Senior DevOps Toolkit
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
This skill should be used when the user wants to "deploy an agent", "deploy my ADK agent", "set up CI/CD", "configure secrets", "troubleshoot a deployment", or needs guidance on Agent Runtime, Cloud…
$ npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install pifferologo/cloud-agents-cli google-agents-cli-deploy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/pifferologo/cloud-agents-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/google-agents-cli-deploy .claude/skills/google-agents-cli-deploy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "google-agents-cli-deploy" agent skill from https://github.com/pifferologo/cloud-agents-cli/tree/main/skills/google-agents-cli-deploy into .claude/skills/google-agents-cli-deploy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-agents-cli-deploy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/pifferologo/cloud-agents-cli/tree/main/skills/google-agents-cli-deployType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install pifferologo/cloud-agents-cli google-agents-cli-deploy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pifferologo/cloud-agents-cli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/google-agents-cli-deploy .agents/skills/google-agents-cli-deploy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "google-agents-cli-deploy" agent skill from https://github.com/pifferologo/cloud-agents-cli/tree/main/skills/google-agents-cli-deploy into .agents/skills/google-agents-cli-deploy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-agents-cli-deploy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install pifferologo/cloud-agents-cli google-agents-cli-deploy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pifferologo/cloud-agents-cli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/google-agents-cli-deploy .cursor/skills/google-agents-cli-deploy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "google-agents-cli-deploy" agent skill from https://github.com/pifferologo/cloud-agents-cli/tree/main/skills/google-agents-cli-deploy into .cursor/skills/google-agents-cli-deploy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-agents-cli-deploy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/pifferologo/cloud-agents-cli.git --path skills/google-agents-cli-deploy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install pifferologo/cloud-agents-cli google-agents-cli-deploy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pifferologo/cloud-agents-cli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/google-agents-cli-deploy .gemini/skills/google-agents-cli-deploy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "google-agents-cli-deploy" agent skill from https://github.com/pifferologo/cloud-agents-cli/tree/main/skills/google-agents-cli-deploy into .gemini/skills/google-agents-cli-deploy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-agents-cli-deploy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install pifferologo/cloud-agents-cli google-agents-cli-deployInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/pifferologo/cloud-agents-cli.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/google-agents-cli-deploy .github/skills/google-agents-cli-deploy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "google-agents-cli-deploy" agent skill from https://github.com/pifferologo/cloud-agents-cli/tree/main/skills/google-agents-cli-deploy into .github/skills/google-agents-cli-deploy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-agents-cli-deploy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install pifferologo/cloud-agents-cli google-agents-cli-deploy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pifferologo/cloud-agents-cli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/google-agents-cli-deploy .opencode/skills/google-agents-cli-deploy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "google-agents-cli-deploy" agent skill from https://github.com/pifferologo/cloud-agents-cli/tree/main/skills/google-agents-cli-deploy into .opencode/skills/google-agents-cli-deploy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "google-agents-cli-deploy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
google-agents-cli-deployThis skill should be used when the user wants to "deploy an agent", "deploy my ADK agent", "set up CI/CD", "configure secrets", "troubleshoot a deployment", or needs guidance on Agent Runtime, Cloud…
Google Agents CLI Deploy is an agent skill from pifferologo/cloud-agents-cli. This skill should be used when the user wants to "deploy an agent", "deploy my ADK agent", "set up CI/CD", "configure secrets", "troubleshoot a deployment", or needs guidance on Agent Runtime, Cloud Run, or GKE deployment targets. Covers deployment workflows, service accounts, rollback, and production infrastructure. Part of the Google ADK (Agent Development Kit) skills suite. Do NOT use for API code patterns (use google-agents-cli-adk-code), evaluation (use google-agents-cli-eval), or project scaffolding (use…
Its SKILL.md is about 6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/agent-runtime.md`, `references/batch-inference.md` and `references/cicd-pipeline.md`).
