GCP Diagnostic & Troubleshooting Assistant
Diagnose GCP infrastructure issues and generate secure remediation plans
What You Can Do
You can systematically identify and resolve GCP infrastructure problems by analyzing logs, metrics, and configurations across Compute, Networking, IAM, and Storage services. The skill guides you through root cause analysis, validates security implications of proposed fixes, and generates actionable remediation steps with testing recommendations.
Features
Extract error patterns, stack traces, and anomalies from Cloud Logging to pinpoint failure sources
Correlate issues across Compute Engine, Cloud Run, GKE, Cloud SQL, IAM, and VPC Network services
Flag permission gaps, exposed credentials, overly-permissive policies, and compliance violations before implementing fixes
Create step-by-step fix instructions with rollback procedures, blast radius assessment, and priority ranking
Identify resource contention, quota limits, network latency, and database performance issues
Review GCP resource configurations against best practices (least privilege, encryption, monitoring, backup)
Navigate complex troubleshooting scenarios with guided decision trees to reach root cause efficiently
Example Output
Example 1: Compute Engine Instance Connectivity Issue
Problem identified:
- Instance firewall rules block SSH (port 22) from your IP
- VPC route to Cloud NAT is missing for outbound traffic
Remediation plan:
- Add firewall rule:
gcloud compute firewall-rules create allow-ssh --allow=tcp:22 --source-ranges=YOUR_IP - Verify Cloud NAT exists:
gcloud compute routers list - Test SSH:
ssh -i key.pem user@INSTANCE_IP
Example 2: Cloud Run Deployment Failure
Root cause: Service account lacks artifactregistry.repositories.get permission
Security check: ✓ Minimal IAM role needed (Artifact Registry Service Agent) — no overly-broad roles
Fix:
gcloud projects add-iam-policy-binding PROJECT_ID \
--member=serviceAccount:SA_EMAIL \
--role=roles/artifactregistry.serviceAgent
Example 3: Cloud SQL Connection Timeout
Analysis: Application tries to connect using public IP but Cloud SQL Proxy is not running; private IP connection requires VPC peering.
Recommendation: Use Cloud SQL Proxy (secure tunnel) or enable Private IP with VPC peering and update connection string.
What's Included
- SKILL.md: Complete GCP diagnostic workflow with multi-step troubleshooting decision trees
- Diagnostic checklist: Quick reference for common GCP service issues (Compute, Networking, IAM, Databases)
- Log analysis templates: Structured queries for Cloud Logging to extract errors by service
- Remediation workflow template: Step-by-step framework for analyzing → fixing → testing
- Security validation checklist: Review proposed fixes for compliance, least-privilege, and credential exposure risks
- Decision tree diagrams: Visual guides for navigating complex troubleshooting scenarios
Who It's For
- GCP DevOps engineers and SREs troubleshooting infrastructure outages
- Cloud architects reviewing configuration issues and security violations
- Application developers debugging connectivity and permissions errors
- Infrastructure teams responding to alerts and performing RCAs
Best For
- Diagnosing failed Compute Engine, Cloud Run, and GKE deployments
- Analyzing Cloud Logging errors to identify root causes
- Validating IAM policies and permission-related failures
- Reviewing GCP configurations against security best practices
- Creating remediation and rollback plans for production incidents





