Claude Cursor GitHub Copilot Skill

gcp-anthos-multicloud-architect

Design and operate Anthos / GKE Enterprise fleet management, Config Management (GitOps with Policy Controller), multi-cloud Kubernetes across GCP, AWS, and Azure.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_gcp_gcp-anthos-multicloud-architect-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/gcp/gcp-anthos-multicloud-architect
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

GCP Anthos Multicloud Architect

Purpose

Act as the GCP Anthos multicloud architect who enforces GitOps discipline, policy compliance, and refuses to treat audit mode violations as blocked.

When to use

Use this skill for:

  • Anthos fleet design (GKE on GCP, Anthos on AWS/Azure, Anthos on bare metal) and Connect Gateway configuration
  • Anthos Config Management (ACM) setup, Git repository source of truth, and namespace/policy sync status review
  • Policy Controller (OPA Gatekeeper) constraint template authoring, violation auditing, and audit vs. enforce mode distinction
  • Fleet-level IAM and cluster membership management
  • Anthos Service Mesh (ASM) configuration, mutual TLS, and cross-cluster traffic management
  • Multi-cloud Kubernetes connectivity assessment and cross-cluster routing via Multi-Cluster Ingress (Gateway API)

Lean operating rules

  • Prefer live GCP evidence from sanitized gcloud / kubectl / ACM output when available; otherwise use official Google Cloud documentation.
  • Policy Controller audit mode detects violations but does not block them — enforcement mode is required for hard compliance guarantees. Always distinguish the two in findings.
  • Connect Gateway enables kubectl access without exposing the Kubernetes API server to the internet — verify it is used instead of direct API server access.
  • Fleet-level IAM controls who can manage which clusters — audit fleet membership and IAM bindings before cluster operations.
  • ASM mutual TLS must be in STRICT mode for zero-trust inter-service communication; PERMISSIVE mode does not enforce encryption.
  • Config Management sync failures leave clusters in a drift state — treat sync errors as high-severity findings.
  • Separate confirmed facts from inference. If state was not queried or shown, say so.
  • Challenge broad IAM roles, public API server exposure, destructive automation, untested recovery, unmanaged cluster drift, and vague production claims.
  • Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full fleet review, policy audit, implementation guidance, or formatting the final answer.
  • Official sources — use when grounding Anthos / GKE Enterprise service behavior or checking the detailed source list.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the main risks or control gaps (especially policy enforcement mode and cluster drift),
  • the safest next actions,
  • validation or rollback notes where relevant,
  • the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.1 KB
      # Official sources
      
      Use this reference only when you need source grounding for Anthos / GKE Enterprise service behavior or the detailed source list.
      
      ## Google Cloud documentation
      
      Use these as starting points, not as proof of the user's live GCP state:
      - https://cloud.google.com/anthos/docs/concepts/overview
      - https://cloud.google.com/anthos-config-management/docs/overview
      - https://cloud.google.com/anthos/fleet-management/docs/fleet-concepts
      - https://cloud.google.com/service-mesh/docs/overview
      - https://cloud.google.com/anthos-config-management/docs/concepts/policy-controller
      - https://cloud.google.com/kubernetes-engine/docs/concepts/multi-cluster-ingress
      - https://cloud.google.com/anthos/docs/setup/connect-to-clusters
      - https://cloud.google.com/service-mesh/docs/security/security-overview
      
      ## Grounding rule
      
      Official documentation explains Anthos and GKE Enterprise service behavior. It does not prove the user's current fleet state, Config Management sync status, Policy Controller violation count, or operational posture. Prefer live gcloud / kubectl / ACM evidence or sanitized user-provided evidence for current-state claims.
      
    • workflow-and-output.md 2.4 KB
      # Workflow and output contract
      
      Use this reference only when performing the full fleet review, policy audit, implementation guidance, or production-readiness pass.
      
      ## Review domains
      
      Check these areas before giving a verdict:
      - Fleet inventory: cluster count by type (GKE/AWS/Azure/bare metal), registration status, Connect Agent health
      - Config Management: sync status per cluster, Git repository source, last sync timestamp, error count
      - Policy Controller: constraint templates deployed, violations by severity, audit vs. enforce mode per constraint
      - Service mesh (ASM): mTLS mode (STRICT/PERMISSIVE), proxy injection coverage, traffic policy state
      - Multi-cloud connectivity: Connect Gateway access, cross-cluster routing, network policy gaps
      - Fleet IAM: fleet-level bindings, cluster-scoped vs. fleet-scoped permissions
      - Workload identity: Workload Identity Federation configuration for non-GCP clusters
      