It sits in DevOps & Cloud, covering Project scaffolding, Deployment and CI/CD. It works with Google Kubernetes Engine, Cloud Run, Kubernetes and Terraform. The repository describes itself as: google cloud agent cli for Drive, Gmail, Calendar, Sheets, Docs, Chat, Admin, and more. Dynamically built from piffer labs. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5957f5a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gcloudterraformkubectluvFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
adk.devAlso links to:
docs.cloud.google.comdocs.astral.shgithub.comcloud.google.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYNEW_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Google Agents CLI Deploy loads about 6k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 2,506 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from pifferologo/cloud-agents-cli at commit 5957f5a, republished under its Apache-2.0 licence (© pifferologo). 2,506 words, ~5,971 tokens.
.claude/skills/google-agents-cli-deploy/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Requires:
agents-cli(uv tool install google-agents-cli) — install uv first if needed.
Prefer using the
agents-clicommands throughout this guide — they wrap Terraform, Docker, and deployment into a tested pipeline. If your project isn't scaffolded yet, see/google-agents-cli-scaffoldto add deployment support first.
For deeper details, consult these reference files in references/:
cloud-run.md — Scaling defaults, Dockerfile, session types, networkingagent-runtime.md — container-based deploy, unified FastAPI app, the /api passthrough, Terraform resource, deployment metadata, CI/CD differencesgke.md — GKE Autopilot cluster, Kubernetes manifests, Workload Identity, session types, networkingterraform-patterns.md — Custom infrastructure, IAM, state management, importing resourcesbatch-inference.md — BigQuery Remote Function trigger; for Pub/Sub / Eventarc see /google-agents-cli-adk-codecicd-pipeline.md — Full CI/CD pipeline setup, infra cicd flags, runner comparison, WIF auth, pipeline stagestesting-deployed-agents.md — Testing instructions per deployment target, curl examples, load testsObservability: See the
/google-agents-cli-observabilityskill for Cloud Trace, prompt-response logging, BigQuery Analytics, and third-party integrations.
Choose the right deployment target based on your requirements:
| Criteria | Agent Runtime | Cloud Run | GKE |
|---|---|---|---|
| Languages | Python | Python | Python (+ others via custom containers) |
| Scaling | Managed auto-scaling (configurable min/max, concurrency) | Fully configurable (min/max instances, concurrency, CPU allocation) | Full Kubernetes scaling (HPA, VPA, node auto-provisioning) |
| Networking | VPC-SC and PSC-I supported (private VPC connectivity via network attachments) | Full VPC support, direct VPC egress, IAP, ingress rules | Full Kubernetes networking |
| Session state | Native VertexAiSessionService (persistent, managed) | In-memory (dev), Cloud SQL, or Agent Platform Sessions backend | In-memory (dev), Cloud SQL, or Agent Platform Sessions backend |
| Batch/event processing | Trigger endpoints reachable via the Agent Engine /api passthrough | Native trigger endpoints (Pub/Sub, Eventarc); see /google-agents-cli-adk-code | Custom (Kubernetes Jobs, Pub/Sub) |
| Cost model | vCPU-hours + memory-hours (not billed when idle) | Per-instance-second + min instance costs | Node pool costs (always-on or auto-provisioned) |
| Setup complexity | Lower (managed, purpose-built for agents) | Medium (Dockerfile, Terraform, networking) | Higher (Kubernetes expertise required) |
| Best for | Managed infrastructure, minimal ops | Custom infra, full networking control | Full Kubernetes control |
Ask the user which deployment target fits their needs. Each is a valid production choice with different trade-offs.
Product name mapping: "Agent Engine" / "Vertex AI Agent Engine" is now Agent Runtime. Use
--deployment-target agent_runtime.
Ambient / scheduled / event-driven agents: ADK's
trigger_sourcesregisters/apps/{app}/trigger/*endpoints on the same FastAPI app for all targets. On Cloud Run / GKE these are public HTTP routes you point a Pub/Sub push subscription or Eventarc trigger at; on Agent Runtime the same routes are reachable through the Agent Engine/apipassthrough (e.g..../reasoningEngines/v1/{resource}/api/apps/{app}/trigger/pubsub). Cloud Run remains the simplest target for unauthenticated trigger sources. See/google-agents-cli-adk-code(references/adk-python.md, section "12. Event-Driven / Ambient Agents") for thetrigger_sourcespattern.
