Task

SkillCloud & infra

Audits VPC subnet IPAM capacity, Cloud NAT ephemeral port exhaustion, Private Service Connect routing, and Cloud Armor WAF policies.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Task skill

What this skill tells your AI

The instructions your AI receives, as published by gke-labs/kube-agents in agents/platform/skills/gcp-networking-fabric-audit/SKILL.md and read by ahel’s review.

Audit Google Cloud VPC subnet IPAM allocation headroom, Cloud NAT ephemeral port capacity, Private Service Connect (PSC) reachability, and Cloud Armor WAF policies, emitting findings for the fleet-audit reporting harness.

Workflow

1. Execute Networking Inspection

Follow the authoritative SOP at governance/gcp_networking_fabric_sop.md to execute the five diagnostic checks across target GCP projects:

  • subnet-ip-exhaustion
  • cloud-nat-exhaustion
  • psc-routing-deadlock
  • mtu-packet-fragmentation
  • cloud-armor-false-positive

Optional helper runner:

./skills/gcp-networking-fabric-audit/scripts/networking_audit.py --output /opt/data/scratch/networking_raw.json

2. Hand Findings to Fleet Audit

Emit findings using the fleet-audit harness lifecycle (start ... finish).

Signals

GitHub stars
54
Forks
36
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
gcp-networking-fabric-audit
Source
github.com/gke-labs/kube-agents