Catalog
google/workload-manager-basics

google

workload-manager-basics

Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API. Use when you need to inspect workload best-practice rules, create and run evaluations for Google Cloud general best practices, SAP, SQL Server, or custom organizational rules, review violations, export results to BigQuery, or automate Workload Manager through client libraries because no service-specific public CLI or MCP server is available. Don't use for general Google Compute Engine instance management, VPC configuration, or standard IAM auditing.

global
category:CloudObservabilityAndMonitoring
New~1.7k
v1.1Saved Jun 29, 2026

Workload Manager Basics

Workload Manager validates enterprise workloads against Google Cloud best practices and recommendations. The public client libraries are centered on evaluations: define a resource scope, choose built-in or custom rules, run an evaluation, then inspect results and scanned resources.

Use This Flow

flowchart LR
    Rules["List rules"] --> Eval["Create or update evaluation"]
    Resources["Project, folder, or org scope"] --> Eval
    Eval --> Run["Run evaluation"]
    Run --> Results["Inspect evaluation results"]
    Results --> Remediate["Remediate findings"]
    Results --> Export["Optional BigQuery export"]

Core API Constraints

To ensure compatibility, security, and successful integration:

  • Public Surface Only: You MUST strictly interact with Workload Manager using the official public google-cloud-workloadmanager client library or the public REST API (workloadmanager.googleapis.com/v1).
  • No Internal or Undocumented APIs: Do NOT attempt to use internal RPC protocols, private service backends, or undocumented discovery mechanisms. They are not supported for public integrations and will fail.
  • No Service-Specific CLI: There is no public gcloud workload-manager CLI command group. Use gcloud only for authentication, IAM role assignment, and fetching raw REST tokens.
  • Sandbox Execution Robustness (Auth/Mock Fallbacks): When gcloud authentication or Workload Manager API calls fail in sandboxed or restricted environments (e.g., due to Context Aware Access token blocks, missing API enablement, or mock resources returning 404/403), immediately fall back to presenting example code and static findings from your references instead of entering retry loops. Present the correct client library code structure or REST API payload example, clearly explain the auth or resource limitation, and list typical rules or mock findings statically to satisfy the request.

Prerequisites

  1. Enable the Workload Manager API:

    gcloud services enable workloadmanager.googleapis.com --quiet
    
  2. Authenticate locally using Application Default Credentials (ADC) before using client libraries:

    gcloud auth application-default login
    
  3. Ensure the Workload Manager service agent has the required roles granted in your project (mandatory for API/client library usage, see IAM & Security).

  4. Grant the least-privileged role needed for the task. Start with roles/workloadmanager.viewer for read-only access to evaluation resources and use roles/workloadmanager.evaluationAdmin or roles/workloadmanager.admin only when creating, updating, running, or deleting evaluations.

Quick Client Library Example

Use the Python client library for the first working automation path:

python3 -m pip install --upgrade google-cloud-workloadmanager
from google.cloud import workloadmanager_v1

project_id = "PROJECT_ID"
location = "LOCATION"
parent = f"projects/{project_id}/locations/{location}"

client = workloadmanager_v1.WorkloadManagerClient()

rules = client.list_rules(
    request=workloadmanager_v1.ListRulesRequest(
        parent=parent,
        evaluation_type=workloadmanager_v1.Evaluation.EvaluationType.OTHER,
    )
)

for rule in rules.rules:
    print(rule.name, rule.display_name, rule.severity)

Reference Directory

  • Core Concepts: Evaluations, rules, results, scanned resources, supported workload types, and API shape.

  • General Best Practices: Google Cloud general best-practice posture checks, OTHER evaluation guidance, custom Rego rules, and scale/automation patterns.

  • Client Libraries: Python and Go client library examples for listing rules, creating evaluations, running evaluations, and reading findings.

  • REST Usage: Direct REST examples for the public Workload Manager API and operations polling.

  • Public CLI Status: No documented service-specific gcloud workload-manager command group; use gcloud only for auth, IAM, API enablement, and REST tokens.

