Google Launches Remote MCP Server for Google Cloud CLI in Preview
Product launch

Google Launches Remote MCP Server for Google Cloud CLI in Preview

The server enables AI agents to run gcloud and bq commands in an isolated sandbox without local installation

4 min read
Based on original reporting byGoogle Cloud AI ↗Translated and summarized by our AI-assisted news systemHow we work

✨Executive summary

Key Takeaways

  • Google has expanded its ecosystem of managed remote MCP servers with the launch of the Google Cloud CLI remote MCP server in preview.

  • The server enables AI agents to run gcloud and bq commands in an isolated execution sandbox on Google Cloud infrastructure without local binary installations.

  • The security mechanism includes zero ambient credentials, IAM policy enforcement, Model Armor integration, and Cloud audit logging capabilities.

  • The server exposes two main tools: run_gcloud_command for infrastructure management and diagnostics, and run_bq_command for BigQuery resources, queries, and permissions.

  • Using the MCP server incurs no additional charge beyond the costs of created GCP resources and applicable data transfer.

Google Launches Remote MCP Server for Google Cloud CLI in Preview

  • Google has expanded its ecosystem of managed remote MCP servers with the launch of the...
  • The server enables AI agents to run gcloud and bq commands in an isolated execution...
  • The security mechanism includes zero ambient credentials, IAM policy enforcement, Model Armor integration, and Cloud...
  • The server exposes two main tools: run_gcloud_command for infrastructure management and diagnostics, and run_bq_command for...
  • Using the MCP server incurs no additional charge beyond the costs of created GCP resources...

In an official announcement, Google announced the expansion of its ecosystem of managed remote Model Context Protocol (MCP) servers with the launch of the Google Cloud CLI remote MCP server in preview. Powered by the familiar command-line tools gcloud and bq for BigQuery, the new server gives artificial intelligence agents immediate and broad access to command-line operations for managing Google Cloud infrastructure and working with advanced BigQuery workflows securely and seamlessly.

Why the Command-Line Interface Matters for AI Agents

According to Google's announcement, AI agents are increasingly performing complex cloud operations, but standardizing how they interact with backend systems remains a challenge. The Cloud CLI remote MCP server bridges this gap by packaging the versatility of hundreds of gcloud and bq commands into a single MCP server. This architecture yields two key benefits for AI agents:

First, higher-level abstractions. CLI commands package complex multi-step workflows, validation checks, and high-level operations into unified commands, rather than requiring multi-step API orchestration.

Second, it leverages model training. Large language models (LLMs) are heavily pre-trained on public command-line documentation, syntax, and usage examples, making CLI invocation intuitive and highly accurate for models.

The Benefits of Running the CLI Behind a Remote MCP Server

Managing cloud infrastructure using AI agents traditionally required installing and maintaining Google Cloud CLI binaries inside agent execution environments. The Cloud CLI remote MCP server bridges CLI capabilities with MCP benefits by providing an isolated execution sandbox on Google Cloud infrastructure. This solution addresses key infrastructure challenges:

  1. Simplified dependency and runtime management: For teams building custom agents, maintaining local CLI versions and different dependencies across development, testing, and production environments creates operational overhead. A remote MCP server completely eliminates the need for local installations and the maintenance of local runtimes.

  2. Access for web-based agent endpoints: Web-hosted agent platforms and web interfaces (such as Gemini Enterprise and other hosted enterprise agent platforms) run in environments where users cannot control or install local packages. A remote MCP server enables secure and managed access to Google Cloud CLI operations directly from these surfaces.

Enterprise-Grade Security and Governance

Connecting an AI agent to enterprise infrastructure requires strict safeguards tailored for enterprises. Google's remote server leverages Google Cloud's standard identity and governance frameworks to keep environments secure:

  • Zero ambient credentials: The server isolates execution inside a network-restricted proxy boundary with no ambient credentials. Authentication and authorization are handled through Agent Identity, the OAuth 2.0 protocol, and the Identity and Access Management (IAM) system.
  • Strict policy enforcement: Every command executed through the remote MCP server is run under the defined permissions of the authenticated caller identity. Both standard IAM permissions and organization policy service constraints are strictly enforced against downstream target resources.
  • Advanced protection with Model Armor: To minimize the risks associated with AI tool calling, the MCP server integrates with the Model Armor system. LLM prompts and responses can be proactively screened to protect against risks such as prompt injection and malicious inputs.
  • Cloud audit logging: The remote MCP server can be configured to log every tool invocation in audit logs (Data Access logs under cloudcli.googleapis.com/mcp). Security teams can gain full visibility into caller identities, OAuth clients, and IAM authorization decisions (under mcp.googleapis.com/tools.call), without exposing sensitive command payloads or personally identifiable information (PII).

