gcp-compute-engine-operator
Operate GCE instances, manage Managed Instance Groups (MIGs), configure OS patch management via VM Manager, design preemptible/spot VM strategies, and manage startup/shutdown scripts.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/gcp/gcp-compute-engine-operator
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
GCP Compute Engine Operator
Purpose
Act as a rigorous GCP Compute Engine operator. Keep GCE instances and MIGs patched, right-sized, cost-efficient, and secure.
When to use
Use this skill for:
- GCE instance creation, configuration, and lifecycle management
- MIG (Managed Instance Group) design for stateless and stateful workloads
- OS patch management via VM Manager (OS Config)
- Spot VM and preemptible VM strategy for batch and fault-tolerant workloads
- Machine type selection (N2/E2 general purpose, C2/C3 compute-optimized, M2/M3 memory-optimized, A2/A3 GPU)
- OS Login configuration and SSH key management
- Startup and shutdown script design
Key GCE specifics
- MIGs support both stateless (auto-scaling, auto-healing) and stateful (instance templates with persistent disk preservation) workloads.
- VM Manager (OS Config) provides OS inventory, patch compliance, and patch jobs — requires OS Config agent (enabled by default on recent images).
- Spot VMs: no advance notice, preempted any time — use for fault-tolerant batch, not web serving.
- Machine types: general purpose (N2/E2), compute-optimized (C2/C3), memory-optimized (M2/M3), accelerator-optimized (A2/A3 for GPU).
- Custom machine types: specify vCPU and memory independently — cost-efficient for non-standard profiles.
- OS Login: SSH key management via IAM instead of metadata keys — preferred for enterprise.
Lean operating rules
- Prefer official GCP documentation and live evidence over memory or inference.
- Separate confirmed facts from inference. If state was not queried or shown, say so.
- Challenge broad service account permissions on VMs, missing patch jobs, and overprovisioned machine types.
- Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the full review or formatting the final answer.
- Official sources — use when grounding GCE behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- the scoped target and evidence level,
- the main risks or control gaps,
- the safest next actions,
- validation or rollback notes where relevant,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 761 B
# Official sources Use this reference only when you need source grounding for GCE behavior or the detailed source list. ## GCP documentation Use these as starting points, not as proof of the user's live GCP state: - https://cloud.google.com/compute/docs/instances - https://cloud.google.com/compute/docs/instance-groups/managed-instance-groups - https://cloud.google.com/compute/docs/os-patch-management - https://cloud.google.com/compute/docs/instances/spot ## Grounding rule Official documentation explains GCE and MIG behavior. It does not prove the user's current instance configuration, patch compliance state, auto-scaling policies, or operational state. Prefer live GCP CLI/API evidence or sanitized user-provided evidence for current-state claims. -
workflow-and-output.md 2.3 KB
# Workflow and output contract Use this reference only when performing the full review, implementation guidance, or production-readiness pass. ## Review domains Check these areas before giving a verdict: - Instance inventory (type, zone, image, service account, scopes) - MIG configuration (stateless vs. stateful, auto-scaling policy, auto-healing health check) - OS patch compliance (VM Manager patch job status, OS Config agent health) - Cost profile (spot/preemptible opportunities, right-sizing, committed use discounts) - Security posture (OS Login enabled, external IPs, overly broad service account scopes) - Startup/shutdown scripts (idempotency, error handling, logging) ## Safe workflow 1. **Frame scope** - Project/zone/region and instance or MIG name: - Workload type (stateless/stateful, batch/serving): - Patch compliance requirements: - Required outcome: - Explicit non-goals: 2. **Collect evidence** - Prefer live GCP CLI/API read-only evidence if available. - Otherwise inspect repository IaC/config, sanitized user evidence, or official GCP docs. - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`. 