  • Public MCP Status: No documented public Workload Manager MCP server; use client libraries or REST API instead.

  • Setup Prerequisites: Terraform examples only for adjacent prerequisites such as API enablement, IAM, BigQuery export datasets, and KMS keys. This is not Workload Manager resource management.

  • IAM & Security: Workload Manager roles, least-privilege guidance, service agents, data handling, and CMEK notes.

If product behavior or API fields are not covered here, check the current Workload Manager product documentation and client library reference before implementing.

Authoritative References

Additional Context

Files9
9 files · 49.9 KB

Select a file to preview

Overall Score

88/100

Grade

A

Excellent

Safety

90

Quality

88

Clarity

87

Completeness

84

Summary

This skill provides structured guidance for using Google Cloud Workload Manager through public client libraries (Python/Go) and REST APIs to create, run, and manage evaluations that validate enterprise workloads against Google Cloud best practices. It covers the full evaluation lifecycle—listing rules, creating scoped evaluations, running executions, reviewing findings, and exporting results to BigQuery—with clear API constraints, prerequisite setup, IAM guardrails, and fallback patterns for sandboxed environments.

Detected Capabilities

client library invocation (Python, Go)REST API calls (curl with Bearer token auth)gcloud command usage (auth, IAM, service enablement only)reading Cloud project and organization configurationBigQuery dataset integrationKMS key references

Trigger Keywords

Phrases that MCP clients use to match this skill to user intent.

workload manager evaluationsgoogle cloud posturebest practices validationsql server checkscustom rego rules

Risk Signals

INFO

gcloud auth print-access-token used in REST examples to obtain short-lived Bearer tokens

references/public-cli-status.md, references/rest-usage.md
INFO

gcloud services enable and gcloud projects add-iam-policy-binding used for prerequisite setup

references/public-cli-status.md
INFO

BigQuery destination and CMEK key references in evaluation configurations

references/client-library-usage.md, references/iam-security.md
INFO

Explicit guidance to use Application Default Credentials (ADC) and gcloud auth for local client library auth

SKILL.md (Prerequisites section)

Referenced Domains

External domains referenced in skill content, detected by static analysis.

discuss.google.devdocs.cloud.google.compypi.orgworkloadmanager.googleapis.comwww.apache.org

Use Cases

  • Create and run Workload Manager evaluations for SQL Server best practices validation
  • List and filter built-in Google Cloud general best-practice rules by evaluation type and severity
  • Build custom organizational rule evaluations using Rego and Cloud Storage buckets
  • Automate execution scheduling and BigQuery export of Workload Manager findings at organization or project scope
  • Debug and remediate Workload Manager API calls in sandboxed or Context Aware Access-restricted environments using provided code examples

Quality Notes

  • Excellent use of flowcharts and decision trees to visualize workflow and custom rule selection
  • Clear boundaries documented: 'Public Surface Only' constraint explicitly prohibits internal RPC protocols and undocumented APIs
  • Comprehensive reference directory with separate files for each domain (core concepts, IAM/security, REST usage, client library usage, CLI/MCP status)
  • Strong edge case handling: Sandbox Execution Robustness section provides explicit fallback patterns for auth failures and missing API enablement
  • Least-privilege IAM guidance with role selection table and clear recommendations to start read-only
  • Well-structured prerequisite examples (gcloud setup, Terraform for adjacent infrastructure) that avoid implying Terraform can manage Workload Manager resources
  • Client library examples use request_id for idempotency and include timeout handling for long-running operations
  • Practical guardrails section covers edge cases like binary files, empty diffs, and long-running operation polling
  • Reference material is current and points to official Google Cloud documentation (discuss.google.dev, docs.cloud.google.com)
  • Explicit note that there is no public CLI command group and no documented MCP server prevents user confusion and misuse
Model: claude-haiku-4-5-20251001Analyzed: Jun 29, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Version History

v1.1

Content updated

2026-06-28

Latest
v1.0

No changelog

2026-06-13

Use google/workload-manager-basics in your dev environment

Command Palette

Search for a command to run...