OAuth / user consent agents: Use Agent Runtime with Gemini Enterprise for agents that need OAuth 2.0 user consent (e.g., accessing Google Drive, Calendar, or other user-scoped APIs). Cloud Run does not currently support managed OAuth flows. See the
adk-ae-oauthsample in/google-agents-cli-workflowPhase 1.
Task tracking: Deployment involves multiple sequential steps (infra setup, CI/CD configuration, deploy, verification). Use a task list to track progress through these steps — skipping one often causes failures in later steps that are hard to trace back.
agents-cli scaffold enhance . --deployment-target <target>agents-cli deployAgent Runtime timeout recovery: Agent Runtime deploys can take 5-10 minutes and may exceed command timeouts. If the deploy command is cancelled or times out, the deployment continues server-side. Run
agents-cli deploy --statusto check progress — poll every 60 seconds until it reports completion or failure.
IMPORTANT: Never run agents-cli deploy without explicit human approval.
Do NOT run
agents-cli infra single-projectbefore deploying. It is not a prerequisite —agents-cli deployworks on its own. Run it separately if the user needs observability features (prompt-response logging, BigQuery analytics) — see/google-agents-cli-observability.
agents-cli infra single-project runs terraform apply in deployment/terraform/single-project/. Use this to provision single-project GCP infrastructure without CI/CD (service accounts, IAM bindings, telemetry resources, Artifact Registry). Also useful to test things in a single project before going to production. It is NOT required for deploying.
# Optional — provision infrastructure in a single GCP project
agents-cli infra single-projectNote:
agents-cli deploydoesn't automatically use the Terraform-createdapp_sa. Pass the service account explicitly:agents-cli deploy --service-account SA_EMAIL.
| Flag | Description | Targets |
|---|---|---|
--project | GCP project ID | All |
--region | GCP region | All |
--service-account | Service account email for the deployed agent | All |
--service-name | Override the deployed service name (Cloud Run service or Agent Runtime display name); defaults to the project name. If you override it, consider updating your Terraform and CI (if present) — they name resources from the project name. Not supported for GKE, whose names are fully owned by Terraform. | Agent Runtime, Cloud Run |
--secrets | Comma-separated ENV=SECRET or ENV=SECRET:VERSION pairs | Agent Runtime, Cloud Run |
--update-env-vars | Comma-separated KEY=VALUE environment variables | Agent Runtime, Cloud Run |
--agent-identity | Enable agent identity (Preview) | Agent Runtime |
--network-attachment | Network attachment resource name for PSC interface (enables private VPC connectivity) | Agent Runtime |
--dns-peering-domain | DNS peering domain suffix, e.g. my-internal.corp. (requires --network-attachment) | Agent Runtime |
--dns-peering-project | Project ID hosting the Cloud DNS managed zone for DNS peering (requires --network-attachment) | Agent Runtime |
--dns-peering-network | VPC network name in the target project for DNS peering (requires --network-attachment) | Agent Runtime |
--memory | Memory limit (default: 4Gi) | Agent Runtime, Cloud Run |
--cpu | CPU limit (default: 1) | Agent Runtime, Cloud Run |
--min-instances | Minimum number of instances (default: 1) | Agent Runtime, Cloud Run |
--max-instances | Maximum number of instances (default: 10) | Agent Runtime, Cloud Run |
--concurrency | Concurrent requests per container (default: 8; see Sizing a deployment) | Agent Runtime, Cloud Run |
--num-workers | Worker processes per container (default: 1) | Agent Runtime |
--port | Container port | Cloud Run, Agent Runtime |
--build-args | Comma-separated KEY=VALUE Docker build args | Agent Runtime |
--iap | Enable Identity-Aware Proxy | Cloud Run |
--image | Container image URI (skips source build; not supported for Agent Runtime) | Cloud Run, GKE |
--no-wait | Start deployment and return immediately | Agent Runtime, Cloud Run |
--status | Check the status of a pending --no-wait deployment | Agent Runtime, Cloud Run |
--list | List existing deployments and exit | All |
--dry-run / -n | Print what would be executed without running it | All |
--no-confirm-project | Skip project confirmation prompt | All |
Run agents-cli deploy --help for the full flag reference.
