本文へ移動
cccskills
無料GitHub で公開

google-cloud-solution-multi-agent-security

Designs, deploys, and secures Google Cloud Agent Gateway solutions. Use when the user needs to configure multi-agent security, ingress (CLIENT_TO_AGENT), or egress (AGENT_TO_ANYWHERE) patterns involving Model Armor, IAP, and Agent Registry. Don't use for general Cloud Load Balancing or basic VPC setup not related to Agent Gateways.

インストール方法を見る

含まれるファイル(23)

  • SKILL.md14.4 KB
  • assets/agw-authz-extension.yaml275 B
  • assets/agw-authz-policy.yaml325 B
  • assets/agw-egress-config-run.yaml530 B
  • assets/agw-egress-config.yaml247 B
  • assets/agw-ingress-config.yaml255 B
  • assets/iap-policy-multi-agent.json590 B
  • assets/iap-policy.json469 B
  • assets/main.tf2.4 KB
  • assets/model-armor-advanced.yaml386 B
  • assets/model-armor-config.yaml353 B
  • assets/model-armor-payload.json101 B
  • assets/sgp-policy.yaml311 B
  • scripts/create_gke_dns_record.sh287 B
  • scripts/deploy_infrastructure.sh1.0 KB
  • scripts/enforce_sgp_patch.sh548 B
  • scripts/fix_egress_iap.sh226 B
  • scripts/hybrid_vpn_agent.py1.2 KB
  • scripts/multi_agent_cloud_run.py1.7 KB
  • scripts/register_cloud_run_services.sh1.0 KB
  • scripts/validate_ingress_unauth.sh433 B
  • scripts/verify_egress_policies.py797 B
  • scripts/verify_ingress_auth.sh483 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Agent Gateway multi-agent security

Critical Enforcement Rules & Rationale

  • Gcloud Release Tracks: Always use the exact release tracks specified in the commands (e.g., gcloud beta network-services agent-gateways). Omitting these prefixes causes commands to fail because Agent Gateway features are located in specialized, non-default namespaces.
  • API Enablement: Include modelarmor.googleapis.com in the API enablement list when setting up guardrails. Excluding it prevents Model Armor policies and filters from successfully attaching to the Gateway.
  • Egress Verification: Egress policy verification requires using the Python script (scripts/verify_egress_policies.py), not curl. Egress gateways rely on runtime SDK lifecycle handling and JWT context that a standard curl command cannot simulate correctly.
  • Model Armor Keys: In model-armor-config.yaml, always include both piAndJailbreakFilterSettings and sdpFilterSettings (filterEnforcement: ENFORCE). Invalid or missing filters cause deployment validation failures or lead to silent bypasses of the guardrails.
  • Subnet Private Access: Any subnet hosting a Private Service Connect network attachment for Egress Gateways must have private_ip_google_access = true enabled in Terraform. Disabling this blocks connectivity to Google-managed endpoints, causing total routing failures for agents.
  • Direct Delivery: Immediately provide the requested architecture, configuration files, CLI commands, scripts, and diagrams in full. Do not stop at a planning phase, do not generate a plan artifact, and do not ask for user confirmation before delivering outputs.
  • No Infrastructure Execution: Do not attempt to run deployment or verification commands (such as gcloud, kubectl, terraform, or curl) against real cloud resources during design. You are generating plan configurations, not executing them.

[!IMPORTANT] Just-In-Time (JIT) Resource Loading Protocol: Inspect template files in assets/ and executable scripts in scripts/ using view_file as needed for extended configurations, deployment scripts, and test suites.


