Google Cloud put a Cloud CLI remote MCP server into public preview (blog 2026-09-30), powered by gcloud and bq, so AI agents can run CLI operations against GCP infra and BigQuery without packaging CLI binaries into agent runtimes. Docs label the feature Preview under Pre-GA Offerings Terms—as is, limited support (blog, docs).
This is a Desk Bot tools/cli briefing. HARD: do not call GA or invent a GA date. Fence from local stdio gcloud-mcp, the separate BigQuery MCP server (GA SQL/analysis), and T4 Gemini Skills / Gems.
Endpoint + enablement
MCP endpoint: https://cloudcli.googleapis.com/mcp (Streamable HTTP). Enable Cloud CLI Execution API (cloudcli.googleapis.com); grant MCP Tool User (roles/mcp.toolUser). Auth: Agent Identity (hosted GCP platforms) or OAuth 2.0 + IAM (external); docs say API keys are not accepted (blog, auth docs).
Two tools
Agents get broad CLI surface via run_gcloud_command and run_bq_command—infrastructure manage/diagnose (gcloud) plus advanced BigQuery admin (scheduling via DTS, jobs/reservations, dataset IAM, snapshots/clones). That admin path is distinct from the separate BigQuery MCP server’s GA SQL/analysis surface (blog, docs).
MCP reference warns: tools are not read-only—they can create/update/delete resources (reference).
Soft: blocked commands (non-exhaustive)
Docs list example blocked gcloud groups (security/inapplicability), including auth, config, iam service-accounts, init, survey—list is non-exhaustive and subject to change. Blocked bq examples: init, pyshell, shell. Reference adds further forbidden gcloud examples (e.g. app deploy, app instances ssh, billing, components, docker, feedback, info, meta). Prefer “examples of blocked groups” over claiming a complete allowlist (docs, reference).
Soft: security / pricing (as Google states)
Network-restricted execution with no ambient credentials; calls run as the authenticated caller with IAM + org-policy enforcement; optional Model Armor screening; configurable Audit Logs (Data Access under cloudcli.googleapis.com/mcp) without exposing sensitive command payloads/PII per blog—attribute as Google-stated (blog, docs).
Pricing: no additional charge for the MCP server itself; customers pay only for GCP resources created and applicable data transfer. Do not invent free-tier quotas for the Execution API (blog).
Who should care
Teams wiring agents to GCP without stuffing CLI binaries into every sandbox should start at the preview blog and use-gcloud-mcp docs—keep Preview / Pre-GA, treat blocked lists as mutable examples, soft-attribute IAM/Model Armor/Audit Logs and pay-for-resources, and leave Skills and BigQuery SQL MCP to their own slugs.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.