google/skills

gke-basics

- Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment.

Ver código-fonte
Documento original do Skill

Renderizado do repositório de origem, preservando títulos, exemplos, código, tabelas, links e imagens.

GKE Basics & Critical Gotchas

Managed Kubernetes platform on Google Cloud. Defaults to Autopilot mode unless Standard is explicitly required.

Key Selection Rules: Autopilot vs. Standard

  • Default to Autopilot for almost all workloads.
  • Use Standard ONLY if:
  • Custom node OS kernel parameters (sysctl) are required.
  • Custom node taints or specific hardware node pools are required.
  • DaemonSets require raw hostPath mounts to the host OS filesystem.
  • When explaining why Standard is required over Autopilot, explicitly cite all matching restrictions (e.g., custom sysctls and custom node taints).
  • For advanced cluster architecture or complex node pool creation planning, refer to `gke-cluster-creation`.

Critical Gotchas & Best Practices

  1. Private Autopilot Clusters:
  • Use --enable-private-nodes for private node IP addresses.
  • Use --enable-private-endpoint to disable public IP access to the control plane.
  • Restrict control plane access with --enable-master-authorized-networks and --master-authorized-networks=CIDR_BLOCK:
bash
     gcloud container clusters create-auto CLUSTER_NAME --region=REGION \
       --enable-private-nodes \
       --enable-private-endpoint \
       --enable-master-authorized-networks \
       --master-authorized-networks=CIDR_BLOCK
  1. Workload Identity (IAM Binding):
  • Never mount raw GCP Service Account JSON keys in Pods.
  • Annotate the Kubernetes ServiceAccount (KSA) to bind to the Google Service Account (GSA):
yaml
     metadata:
       annotations:
         iam.gke.io/gcp-service-account: GSA_NAME@PROJECT_ID.iam.gserviceaccount.com
  1. Autopilot Resource Requests:
  • In Autopilot, CPU requests must be specified in increments of 250m (0.25 vCPU). If an unaligned CPU request (e.g., 300m) is requested, round up to the nearest 250m increment (500m / 0.5 vCPU).
  • Resource requests equal limits automatically. Omit limits to allow Autopilot to set defaults matching requests.
  1. Cluster Credentials:
  • Always explicitly specify --region (for regional clusters) or --zone (for zonal clusters) when fetching credentials:
bash
     gcloud container clusters get-credentials CLUSTER_NAME --region=REGION --quiet

Reference Directory

  • Core Concepts: Architecture, cluster modes (Autopilot vs Standard), networking, scaling, and security model.
  • CLI Usage & Tool Reference: Tool preference hierarchy (MCP vs gcloud vs kubectl), gcloud container commands, and user preference overrides.
  • Client Libraries: Official Kubernetes and Google Cloud Container client libraries in Python, Go, Node.js, and Java.
  • MCP Usage: Connecting to and using the 23 structured GKE MCP tools for cluster management, K8s resources, and diagnostics.
  • Infrastructure as Code: Terraform examples for google_container_cluster (Autopilot), Kubernetes provider resources, and YAML samples.
do mesmo repositório

Mais Skills

Todos os Skills
google
Comunidade

google-analytics-admin-api-basics

- Manages Google Analytics account and property settings, enables the Analytics Admin API via the Cloud CLI, lists accounts and properties, and manages data streams, custom dimensions, conversion events, and integrations. Use when you need to programmatically configure Google Analytics accounts, provision properties, manage data retention, configure Measurement Protocol secrets, or manage Firebase and Google Ads links.

instalações
4
GitHub Stars
20,3 mil
Atualizado
22 de set.
google
Comunidade

gke-workload-security

- Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (auditcluster.sh), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (gVisor), enforcing Pod Security Standards (restricted labeling), and mounting Secret Manager secrets via CSI (SecretProviderClass). Use when auditing cluster security posture, isolating namespaces, applying pod security standards, setting up Workload Identity, or configuring network policies and secret volume mounts. Don't use for cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).

instalações
3
GitHub Stars
20,3 mil
Atualizado
22 de set.
google
Comunidade

google-ads-api-account-diagnostics

- Diagnoses Google Ads account performance issues such as conversion loss (value or volume), low lead flow/volume, and lost impression share (opportunities) due to ad rank, bids, or budgets. Use when troubleshooting sudden performance drops, analyzing campaign impression share metrics, investigating low lead flow, or searching for bidding and budget constraints. Don't use for setting up new campaigns, uploading conversion events directly, or general Google Mobile Ads SDK integration issues (use gma-android-integrate instead).

instalações
4
GitHub Stars
20,3 mil
Atualizado
22 de set.
google
Comunidade

google-ads-api-mcp-setup

Guides developers through downloading, configuring, and installing the official open-source Google Ads MCP Server. Use this skill when a user wants to connect their AI assistant (such as Gemini, Claude Code, or Cursor) to their Google Ads account to query campaigns or retrieve reporting metrics using natural language.

instalações
4
GitHub Stars
20,3 mil
Atualizado
22 de set.