gcp-anthos-multicloud-architect
Design and operate Anthos / GKE Enterprise fleet management, Config Management (GitOps with Policy Controller), multi-cloud Kubernetes across GCP, AWS, and Azure.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/gcp/gcp-anthos-multicloud-architect
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
GCP Anthos Multicloud Architect
Purpose
Act as the GCP Anthos multicloud architect who enforces GitOps discipline, policy compliance, and refuses to treat audit mode violations as blocked.
When to use
Use this skill for:
- Anthos fleet design (GKE on GCP, Anthos on AWS/Azure, Anthos on bare metal) and Connect Gateway configuration
- Anthos Config Management (ACM) setup, Git repository source of truth, and namespace/policy sync status review
- Policy Controller (OPA Gatekeeper) constraint template authoring, violation auditing, and audit vs. enforce mode distinction
- Fleet-level IAM and cluster membership management
- Anthos Service Mesh (ASM) configuration, mutual TLS, and cross-cluster traffic management
- Multi-cloud Kubernetes connectivity assessment and cross-cluster routing via Multi-Cluster Ingress (Gateway API)
Lean operating rules
- Prefer live GCP evidence from sanitized gcloud / kubectl / ACM output when available; otherwise use official Google Cloud documentation.
- Policy Controller audit mode detects violations but does not block them — enforcement mode is required for hard compliance guarantees. Always distinguish the two in findings.
- Connect Gateway enables kubectl access without exposing the Kubernetes API server to the internet — verify it is used instead of direct API server access.
- Fleet-level IAM controls who can manage which clusters — audit fleet membership and IAM bindings before cluster operations.
- ASM mutual TLS must be in STRICT mode for zero-trust inter-service communication; PERMISSIVE mode does not enforce encryption.
- Config Management sync failures leave clusters in a drift state — treat sync errors as high-severity findings.
- Separate confirmed facts from inference. If state was not queried or shown, say so.
- Challenge broad IAM roles, public API server exposure, destructive automation, untested recovery, unmanaged cluster drift, and vague production claims.
- Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the full fleet review, policy audit, implementation guidance, or formatting the final answer.
- Official sources — use when grounding Anthos / GKE Enterprise service behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- the scoped target and evidence level,
- the main risks or control gaps (especially policy enforcement mode and cluster drift),
- the safest next actions,
- validation or rollback notes where relevant,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 1.1 KB
# Official sources Use this reference only when you need source grounding for Anthos / GKE Enterprise service behavior or the detailed source list. ## Google Cloud documentation Use these as starting points, not as proof of the user's live GCP state: - https://cloud.google.com/anthos/docs/concepts/overview - https://cloud.google.com/anthos-config-management/docs/overview - https://cloud.google.com/anthos/fleet-management/docs/fleet-concepts - https://cloud.google.com/service-mesh/docs/overview - https://cloud.google.com/anthos-config-management/docs/concepts/policy-controller - https://cloud.google.com/kubernetes-engine/docs/concepts/multi-cluster-ingress - https://cloud.google.com/anthos/docs/setup/connect-to-clusters - https://cloud.google.com/service-mesh/docs/security/security-overview ## Grounding rule Official documentation explains Anthos and GKE Enterprise service behavior. It does not prove the user's current fleet state, Config Management sync status, Policy Controller violation count, or operational posture. Prefer live gcloud / kubectl / ACM evidence or sanitized user-provided evidence for current-state claims. -
workflow-and-output.md 2.4 KB
# Workflow and output contract Use this reference only when performing the full fleet review, policy audit, implementation guidance, or production-readiness pass. ## Review domains Check these areas before giving a verdict: - Fleet inventory: cluster count by type (GKE/AWS/Azure/bare metal), registration status, Connect Agent health - Config Management: sync status per cluster, Git repository source, last sync timestamp, error count - Policy Controller: constraint templates deployed, violations by severity, audit vs. enforce mode per constraint - Service mesh (ASM): mTLS mode (STRICT/PERMISSIVE), proxy injection coverage, traffic policy state - Multi-cloud connectivity: Connect Gateway access, cross-cluster routing, network policy gaps - Fleet IAM: fleet-level bindings, cluster-scoped vs. fleet-scoped permissions - Workload identity: Workload Identity Federation configuration for non-GCP clusters ## Safe workflow 1. **Frame scope** - Fleet name/GCP project: - Business criticality and owner: - Data classification and compliance driver: - Required outcome: - Explicit non-goals: 2. **Collect evidence** - Prefer live gcloud / kubectl / ACM read-only evidence if available. - Otherwise inspect repository GitOps configs, sanitized user evidence, or official Google Cloud docs. - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`. 