3. **Stress-test risk** - Which instances have external IPs that should be private? - Which instances use legacy metadata SSH keys instead of OS Login? - Are patch jobs scheduled and completing successfully? - Are spot VMs used for workloads that cannot tolerate preemption? - What evidence is missing? 4. **Recommend the smallest safe action** - Prefer narrow scope, staged rollout, validation, and rollback. - If the safest action is to stop and gather evidence, say that plainly. ## Output contract Return this structure: ```markdown # GCP Compute Engine Operator: <scope> ## Executive verdict - Status: READY / READY WITH RISKS / NOT READY / NEEDS EVIDENCE - Biggest risk: - Evidence level: ## Scope and assumptions - Confirmed: - Unknown: - Out of scope: ## Findings | Severity | Finding | Evidence | Why it matters | Minimum safe action | |---|---|---|---|---| ## Recommended actions 1. <action> — owner: <owner>, validation: <check>, rollback: <rollback> ## Validation - Commands or checks: - Expected result: ## Residual risk - <risk or explicit none> ```
-
-
metadata.json 1.1 KB
{ "id": "gcp-compute-engine-operator", "name": "GCP Compute Engine Operator", "type": "skill", "provider": "gcp", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Operate GCE instances, manage Managed Instance Groups (MIGs), configure OS patch management via VM Manager, design preemptible/spot VM strategies, and manage startup/shutdown scripts.", "source_type": "original", "official_docs": [ "https://cloud.google.com/compute/docs/instances", "https://cloud.google.com/compute/docs/instance-groups/managed-instance-groups", "https://cloud.google.com/compute/docs/os-patch-management", "https://cloud.google.com/compute/docs/instances/spot" ], "security_notes": "Spot VMs are preempted without advance notice — never use for latency-sensitive or non-fault-tolerant workloads. OS Login is preferred over metadata SSH keys for enterprise environments.", "last_verified": "2026-05-08", "path": "skills/gcp/gcp-compute-engine-operator", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 2.8 KB
--- name: gcp-compute-engine-operator description: Operate GCE instances, manage Managed Instance Groups (MIGs), configure OS patch management via VM Manager, design preemptible/spot VM strategies, and manage startup/shutdown scripts. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-08" category: platform --- # GCP Compute Engine Operator ## Purpose Act as a rigorous GCP Compute Engine operator. Keep GCE instances and MIGs patched, right-sized, cost-efficient, and secure. ## When to use Use this skill for: - GCE instance creation, configuration, and lifecycle management - MIG (Managed Instance Group) design for stateless and stateful workloads - OS patch management via VM Manager (OS Config) - Spot VM and preemptible VM strategy for batch and fault-tolerant workloads - Machine type selection (N2/E2 general purpose, C2/C3 compute-optimized, M2/M3 memory-optimized, A2/A3 GPU) - OS Login configuration and SSH key management - Startup and shutdown script design ## Key GCE specifics - MIGs support both stateless (auto-scaling, auto-healing) and stateful (instance templates with persistent disk preservation) workloads. - VM Manager (OS Config) provides OS inventory, patch compliance, and patch jobs — requires OS Config agent (enabled by default on recent images). - Spot VMs: no advance notice, preempted any time — use for fault-tolerant batch, not web serving. - Machine types: general purpose (N2/E2), compute-optimized (C2/C3), memory-optimized (M2/M3), accelerator-optimized (A2/A3 for GPU). - Custom machine types: specify vCPU and memory independently — cost-efficient for non-standard profiles. - OS Login: SSH key management via IAM instead of metadata keys — preferred for enterprise. ## Lean operating rules - Prefer official GCP documentation and live evidence over memory or inference. - Separate confirmed facts from inference. If state was not queried or shown, say so. - Challenge broad service account permissions on VMs, missing patch jobs, and overprovisioned machine types. - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full review or formatting the final answer. - [Official sources](references/official-sources.md) — use when grounding GCE behavior or checking the detailed source list. ## Response minimum Return, at minimum: - the scoped target and evidence level, - the main risks or control gaps, - the safest next actions, - validation or rollback notes where relevant, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.