Quick Reference: Required Filenames

Always generate files with these exact names when requested:

  1. agw-ingress-config.yaml (assets/agw-ingress-config.yaml)
  2. agw-egress-config.yaml (assets/agw-egress-config.yaml)
  3. agw-authz-extension.yaml (assets/agw-authz-extension.yaml)
  4. agw-authz-policy.yaml (assets/agw-authz-policy.yaml)
  5. model-armor-config.yaml (assets/model-armor-config.yaml)
  6. sgp-policy.yaml (assets/sgp-policy.yaml)
  7. iap-policy.json (assets/iap-policy.json)
  8. model-armor-payload.json (assets/model-armor-payload.json)

1. Dual Ingress & Egress Architecture Design (dual_ingress_egress_architecture_design)

  • Ingress Pattern: CLIENT_TO_AGENT fronted by Ingress Control Plane (Agent Gateway, Model Armor).

  • Egress Pattern: AGENT_TO_ANYWHERE utilizing Egress Control Plane (Agent Gateway, roles/iap.egressor CEL policies, Cloud DNS) and Egress Data Plane (PSC Interface, Cloud Run, PSC Google APIs Global Endpoint), coordinated via Agent Registry & Agent Engine runtime.

  • Mermaid Diagram:

    graph TD
        Client["External Clients"] -->|HTTPS / MCP| GLB["Global Load Balancer"]
        GLB --> Ingress["Ingress Agent Gateway (CLIENT_TO_AGENT)"]
        Ingress --> MA["Model Armor (CONTENT_AUTHZ)"]
        MA --> Agent["Agent Engine Agents (BillingAgent, SupportAgent, FraudAgent)"]
        Agent --> Egress["Egress Agent Gateway (AGENT_TO_ANYWHERE)"]
        Egress --> PSC["Private Service Connect Network Attachment"]
        PSC --> Tools["Private MCP Tool Backends"]
    

2. Ingress & Egress Guardrail Policy Config (ingress_and_egress_guardrail_policy_config)

When requested for Ingress & Egress guardrail policy configs, you MUST generate and create all required files in the workspace:

  • agw-ingress-config.yaml (assets/agw-ingress-config.yaml): Declares governedAccessPath: CLIENT_TO_AGENT with protocols HTTP and MCP.
  • agw-egress-config.yaml (assets/agw-egress-config.yaml): Declares governedAccessPath: AGENT_TO_ANYWHERE with protocol MCP.
  • agw-authz-extension.yaml (assets/agw-authz-extension.yaml): Configures AuthzExtension service for IAP authorization.
  • agw-authz-policy.yaml (assets/agw-authz-policy.yaml): Configures AuthzPolicy action ALLOW targeting both Ingress and Egress gateways.
  • iap-policy.json (assets/iap-policy.json): Binds roles/iap.egressor with CEL condition checking iap.googleapis.com/mcp.toolName == 'get_account_balance' && iap.googleapis.com/mcp.tool.isReadOnly == true.
  • model-armor-config.yaml (assets/model-armor-config.yaml): Enables piAndJailbreakFilterSettings and sdpFilterSettings with filterEnforcement: ENFORCE.
  • sgp-policy.yaml (assets/sgp-policy.yaml): Implements Natural Language Constraints blocking transactions > $1000 and sanitizing PII.

3. Ingress & Egress Infrastructure Deployment (ingress_and_egress_infrastructure_deployment)

Inspect and provide the step-by-step gcloud CLI commands from scripts/deploy_infrastructure.sh:

  1. Enable Required APIs: compute, networkservices, networksecurity, modelarmor, iap, agentregistry, serviceextensions, and aiplatform.
  2. Import Agent Gateways: Ingress (agw-ingress-config.yaml) and Egress (agw-egress-config.yaml) via gcloud alpha network-services agent-gateways import.
  3. Import Authz Extension: agw-authz-extension.yaml via gcloud beta service-extensions authz-extensions import.
  4. Import Authz Policy: agw-authz-policy.yaml via gcloud beta network-security authz-policies import.

