Google Cloud BlogProsper Nwankpa3 min readintermediate
Empower your agents with the Google Cloud CLI remote MCP server
Summary
Google Cloud introduced a preview remote MCP server that exposes gcloud and bq commands to AI agents via the Model Context Protocol, removing the need to bundle CLI binaries. It enforces IAM‑based auth, zero ambient credentials, Model Armor screening, and audit logging for secure, managed access.
- Agents can invoke any gcloud or bq command through the remote MCP server without installing the CLI locally.
- Execution runs in an isolated sandbox with no ambient credentials; auth is handled via Agent Identity, OAuth, and IAM.
- Model Armor screens prompts and responses to mitigate prompt‑injection and other malicious inputs.
- Every command invocation is logged to Cloud Audit Logs, exposing caller identity and IAM decisions without leaking payload data.
Teams building AI agents that need to manage Google Cloud resources should care because it eliminates CLI packaging overhead while providing enterprise‑grade security and observability.
5/10