Connecting and Configuring the Remote MCP Server

Integrating cloud management into agents no longer requires packaging Google Cloud CLI binaries, managing local execution runtimes, or maintaining dependencies inside agent container images. Because the remote MCP server implements the standard Model Context Protocol, any MCP-compatible agent platform or orchestration environment can connect immediately using a standard configuration, configuring the server under google-cloud-cli with the URI pointing to https://cloudcli.googleapis.com/mcp.

Following connection, the agent immediately gains access to execute gcloud and bq commands inside a secure, network-isolated cloud sandbox. The authentication process is handled via keyless Agent Identity for hosted Google Cloud platforms, or standard OAuth 2.0 for external runtimes.

Managing Infrastructure and Extending BigQuery Operations with run_gcloud_command and run_bq_command

The remote MCP server exposes two central tools for AI agents:

  1. Managing cloud infrastructure with run_gcloud_command: This tool allows agents to run the full breadth of gcloud operations to manage, diagnose, and secure the Google Cloud environment. An example is the area of observability and incident diagnostics, where an agent streamlines incident diagnostics by automating command execution and reducing context-switching across different tools.

  2. Extending BigQuery operations with run_bq_command: While the existing BigQuery MCP server already assisted organizations in analyzing and exploring data using AI agents, the run_bq_command tool enables agents to handle advanced BigQuery tasks such as resource allocation, job monitoring, and task scheduling by unlocking the full scope of bq CLI functionality. Key capabilities include:

  • Automating scheduled queries: The agent uses BigQuery Data Transfer Service configurations to schedule queries automatically.
  • Job and resource management: Gaining deep insight into query execution details, including processed data volume, slot usage, execution plans, as well as managing reservations.
  • Access and permissions control: Data administrators and owners can inspect and update table permissions directly through the agent.

Pricing, Availability, and Getting Started

The Google Cloud CLI remote MCP server is available now in public preview. Google stated that there is no additional charge or fee for using the MCP server itself; users pay only for the GCP resources they create as part of the activity and any applicable data transfer costs.

To get started with the server, three steps are required:

  1. Enable the Cloud CLI Execution API (cloudcli.googleapis.com) in the Google Cloud project.
  2. Grant the required MCP Tool User IAM role (roles/mcp.toolUser) to the agent or user identity.
  3. Configure the MCP client to connect to cloudcli.googleapis.com/mcp.

Questions & Answers

FAQ

This article was produced by our AI-assisted system through translation, summarization, and automated quality controls based on original reporting by Google Cloud AI. Read about our editorial process. Link to the original source.

Get useful AI updates by email

A concise digest from our news desk.

More from Google Cloud AI

All articles from Google Cloud AI
חידושים בתשתיות ותזמור בינה מלאכותית ב-Google Cloud
חדשות
4 דקות
מ־Google Cloud AI

חידושים בתשתיות ותזמור בינה מלאכותית ב-Google Cloud

גוגל קלאוד (Google Cloud) פרסמה סקירה מקיפה של עדכוני תשתיות ותזמור AI לחודשים מאי עד אוגוסט 2026. בין החידושים: שכבת אחסון חדשה ל-Filestore המבוססת על מערכת Colossus לתמיכה בקבוצות סוכני AI, סביבות gVisor בתוך אשכולות Ray מבוזרים על גבי GKE, מופעי Cloud Run ייעודיים לסוכנים בעלות של 5.70 דולר ל-30 יום, והפיכת ליבת פרוטוקול MCP לחסרת מצב (stateless). כמו כן הוצגו זמינות כללית ל-Managed Lustre ולמכונות C4N, כלי אבטחה בקוד פתוח בשם k8s-aibom, שדרוגי ביצועים ב-GKE Inference Gateway, ותוצאות סקר שבו 83% מהארגונים ציינו צורך בשדרוג תשתיות עבור יישומי Agentic AI.