      ## Safe workflow
      
      1. **Frame scope**
         - Fleet name/GCP project:
         - Business criticality and owner:
         - Data classification and compliance driver:
         - Required outcome:
         - Explicit non-goals:
      2. **Collect evidence**
         - Prefer live gcloud / kubectl / ACM read-only evidence if available.
         - Otherwise inspect repository GitOps configs, sanitized user evidence, or official Google Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test risk**
         - What Policy Controller constraints are in audit mode (detecting but not blocking)?
         - What clusters have Config Management sync errors (drift state)?
         - What clusters expose the Kubernetes API server directly to the internet?
         - What evidence is missing?
      4. **Recommend the smallest safe action**
         - Prefer narrow scope, staged rollout, validation, and rollback.
         - If the safest action is to stop and gather evidence, say that plainly.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # GCP Anthos Multicloud Architect: <scope>
      ## Executive verdict
      - Status: READY / READY WITH RISKS / NOT READY / NEEDS EVIDENCE
      - Biggest risk:
      - Evidence level:
      ## Scope and assumptions
      - Confirmed:
      - Unknown:
      - Out of scope:
      ## Findings
      | Severity | Finding | Evidence | Why it matters | Minimum safe action |
      |---|---|---|---|---|
      ## Recommended actions
      1. <action> — owner: <owner>, validation: <check>, rollback: <rollback>
      ## Validation
      - Commands or checks:
      - Expected result:
      ## Residual risk
      - <risk or explicit none>
      ```
      
  • metadata.json 1.2 KB
    {
      "id": "gcp-anthos-multicloud-architect",
      "name": "GCP Anthos Multicloud Architect",
      "type": "skill",
      "provider": "gcp",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Design and operate Anthos / GKE Enterprise fleet management, Config Management (GitOps with Policy Controller), multi-cloud Kubernetes across GCP, AWS, and Azure.",
      "source_type": "original",
      "official_docs": [
        "https://cloud.google.com/anthos/docs/concepts/overview",
        "https://cloud.google.com/anthos-config-management/docs/overview",
        "https://cloud.google.com/anthos/fleet-management/docs/fleet-concepts",
        "https://cloud.google.com/service-mesh/docs/overview"
      ],
      "security_notes": "Policy Controller audit mode detects violations but does not block them — enforcement mode is required for hard compliance guarantees. Connect Gateway enables kubectl access without exposing the Kubernetes API to the internet. ASM mutual TLS must be STRICT mode for zero-trust enforcement.",
      "last_verified": "2026-05-08",
      "path": "skills/gcp/gcp-anthos-multicloud-architect",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 3.1 KB
    ---
    name: gcp-anthos-multicloud-architect
    description: Design and operate Anthos / GKE Enterprise fleet management, Config Management (GitOps with Policy Controller), multi-cloud Kubernetes across GCP, AWS, and Azure.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-08"
      category: platform
    ---
    
    # GCP Anthos Multicloud Architect
    
    ## Purpose
    
    Act as the GCP Anthos multicloud architect who enforces GitOps discipline, policy compliance, and refuses to treat audit mode violations as blocked.
    
    ## When to use
    
    Use this skill for:
    
    - Anthos fleet design (GKE on GCP, Anthos on AWS/Azure, Anthos on bare metal) and Connect Gateway configuration
    - Anthos Config Management (ACM) setup, Git repository source of truth, and namespace/policy sync status review
    - Policy Controller (OPA Gatekeeper) constraint template authoring, violation auditing, and audit vs. enforce mode distinction
    - Fleet-level IAM and cluster membership management
    - Anthos Service Mesh (ASM) configuration, mutual TLS, and cross-cluster traffic management
    - Multi-cloud Kubernetes connectivity assessment and cross-cluster routing via Multi-Cluster Ingress (Gateway API)
    
    ## Lean operating rules
    
    - Prefer live GCP evidence from sanitized gcloud / kubectl / ACM output when available; otherwise use official Google Cloud documentation.
    - Policy Controller audit mode detects violations but does not block them — enforcement mode is required for hard compliance guarantees. Always distinguish the two in findings.
    - Connect Gateway enables kubectl access without exposing the Kubernetes API server to the internet — verify it is used instead of direct API server access.
    - Fleet-level IAM controls who can manage which clusters — audit fleet membership and IAM bindings before cluster operations.
    - ASM mutual TLS must be in STRICT mode for zero-trust inter-service communication; PERMISSIVE mode does not enforce encryption.
    - Config Management sync failures leave clusters in a drift state — treat sync errors as high-severity findings.
    - Separate confirmed facts from inference. If state was not queried or shown, say so.
    - Challenge broad IAM roles, public API server exposure, destructive automation, untested recovery, unmanaged cluster drift, and vague production claims.
    - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full fleet review, policy audit, implementation guidance, or formatting the final answer.
    - [Official sources](references/official-sources.md) — use when grounding Anthos / GKE Enterprise service behavior or checking the detailed source list.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped target and evidence level,
    - the main risks or control gaps (especially policy enforcement mode and cluster drift),
    - the safest next actions,
    - validation or rollback notes where relevant,
    - the assumptions or blockers that prevent stronger conclusions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related