Advanced Cloud Run Deploys: If you need features not exposed via
agents-cliflags, use--dry-run(or-n) to print the fullgcloudcommand, copy it, and add additional arguments as needed.
Project Confirmation: If the project is resolved automatically (not passed via
--project), the command will prompt for confirmation in interactive mode. Since agents typically run in non-interactive mode, you MUST pass--no-confirm-projectto proceed if you are relying on automatic project resolution.
Defaults (same on Agent Runtime, Cloud Run, and the generated service.tf): --cpu 1, --memory 4Gi, --num-workers 1, --concurrency 8, --min-instances 1, --max-instances 10.
The params are coupled — scale them together:
--num-workers with --cpu (e.g. --cpu 4 → --num-workers 4) or you pay for idle cores.concurrency × per-request memory. Memory — not CPU — is the first limit, so raising --concurrency without --memory is the main OOM cause.8 protects a memory-heavy (RAG/multimodal) agent. Light agents can raise it to 16–32+ after load-testing. See Underutilized asynchronous workers.# 4x throughput: scale every param, not just one
agents-cli deploy --cpu 4 --num-workers 4 --concurrency 16 --memory 16GiTune with the scaffolded load test (tests/load_test/, run locally or in the CI/CD staging pipeline): drive load, watch max latency and memory/OOM restarts, then adjust — high max latency → raise concurrency (+ workers/cpu); OOM → raise memory or lower concurrency.
--num-workersis Agent-Runtime-only (Cloud Run runs one uvicorn process). On GKE these flags are rejected — size via the Terraform manifests + HorizontalPodAutoscaler underdeployment/terraform/.
For the full CI/CD pipeline setup guide — prerequisites, infra cicd flags, runner comparison, WIF authentication, pipeline stages, and production approval — see references/cicd-pipeline.md.
For detailed infrastructure configuration (scaling defaults, Dockerfile, FastAPI endpoints, session types, networking), see references/cloud-run.md. For ADK docs on Cloud Run deployment, fetch https://adk.dev/deploy/cloud-run/index.md.
For event-driven / ambient agent deployment on Cloud Run, see the ambient-expense-agent sample and /google-agents-cli-adk-code (references/adk-python.md, section "12. Event-Driven / Ambient Agents") for the trigger_sources pattern.
Agent Runtime is a managed Vertex AI service for deploying Python ADK agents. Uses container-based deployment: agents-cli deploy packages your project and Agent Engine builds the image from your project's Dockerfile (required) — the same fast_api_app:app image that serves Cloud Run and GKE.
No
gcloudCLI exists for Agent Runtime. Deploy viaagents-cli deploy. Query via the Pythonvertexai.ClientSDK.
Deployments can take 5-10 minutes. Use --no-wait to start a deployment and return immediately, then check on it later with --status:
# Start deployment without blocking
agents-cli deploy --no-wait
# Check on progress later
agents-cli deploy --statusWhen --status detects the operation has completed, it writes deployment_metadata.json and prints the same success output as a normal deploy.
For detailed infrastructure configuration (container deploy flow, the unified FastAPI app and /api passthrough, Terraform resource, deployment metadata, session/artifact services, CI/CD differences), see references/agent-runtime.md. For ADK docs on Agent Runtime deployment, fetch https://adk.dev/deploy/agent-runtime/index.md.
For detailed infrastructure configuration (Kubernetes manifests, Terraform resources, Workload Identity, session types, networking), see references/gke.md. For ADK docs on GKE deployment, fetch https://adk.dev/deploy/gke/index.md.
Scaffolded projects use two service accounts:
app_sa (per environment) — Runtime identity for the deployed agent. Roles defined in deployment/terraform/iam.tf.cicd_runner_sa (CI/CD project) — CI/CD pipeline identity (GitHub Actions / Cloud Build). Lives in the CI/CD project (defaults to prod project), needs permissions in both staging and prod projects.Check deployment/terraform/iam.tf for exact role bindings. Cross-project permissions (Cloud Run service agents, artifact registry access) are also configured there.