קרא עוד

More articles you might like

All articles
הכרזת n8n Agents: שילוב סוכני AI עצמאיים לצד תהליכי עבודה
מוצר חדש
4 דקות
מ־n8n

הכרזת n8n Agents: שילוב סוכני AI עצמאיים לצד תהליכי עבודה

פלטפורמת n8n הכריזה על השקת Agents (סוכנים), המאפשרים למשתמשים להגדיר מטרות בשפה חופשית ולהשאיר לסוכן לקבוע את שלבי הביצוע בעזרת מודלים, כלים ותהליכי עבודה קיימים. הסוכנים יכולים לפעול מתוך Slack, Telegram, Discord, לפי תזמון מוגדר או מתוך תהליכי עבודה באמצעות הצומת החדש Message an Agent. כל סוכן כולל ניהול זיכרון, הפעלות, כלים, מיומנויות ומנגנוני אישור אנושי לפעולות רגישות. התכונה זמינה כעת ב-Preview למשתמשי n8n Cloud ובהתקנה עצמאית.

קרא עוד
מודל Jev של TypeSafe AI: קבלת החלטות מהירה לאוטומציה ללא הזיות
מוצר חדש
4 דקות
מ־TechCrunch

מודל Jev של TypeSafe AI: קבלת החלטות מהירה לאוטומציה ללא הזיות

חברת TypeSafe AI, שהוקמה על ידי חוקר OpenAI לשעבר דיוגו אלמיידה, השיקה את Jev — מודל טרנספורמר חדש שאינו מפיק טקסט אלא הסתברויות והחלטות מכוילות. המודל מאפשר קבלת החלטות מהירה וזולה לאוטומציית תוכנה ללא סכנת הזיות, הודות להגדרת הפלטים מראש על ידי המשתמש ואימונו הבלעדי על נתונים סינתטיים. מפתחים מדווחים על שיפורי מהירות משמעותיים ועלויות נמוכות בהשוואה למודלי שפה מסורתיים.

קרא עוד
Amazon Quick זמין כעת באופן כללי למחשב השולחני
מוצר חדש
4 דקות
מ־AWS Machine Learning

Amazon Quick זמין כעת באופן כללי למחשב השולחני

אפליקציית הדסקטופ של Amazon Quick זמינה כעת באופן כללי למשתמשי macOS ו-Windows, ובמקביל נוסף פיד פעילות למובייל ב-iOS וב-Android. המערכת מרכזת נתונים מדואר אלקטרוני, מיומן פגישות, ממערכות CRM ומהודעות לתצוגה מתועדפת אחת, כאשר סוכני AI מטפלים במשימות שגרתיות ברקע. Quick פועל על גבי תשתיות AWS ושומר על נתוני הארגון בסביבתו המקומית, כולל תמיכה במעקב ביקורת דרך CloudWatch ו-CloudTrail והסמכות תאימות דוגמת HIPAA, FedRAMP, SOC 2 ו-ISO 27001. לקוחות בארגונים כמו Southwest Airlines, LabCorp ו-PGA TOUR משתמשים בכלי להשלמת משימות, סינתזת מידע ופיתוח אבות-טיפוס.

קרא עוד
סיילספורס מציגה את סוכן התזמון של Agentforce לשירות שטח
מוצר חדש
4 דקות
מ־Salesforce Blog

סיילספורס מציגה את סוכן התזמון של Agentforce לשירות שטח

סיילספורס הציגה את Scheduling Agent במסגרת Agentforce Field Service, סוכן בינה מלאכותית הפועל 24/7 לתיאום, שינוי וביטול פגישות שירות שטח. הסוכן מחובר לנתוני הלקוחות, ללוחות הזמנים של הטכנאים ולמנוע האופטימיזציה של הארגון, ופועל בערוצי תקשורת מגוונים בהם וואטסאפ, דוא"ל, SMS, iMessage ושיחות קוליות. המערכת מבוססת על Agent Script לקבלת החלטות דטרמיניסטית ואכיפת כללים עסקיים ללא ניחושים של מודלי שפה, ומספקת מענה לפניות לקוחות, סדרנים, טכנאים וטריגרים מנכסים. המערכת תוצג בכנס Dreamforce וב-Salesforce+.

קרא עוד