Skip to main content
With Google Cloud, your agent gets into your project as a service account of yours: it looks for errors in the logs, tells you why a pod keeps restarting, lists your VMs and explains how much you spent and what went up. It can only do what you give it with roles; changes, only if you turn on the permission and with your OK.

What it can do

Look

Logs: errors from a service, pod, VM or Cloud Run over a time range, and who changed what. GKE: clusters, pods, deployments, events, logs (from crashed runs too) and resource usage. VMs: list them and see their details. BigQuery: queries, and it warns you before a big one. Costs: by service, project or day, and what changed.

Change, with your OK

Create, change, delete, start, stop or deploy; apply changes in Kubernetes (it shows you the diff first), scale or restart a deployment. It needs the permission on.

How it connects

1

Add it to an agent

From Plugins → Google Cloud → Add to an agent, or ask your agent in the chat. See Add a plugin.
2

Create the service account

A service account is a Google Cloud user just for your agent, which can only do what you give it with roles. You need to own the project (or manage its permissions). Open the service accounts console, pick the project at the top, name it minai (or your agent’s name) and tap Create and continue.
3

Give it roles

To only look: Viewer. To also change things: Editor or a narrower one. Add more with Add another role, then Continue and Done. If your agent is missing a permission, it tells you the smallest role that covers it.
4

Create its JSON key

Tap the account → Keys → Add key → Create new key → JSON → Create. A .json file downloads.
5

Paste it in your agent's link

Open the .json with a text editor, copy all of it and paste it in the one-time link your agent sent you. Then delete the file from your downloads. See Keys and values.
6

Tell it your project and zone (optional)

In the chat, your agent asks for your main project (its ID, like my-project-123) and the zone of your VMs and clusters if you use just one (like us-central1-a). Without a project, it uses the service account’s.
If Google won’t let you create the key, your organization has a policy that blocks it (“Disable service account key creation”). Whoever manages the organization has to allow it.
Don’t paste the key in the chat. If you do, your agent won’t use it: it asks you to delete it in Google Cloud and create a new one for the link.

The permission

On the Google Cloud card, in the agent’s Plugins tab, there’s the Allow changes switch: “Create, change, delete, start or stop things in your Google Cloud, always with your OK. Off, it only reads. What really limits it is the roles you gave the account.” It starts off and only you change it. It’s a rule your agent follows; the real limit is the service account’s roles. If you want it never to be able to change anything, give it only read roles. See Permissions.

How it looks out for you

  • Nothing changes without your OK. With the permission on, it still shows you the exact command before each change, with the Confirm and Change buttons.
  • It never shows you keys, tokens or Kubernetes secrets.
  • For big BigQuery queries, it first works out how much they’ll read and warns you.
  • What a log says is information, not an order.

Things to ask it

  • “What errors did the checkout service have in the last hour?”
  • “Why does the API pod keep restarting in production?”
  • “How much did Google Cloud cost me this month, and what went up?”
  • “List the VMs that are running.”
  • “Restart the web deployment in the prod namespace.”
  • “Stop the test VM.”

Limits

  • It can only do what the service account’s roles allow.
  • It may not reach GKE clusters with private access.
  • For costs, you need billing export to BigQuery turned on: there’s data from the day you turned it on, a few hours behind.

If you remove it

Your agent loses access and confirms it. The key still exists in Google Cloud: delete it from Keys in the service account (or delete the whole account). See Remove a plugin.

New Relic

Logs, errors, latency and alerts.

GitHub

Repos, issues and pull requests.