Common 403 errors:
cicd_runner_sa missing deployment role in the target projectiam.serviceAccountUser binding on app_saapp_sa missing secretmanager.secretAccessorroles/cloudsql.clientroles/secretmanager.admin granted to the Cloud Build service account (service-<PROJECT_NUMBER>@gcp-sa-cloudbuild.iam.gserviceaccount.com) in the CI/CD project. This allows Cloud Build to access the GitHub token stored in Secret Manager.The following Google Cloud APIs must be enabled in your project for the skills and deployment to work:
cloudbuild.googleapis.com — Required for building container images and running CI/CD pipelines.secretmanager.googleapis.com — Required for managing secrets and API keys.run.googleapis.com — Required for deploying to Cloud Run.Ensure these are enabled before running deployment or CI/CD setup commands:
gcloud services enable cloudbuild.googleapis.com secretmanager.googleapis.com run.googleapis.com --project=YOUR_PROJECT_IDInstead of passing sensitive keys as environment variables, use GCP Secret Manager.
# Create a secret
echo -n "YOUR_API_KEY" | gcloud secrets create MY_SECRET_NAME --data-file=-
# Update an existing secret
echo -n "NEW_API_KEY" | gcloud secrets versions add MY_SECRET_NAME --data-file=-Grant access: For Cloud Run, grant secretmanager.secretAccessor to app_sa. For Agent Runtime, grant it to the platform-managed SA (service-PROJECT_NUMBER@gcp-sa-aiplatform-re.iam.gserviceaccount.com). For GKE, grant secretmanager.secretAccessor to app_sa. Access secrets via Kubernetes Secrets or directly via the Secret Manager API with Workload Identity.
Pass secrets at deploy time (Agent Runtime, Cloud Run):
agents-cli deploy --secrets "API_KEY=my-api-key,DB_PASS=db-password:2"Format: ENV_VAR=SECRET_ID or ENV_VAR=SECRET_ID:VERSION (defaults to latest). Access in code via os.environ.get("API_KEY").
When using Cloud SQL with Cloud Run in a manual deployment (e.g., adding --add-cloudsql-instances in non-Terraform setups), you must manually grant the Cloud SQL Client role to the runtime service account.
Without this, the deployment may succeed but fail at runtime with cloudsql.instances.get authorization errors.
gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \
--member="serviceAccount:YOUR_RUNTIME_SA_EMAIL" \
--role="roles/cloudsql.client"Note: In full Terraform-managed setups (
infra cicd/infra single-project), this role is configured and managed automatically.
See the agents-cli-observability skill for observability configuration (Cloud Trace, prompt-response logging, BigQuery Analytics, third-party integrations).
The quickest way to test a deployed agent is agents-cli run --url <service-url> --mode <a2a|adk> "your prompt" — it handles auth, sessions, and streaming automatically (supports Agent Runtime and Cloud Run).
For advanced testing (custom headers, session reuse, scripting, load tests), see references/testing-deployed-agents.md.
IAP (Identity-Aware Proxy) secures a Cloud Run service so only authorized Google accounts can access it. Enable it by adding the --iap flag when deploying (Cloud Run only): agents-cli deploy --iap.
For Agent Runtime with a custom frontend, use a decoupled deployment — deploy the frontend separately to Cloud Run or Cloud Storage, connecting to the Agent Runtime backend API.
For more information on IAP with Cloud Run, see the Cloud Console IAP settings.
The primary rollback mechanism is git-based: fix the issue, commit, and push to main. The CI/CD pipeline will automatically build and deploy the new version through staging → production.
For immediate Cloud Run rollback without a new commit, use revision traffic shifting:
gcloud run revisions list --service=SERVICE_NAME --region=REGION
gcloud run services update-traffic SERVICE_NAME \
--to-revisions=REVISION_NAME=100 --region=REGIONAgent Runtime doesn't support revision-based rollback — fix and redeploy via agents-cli deploy.