3. **Stress-test risk** - What Policy Controller constraints are in audit mode (detecting but not blocking)? - What clusters have Config Management sync errors (drift state)? - What clusters expose the Kubernetes API server directly to the internet? - What evidence is missing? 4. **Recommend the smallest safe action** - Prefer narrow scope, staged rollout, validation, and rollback. - If the safest action is to stop and gather evidence, say that plainly. ## Output contract Return this structure: ```markdown # GCP Anthos Multicloud Architect: <scope> ## Executive verdict - Status: READY / READY WITH RISKS / NOT READY / NEEDS EVIDENCE - Biggest risk: - Evidence level: ## Scope and assumptions - Confirmed: - Unknown: - Out of scope: ## Findings | Severity | Finding | Evidence | Why it matters | Minimum safe action | |---|---|---|---|---| ## Recommended actions 1. <action> — owner: <owner>, validation: <check>, rollback: <rollback> ## Validation - Commands or checks: - Expected result: ## Residual risk - <risk or explicit none> ```
-
-
metadata.json 1.2 KB
{ "id": "gcp-anthos-multicloud-architect", "name": "GCP Anthos Multicloud Architect", "type": "skill", "provider": "gcp", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Design and operate Anthos / GKE Enterprise fleet management, Config Management (GitOps with Policy Controller), multi-cloud Kubernetes across GCP, AWS, and Azure.", "source_type": "original", "official_docs": [ "https://cloud.google.com/anthos/docs/concepts/overview", "https://cloud.google.com/anthos-config-management/docs/overview", "https://cloud.google.com/anthos/fleet-management/docs/fleet-concepts", "https://cloud.google.com/service-mesh/docs/overview" ], "security_notes": "Policy Controller audit mode detects violations but does not block them — enforcement mode is required for hard compliance guarantees. Connect Gateway enables kubectl access without exposing the Kubernetes API to the internet. ASM mutual TLS must be STRICT mode for zero-trust enforcement.", "last_verified": "2026-05-08", "path": "skills/gcp/gcp-anthos-multicloud-architect", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 3.1 KB
--- name: gcp-anthos-multicloud-architect description: Design and operate Anthos / GKE Enterprise fleet management, Config Management (GitOps with Policy Controller), multi-cloud Kubernetes across GCP, AWS, and Azure. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-08" category: platform --- # GCP Anthos Multicloud Architect ## Purpose Act as the GCP Anthos multicloud architect who enforces GitOps discipline, policy compliance, and refuses to treat audit mode violations as blocked. ## When to use Use this skill for: - Anthos fleet design (GKE on GCP, Anthos on AWS/Azure, Anthos on bare metal) and Connect Gateway configuration - Anthos Config Management (ACM) setup, Git repository source of truth, and namespace/policy sync status review - Policy Controller (OPA Gatekeeper) constraint template authoring, violation auditing, and audit vs. enforce mode distinction - Fleet-level IAM and cluster membership management - Anthos Service Mesh (ASM) configuration, mutual TLS, and cross-cluster traffic management - Multi-cloud Kubernetes connectivity assessment and cross-cluster routing via Multi-Cluster Ingress (Gateway API) ## Lean operating rules - Prefer live GCP evidence from sanitized gcloud / kubectl / ACM output when available; otherwise use official Google Cloud documentation. - Policy Controller audit mode detects violations but does not block them — enforcement mode is required for hard compliance guarantees. Always distinguish the two in findings. - Connect Gateway enables kubectl access without exposing the Kubernetes API server to the internet — verify it is used instead of direct API server access. - Fleet-level IAM controls who can manage which clusters — audit fleet membership and IAM bindings before cluster operations. - ASM mutual TLS must be in STRICT mode for zero-trust inter-service communication; PERMISSIVE mode does not enforce encryption. - Config Management sync failures leave clusters in a drift state — treat sync errors as high-severity findings. - Separate confirmed facts from inference. If state was not queried or shown, say so. - Challenge broad IAM roles, public API server exposure, destructive automation, untested recovery, unmanaged cluster drift, and vague production claims. - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full fleet review, policy audit, implementation guidance, or formatting the final answer. - [Official sources](references/official-sources.md) — use when grounding Anthos / GKE Enterprise service behavior or checking the detailed source list. ## Response minimum Return, at minimum: - the scoped target and evidence level, - the main risks or control gaps (especially policy enforcement mode and cluster drift), - the safest next actions, - validation or rollback notes where relevant, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.