einverne/dotfiles

    Guide for implementing Google Gemini API audio capabilities - analyze audio with transcription, summarization, and understanding (up to 9.5 hours), plus generate speech with controllable TTS.

    121 GitHub starsUsed in 1 repo~2k tokens
    Auto-check: notes
  • Gemini Image Gen

    einverne/dotfiles

    Guide for implementing Google Gemini API image generation - create high-quality images from text prompts using gemini-2.5-flash-image model.

    121 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check: notes
  • Gemini Vision

    einverne/dotfiles

    Guide for implementing Google Gemini API image understanding - analyze images with captioning, classification, visual QA, object detection, segmentation, and multi-image comparison.

    121 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check: notes

Questions about Gcloud

What does Gcloud do?

Guide for implementing Google Cloud SDK (gcloud CLI) - a command-line tool for managing Google Cloud resources. Gcloud is an agent skill from einverne/dotfiles. Guide for implementing Google Cloud SDK (gcloud CLI) - a command-line tool for managing Google Cloud resources.

When should I use Gcloud?

Gcloud fits situations like: installing/configuring gcloud; authenticating with Google Cloud; managing projects/configurations; deploying applications.

How do I install Gcloud in Claude Code?

Run `npx skills add einverne/dotfiles --skill gcloud -a claude-code`. Or copy the skill folder (claude/skills/gcloud in einverne/dotfiles) into .claude/skills/gcloud in your project. Claude Code loads it when a task matches its description.

How do I install Gcloud in Codex?

Run `npx skills add einverne/dotfiles --skill gcloud -a codex`. Or copy the skill folder (claude/skills/gcloud in einverne/dotfiles) into .agents/skills/gcloud in your project. Codex loads it when a task matches its description.

Can I use Gcloud in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add einverne/dotfiles --skill gcloud -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gcloud, .gemini/skills/gcloud, .github/skills/gcloud and .opencode/skills/gcloud in your project.

What does Gcloud need to run?

Going by SKILL.md and its folder, Gcloud needs the command-line tools its instructions call (gcloud, gsutil, curl and apt-get) and credentials named GCP_SA_KEY and GOOGLE_APPLICATION_CREDENTIALS. Our summary lists: Python 3.

Does Gcloud access the network?

SKILL.md names 4 domains. In commands or code: cloud.google.com, dl.google.com and packages.cloud.google.com; the agent is likely to contact these when it follows the instructions. As links in the text: console.cloud.google.com. This is read from the text; nothing was executed.

Is Gcloud safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Gcloud use?

Gcloud is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gcloud use?

About 5.6k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Gcloud?

Skills that share tags, products or a category with Gcloud: Apollo Deploy Integration (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars) and Google Agents CLI Scaffold (pifferologo/cloud-agents-cli, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gcloud?

einverne (a GitHub user) maintains it in einverne/dotfiles, which has 121 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on September 9, 2026.

Source: einverne/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.