For GKE rollback, use kubectl rollout undo:
kubectl rollout undo deployment/DEPLOYMENT_NAME -n NAMESPACE
kubectl rollout status deployment/DEPLOYMENT_NAME -n NAMESPACECRITICAL: When your agent requires custom infrastructure (Cloud SQL, Pub/Sub, Eventarc, BigQuery, etc.), you MUST define it in Terraform — never create resources manually via gcloud commands. Exception: quick experimentation is fine with gcloud or console, but production infrastructure must be in Terraform.
For custom infrastructure patterns, consult references/terraform-patterns.md for:
| Issue | Solution |
|---|---|
| Terraform state locked | terraform force-unlock -force LOCK_ID in deployment/terraform/ |
| GitHub Actions auth failed | Re-run terraform apply in CI/CD terraform dir; verify WIF pool/provider |
| Cloud Build authorization pending | Use github_actions runner instead |
| Resource already exists | terraform import (see references/terraform-patterns.md) |
| Agent Runtime deploy timeout / hangs | Deployments take 5-10 min; check if engine was created (see Agent Runtime Specifics) |
| Secret not available | Verify secretAccessor granted to app_sa (not the default compute SA) |
| Cloud SQL connection failed / 403 | Grant roles/cloudsql.client to the runtime service account when using manual deployments |
| 403 on deploy | Check deployment/terraform/iam.tf — cicd_runner_sa needs deployment + SA impersonation roles in the target project |
| 403 when testing Cloud Run | Default is --no-allow-unauthenticated; include Authorization: Bearer $(gcloud auth print-identity-token) header |
| Cold starts too slow | Set min_instance_count > 0 in Cloud Run Terraform config |
| Cloud Run 503 errors | Check resource limits (memory/CPU), increase max_instance_count, or check container crash logs |
| 403 right after granting IAM role | IAM propagation is not instant — wait a couple of minutes before retrying. Don't keep re-granting the same role |
| Resource seems missing but Terraform created it | Run terraform state list to check what Terraform actually manages. Resources created via null_resource + local-exec (e.g., BQ linked datasets) won't appear in gcloud CLI output |
| Deployment failed or agent not responding | Check Cloud Logging: gcloud logging read "resource.type=cloud_run_revision AND resource.labels.service_name=SERVICE" --project=PROJECT --limit=50 --format="table(timestamp,severity,textPayload)" for Cloud Run, or gcloud logging read "resource.type=aiplatform.googleapis.com/ReasoningEngine" --project=PROJECT --limit=50 for Agent Runtime |
| Agent returns errors after deploy | Open Cloud Logging in Console → filter by service name (Cloud Run) or reasoning engine resource (Agent Runtime) → look for Python tracebacks or permission errors in recent log entries |
For registering deployed agents with Gemini Enterprise, see /google-agents-cli-publish.
/google-agents-cli-workflow — Development workflow, coding guidelines, and operational rules/google-agents-cli-adk-code — ADK Python API quick reference for writing agent code/google-agents-cli-eval — Evaluation methodology, dataset schema, and the eval-fix loop/google-agents-cli-scaffold — Project creation and enhancement with agents-cli scaffold create / scaffold enhance/google-agents-cli-observability — Cloud Trace, logging, BigQuery Analytics, and third-party integrations/google-agents-cli-publish — Gemini Enterprise registration© pifferologo, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (references) in skills/google-agents-cli-deploy of pifferologo/cloud-agents-cli.
Open the folder on GitHubat commit 5957f5a
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in pifferologo/cloud-agents-cli, which our catalogue first saw on October 7, 2026.
Google Agents CLI Deploy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Google Agents CLI Deploy this skillpifferologo/cloud-agents-cli | 129 | 1 repos | ~6k | Automated safety check: Pass | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 259 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| CI CDEliasOulkadi/shokunin | 114 | — | ~3.4k | Automated safety check: Notes | MIT | |
| DeployingGoogleCloudPlatform/race-condition | 234 | — | ~3k | Automated safety check: Pass | Custom licence | |
| CI/CD Pipeline Principlesirahardianto/awesome-agv | 157 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Devops Deploysickn33/agentic-awesome-skills | 47k | 2 repos | ~1.9k | Automated safety check: Pass | MIT |
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
EliasOulkadi/shokunin
Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…
GoogleCloudPlatform/race-condition
Guides deployment of Race Condition to a GCP project. An agent skill from GoogleCloudPlatform/race-condition.