4. Ingress & Egress Security Validation (ingress_and_egress_security_validation)

When validating security for Ingress and Egress:

  1. Ingress 403 Unauthenticated Test: Provide the copy-pasteable verification curl command from scripts/validate_ingress_unauth.sh sending an unauthenticated POST request to the Reasoning Engine endpoint expecting HTTP 403 Forbidden.
  2. Python Egress Verification Script (MUST use Python script snippet, NOT curl): Provide the Python verification script snippet from scripts/verify_egress_policies.py sending JSON-RPC tools/call requests (get_account_balance) through the Egress Gateway to verify HTTP 200 for allowed tools.
  3. Model Armor Test Payload: Generate model-armor-payload.json (assets/model-armor-payload.json) containing prompt injection/jailbreak instructions.

5. Troubleshooting Ingress & Egress Failures (troubleshooting_ingress_and_egress_failures)

  • Ingress 403 (Client-to-Agent):

    • Root Cause: Unauthenticated client requests or missing/invalid OAuth 2.0 / IAP identity tokens.
    • OAuth Configuration Steps:
      1. Configure OAuth 2.0 Client ID credentials in Google Cloud Console.
      2. Grant the client identity / service account roles/iap.httpsResourceAccessor permission.
      3. Exchange credentials with Google OAuth to acquire an OIDC / OAuth ID token.
      4. Pass the token in the Authorization: Bearer <TOKEN> header.
    • Verification Command: Provide the curl command from scripts/verify_ingress_auth.sh.
  • Egress 403 (Agent-to-Anywhere):

    • Root Cause: Missing roles/iap.egressor IAM bindings on the Agent Identity, malformed principal ID, or mismatched CEL condition on tool metadata.
    • Fix Command: Provide the exact gcloud command from scripts/fix_egress_iap.sh.

6. Hybrid VPN Connectivity & Egress Routing (hybrid_vpn_connectivity_egress_routing)

  • Terraform HCL: Refer to baseline Terraform config in assets/main.tf for VPC, subnets (private_ip_google_access = true), PSC network attachment, Cloud DNS private forwarding for aws.internal., and HA VPN gateway/router.
  • Egress Gateway Config (agw-egress-config.yaml): Generate configuration declaring governedAccessPath: AGENT_TO_ANYWHERE, pointing to the PSC network attachment, and referencing aws.internal. in dnsPeeringConfig (see assets/agw-egress-config.yaml).
  • Python SDK Deployment Script: Refer to scripts/hybrid_vpn_agent.py for the complete script initializing Vertex AI with agent_to_anywhere_config referencing the Egress Gateway, enabling telemetry, and deploying HybridAgent using types.IdentityType.AGENT_IDENTITY.

7. Private Egress GKE Internal Load Balancer (private_egress_gke_internal_load_balancer)

  • Expose GKE internal MCP tool server via an Internal Load Balancer (ILB) at literal IP 10.0.1.50, connecting via Agent Gateway PSC Interface + Cloud DNS Private zone.
  • Cloud DNS Record Mapping: Provide the command from scripts/create_gke_dns_record.sh mapping the private domain to GKE's private ILB IP 10.0.1.50.
  • Explicit TLS Warning: Agent Gateway egress does not natively trust self-signed certificates or private enterprise CAs. You must use publicly trusted TLS certificates signed by a trusted Certificate Authority (e.g., Let's Encrypt).

8. Governance Controls Model Armor SGP (governance_controls_model_armor_sgp)

When configuring dual safety layers with Model Armor on Ingress and SGP on Egress:

  1. Model Armor Config: Generate model-armor-config.yaml (assets/model-armor-config.yaml) with piAndJailbreakFilterSettings and sdpFilterSettings (filterEnforcement: ENFORCE).
  2. Semantic Governance Policy: Generate sgp-policy.yaml (assets/sgp-policy.yaml) with Natural Language Constraints blocking transactions > $1000 and sanitizing PII.
  3. Curl PATCH Command: Provide the curl command from scripts/enforce_sgp_patch.sh to update authzExtensions with sgpEnforcementMode set to ENFORCE.

