Google Cloud
Shanone’s Google Cloud integration gives your agent 24 tools for operator-level GCP administration — enabling/disabling services, managing IAM policies and roles, and auditing organization-level changes — authenticated via Workload Identity Federation rather than a downloadable service account key.Getting Started
1
Set up Workload Identity Federation
In Google Cloud Console, create a Workload Identity Pool and Provider that trusts Shanone’s backend, and create a service account for Shanone to impersonate.
2
Add the WIF details in Shanone
Open Integrations in the Shanone dashboard, select Google Cloud, and enter the project number, pool ID, provider ID, service account email, and target project ID. No service account key file is needed.
3
Retry your request
Once saved,
shanone_execute_tool calls for gcloud_* tools will succeed.Available Tools
Shanone provides 24 tools for Google Cloud, organized into these categories:Service usage
Service usage
gcloud_service_usage_list, gcloud_service_usage_get, gcloud_service_usage_batch_get, gcloud_service_usage_search, gcloud_service_usage_enable, gcloud_service_usage_disable, gcloud_service_usage_batch_enable, gcloud_service_usage_disable_checkIAM policy & members
IAM policy & members
gcloud_iam_get_policy, gcloud_iam_add_binding, gcloud_iam_remove_binding, gcloud_iam_set_policy, gcloud_iam_list_membersIAM roles & permissions
IAM roles & permissions
gcloud_iam_list_grantable_roles, gcloud_iam_get_role, gcloud_iam_test_permissions, gcloud_iam_list_service_accounts, gcloud_iam_search_rolesOrganization-level
Organization-level
gcloud_org_get_policy, gcloud_org_add_binding, gcloud_org_list_projectsAudit
Audit
gcloud_audit_get_connection_status, gcloud_audit_list_recent_changes, gcloud_audit_export_policy_snapshotCommon Use Cases
API enablement rollout
Batch-enable a set of required APIs across a project before deploying a new service
IAM access review
List IAM policy bindings and members on a project to check for overly broad access
Permission troubleshooting
Use
gcloud_iam_test_permissions to confirm whether a service account actually has the access a failing call needsChange auditing
Export a policy snapshot and list recent changes to investigate who modified IAM bindings
Troubleshooting
Every gcloud_* call fails immediately after connecting
Every gcloud_* call fails immediately after connecting
Run
gcloud_audit_get_connection_status first — it’s the fastest way to confirm the Workload Identity Federation trust relationship and impersonated service account are configured correctly.gcloud_iam_add_binding or gcloud_org_add_binding returns a permission-denied error
gcloud_iam_add_binding or gcloud_org_add_binding returns a permission-denied error
The impersonated service account itself needs
resourcemanager.projects.setIamPolicy (or the organization equivalent) — check its own IAM role with gcloud_iam_get_policy on the target resource.gcloud_service_usage_enable succeeds but the API isn't usable yet
gcloud_service_usage_enable succeeds but the API isn't usable yet
Enabling a service can take a minute or two to propagate — poll
gcloud_service_usage_get or gcloud_service_usage_disable_check rather than assuming it’s instantly active.