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
sickn33/agentic-awesome-skills
DevOps e deploy de aplicacoes — Docker, CI/CD com GitHub Actions, AWS Lambda, SAM, Terraform, infraestrutura como codigo e monitoramento.
google/skills
Guides the migration of existing AI workloads (Cloud Run, Gemini API, Gemini Enterprise Agent Platform) to self-hosted GKE inference using gcloud and kubectl.
pifferologo/cloud-agents-cli
This skill should be used when the user wants to "write agent code", "build an agent with ADK", "add a tool", "create a callback", "define an agent", "use state management", or needs ADK (Agent…
pifferologo/cloud-agents-cli
This skill should be used when the user wants to "set up tracing", "monitor my ADK agent", "configure logging", "add observability", "debug production traffic", or needs guidance on monitoring…
pifferologo/cloud-agents-cli
This skill should be used when the user wants to "create an agent project", "start a new ADK project", "build me a new agent", "add CI/CD to my project", "add deployment", "enhance my project", or…
pifferologo/cloud-agents-cli
This skill should be used when the user wants to "run an evaluation", "evaluate my ADK agent", "write an eval dataset", "analyze eval failures", "compare eval results", "optimize agent", or needs…
pifferologo/cloud-agents-cli
This skill should be used when the user wants to "publish an agent", "publish my ADK agent", "register an agent with Gemini Enterprise", "publish to Gemini Enterprise", or needs guidance on the…
pifferologo/cloud-agents-cli
This skill should be used when the user wants to "develop an agent", "build an agent using ADK", "run the agent locally", "debug agent code", "test an agent", "deploy an agent", "publish an agent"…
Categories
This skill should be used when the user wants to "deploy an agent", "deploy my ADK agent", "set up CI/CD", "configure secrets", "troubleshoot a deployment", or needs guidance on Agent Runtime, Cloud…. Google Agents CLI Deploy is an agent skill from pifferologo/cloud-agents-cli. This skill should be used when the user wants to "deploy an agent", "deploy my ADK agent", "set up CI/CD", "configure secrets", "troubleshoot a deployment", or needs guidance on Agent Runtime, Cloud Run, or GKE deployment targets.
Google Agents CLI Deploy fits situations like: wants to deploy an agent; deploy my ADK agent; configure secrets; troubleshoot a deployment.
Run `npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a claude-code`. Or copy the skill folder (skills/google-agents-cli-deploy in pifferologo/cloud-agents-cli) into .claude/skills/google-agents-cli-deploy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a codex`. Or copy the skill folder (skills/google-agents-cli-deploy in pifferologo/cloud-agents-cli) into .agents/skills/google-agents-cli-deploy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pifferologo/cloud-agents-cli --skill google-agents-cli-deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-agents-cli-deploy, .gemini/skills/google-agents-cli-deploy, .github/skills/google-agents-cli-deploy and .opencode/skills/google-agents-cli-deploy in your project.
Going by SKILL.md and its folder, Google Agents CLI Deploy needs the command-line tools its instructions call (gcloud, terraform, kubectl and uv) and credentials named API_KEY and NEW_API_KEY. Our summary lists: Python 3; Docker.
SKILL.md names 5 domains. In commands or code: adk.dev; the agent is likely to contact it when it follows the instructions. As links in the text: docs.cloud.google.com, docs.astral.sh, github.com and cloud.google.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Google Agents CLI Deploy is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Google Agents CLI Deploy: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars), CI CD (EliasOulkadi/shokunin, 114 stars), Deploying (GoogleCloudPlatform/race-condition, 234 stars) and CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
pifferologo (a GitHub user) maintains it in pifferologo/cloud-agents-cli, which has 129 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on September 3, 2026.
Source: pifferologo/cloud-agents-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.