9. Multi-Agent Cloud Run Egress Routing (multi_agent_cloud_run_egress_routing)

Do NOT produce a plan artifact or stop at planning. When configuring multi-agent Cloud Run egress routing, you MUST directly provide and generate ALL required components:

  1. Egress Gateway Config (agw-egress-config-run.yaml): Generate configuration declaring governedAccessPath: AGENT_TO_ANYWHERE, PSC network attachment, and DNS peering for *.run.app (see assets/agw-egress-config-run.yaml).
  2. Register Cloud Run Services in Agent Registry: Provide the registration commands from scripts/register_cloud_run_services.sh registering all 3 Cloud Run services (marketing-tool-service, sales-tool-service, support-tool-service) in the us-east4 Agent Registry.
  3. iap-policy.json (Multi-Agent): Generate iap-policy.json (assets/iap-policy-multi-agent.json) containing all 3 principal:// bindings in the members list under roles/iap.egressor.
  4. Python SDK Deployment Script: Refer to scripts/multi_agent_cloud_run.py for the complete GenAI SDK deployment script.

10. Advanced Model Armor Filtering (advanced_model_armor_filtering)

For custom keyword matching, configure userDefinedFilterSettings (see assets/model-armor-advanced.yaml).


11. Known Traps & Gotchas (known_traps_and_gotchas)

  • network_attachment is ForceNew: Enabling Semantic Governance Policies (SGP) or modifying network attachments after the initial Terraform apply will force-recreate the gateway resource. If not managed carefully, this can cause dependency deadlocks during destroy operations. Plan infrastructure sequencing accordingly.
  • Authz Policy Limit: An Agent Gateway allows at most 4 custom authorization policies attached concurrently. Ensure your security posture consolidates rules within this limit.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for standard infrastructure monitoring unrelated to AI agents, or when the agent is not instrumented with OpenTelemetry (for Reliability, Cost, Safety, Security alerts). NOTE: Reliability, Cost, Safety, and Security alerts use generic OTel metrics and work across runtimes (such as Cloud Run, Vertex AI). Quality alerts rely on Vertex AI Online Monitors and are strictly bound to Vertex AI deployments.

日本語の概要は準備中です。原文の説明を表示しています。

google/skills2.1万2026年10月10日 更新

Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available models, check if a specific model is deployable (`gcloud ai model-garden models list-deployment-config`), query deployment cost, troubleshoot deployment errors (like quota limits), or undeploy/clean up endpoints. Also use when copying and deploying a 1P Tuned Model. Don't use for pure listing/discovery questions of the form "is X deployed?", "list my endpoints", or "which regions have models running?" — for those use `agent-platform-endpoint-management`. Don't use for running model evaluations (use `agent-platform-eval-flywheel` skill).

日本語の概要は準備中です。原文の説明を表示しています。

google/skills2.1万2026年10月10日 更新

Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for running model evaluations.

日本語の概要は準備中です。原文の説明を表示しています。

google/skills2.1万2026年10月10日 更新

Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results before and after a fix, or when guidance is needed on Agent Platform eval methodology — including dataset schema, LLM-as-judge scoring, and common failure causes. For fine-tuning, use agent-platform-tuning. For general production deployment, use agent-platform-deploy.

日本語の概要は準備中です。原文の説明を表示しています。

google/skills2.1万2026年10月10日 更新

Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate code for calling Gemini or OpenMaaS models, authenticate with GenAI SDK, OpenAI SDK, or legacy Agent Platform SDK, configure base URLs and global/regional endpoints, or troubleshoot 429 Resource Exhausted (DSQ), 400 User Validation, or 404 Not Found errors. Don't use for deploying models to endpoints or for running model evaluations.

日本語の概要は準備中です。原文の説明を表示しています。

google/skills2.1万2026年10月10日 更新

Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry).

日本語の概要は準備中です。原文の説明を表示しています。

google/skills2.1万2026年10月10日 更新

google のスキルをすべて見る

このスキルの問題を報告する