Skip to main content

Google Cloud

Shanone’s Google Cloud integration gives your agent 24 tools for operator-level GCP administration — enabling/disabling services, managing IAM policies and roles, and auditing organization-level changes — authenticated via Workload Identity Federation rather than a downloadable service account key.

Getting Started

1

Set up Workload Identity Federation

In Google Cloud Console, create a Workload Identity Pool and Provider that trusts Shanone’s backend, and create a service account for Shanone to impersonate.
2

Add the WIF details in Shanone

Open Integrations in the Shanone dashboard, select Google Cloud, and enter the project number, pool ID, provider ID, service account email, and target project ID. No service account key file is needed.
3

Retry your request

Once saved, shanone_execute_tool calls for gcloud_* tools will succeed.

Available Tools

Shanone provides 24 tools for Google Cloud, organized into these categories:
gcloud_service_usage_list, gcloud_service_usage_get, gcloud_service_usage_batch_get, gcloud_service_usage_search, gcloud_service_usage_enable, gcloud_service_usage_disable, gcloud_service_usage_batch_enable, gcloud_service_usage_disable_check
gcloud_iam_get_policy, gcloud_iam_add_binding, gcloud_iam_remove_binding, gcloud_iam_set_policy, gcloud_iam_list_members
gcloud_iam_list_grantable_roles, gcloud_iam_get_role, gcloud_iam_test_permissions, gcloud_iam_list_service_accounts, gcloud_iam_search_roles
gcloud_org_get_policy, gcloud_org_add_binding, gcloud_org_list_projects
gcloud_audit_get_connection_status, gcloud_audit_list_recent_changes, gcloud_audit_export_policy_snapshot

Common Use Cases

API enablement rollout

Batch-enable a set of required APIs across a project before deploying a new service

IAM access review

List IAM policy bindings and members on a project to check for overly broad access

Permission troubleshooting

Use gcloud_iam_test_permissions to confirm whether a service account actually has the access a failing call needs

Change auditing

Export a policy snapshot and list recent changes to investigate who modified IAM bindings

Troubleshooting

Run gcloud_audit_get_connection_status first — it’s the fastest way to confirm the Workload Identity Federation trust relationship and impersonated service account are configured correctly.
The impersonated service account itself needs resourcemanager.projects.setIamPolicy (or the organization equivalent) — check its own IAM role with gcloud_iam_get_policy on the target resource.
Enabling a service can take a minute or two to propagate — poll gcloud_service_usage_get or gcloud_service_usage_disable_check rather than assuming it’s instantly active.