Jeremy Github Actions Gcp
GitHub Actions CI/CD workflows for Google Cloud and Vertex AI deployments
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 2.27.0
- Author
- Jeremy Longshore
What Jeremy Github Actions Gcp is
Jeremy Github Actions Gcp is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Jeremy Github Actions Gcp adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Jeremy Github Actions Gcp
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install jeremy-github-actions-gcp@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Jeremy Github Actions Gcp in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/devops/jeremy-github-actions-gcp/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
GitHub Actions expert for Google Cloud and Vertex AI deployments with Workload Identity Federation (WIF), comprehensive security validation, and deployment best practices enforcement.
Overview
This plugin ensures secure, production-ready CI/CD pipelines for Vertex AI Agent Engine and Google Cloud services. It enforces Workload Identity Federation (WIF) instead of JSON service account keys, validates post-deployment health, and implements GitHub Actions best practices.
Installation
/plugin install jeremy-github-actions-gcp@claude-code-plugins-plusFeatures
✅ Workload Identity Federation (WIF): Keyless authentication from GitHub to GCP ✅ Vertex AI Agent Engine: Automated deployment and validation pipelines ✅ Security Enforcement: No JSON keys, least privilege IAM, secrets scanning ✅ Post-Deployment Validation: Comprehensive health checks for deployed agents ✅ A2A Protocol Compliance: AgentCard validation and endpoint testing ✅ Automated Hooks: Pre-commit validation of workflow files ✅ Best Practices: OIDC permissions, security scanning, monitoring setup
Components
Agent
- gh-actions-gcp-expert: Expert in GitHub Actions for Vertex AI / GCP deployments
Skills (Auto-Activating)
- gh-actions-validator: Validates and enforces GitHub Actions best practices
- Tool Permissions: Read, Write, Edit, Grep, Glob, Bash
- Version: 1.0.0 (2026 schema compliant)
Hooks
- PreToolUse: Validates workflow files before writing/editing
- Triggers on: .github/workflows/.yml, .github/workflows/.yaml
- Runs: scripts/validate-workflow.sh
Quick Start
Natural Language Activation
Simply mention what you need:
"Create GitHub Actions workflow for Vertex AI deployment"
"Set up Workload Identity Federation for my project"
"Deploy ADK agent to Vertex AI Engine with CI/CD"
"Validate my GitHub Actions security"
"Automate Vertex AI agent deployment"The skill auto-activates and enforces best practices.
Validation Rules Enforced
1. Workload Identity Federation (WIF) Mandatory
❌ NEVER ALLOWED - JSON Service Account Keys:
# ❌ FORBIDDEN
- uses: google-github-actions/auth@v2
with:
credentials_json: ${{ secrets.GCP_SA_KEY }} # ❌ BLOCKS HOOK✅ REQUIRED - WIF with OIDC:
# ✅ ENFORCED
permissions:
id-token: write # ✅ REQUIRED for WIF
- uses: google-github-actions/auth@v2
with:
workload_identity_provider: ${{ secrets.WIF_PROVIDER }}
service_account: ${{ secrets.WIF_SERVICE_ACCOUNT }}2. OIDC Permissions Required
# ✅ ENFORCED - Must have id-token: write
permissions:
contents: read
id-token: write # REQUIRED for WIF3. IAM Least Privilege
❌ Overly Permissive Roles Blocked:
- roles/owner - ❌ Blocked
- roles/editor - ❌ Blocked
✅ Least Privilege Roles Required:
- roles/run.admin - Cloud Run deployments
- roles/iam.serviceAccountUser - Service account impersonation
- roles/aiplatform.user - Vertex AI operations
4. Post-Deployment Validation
For Vertex AI deployments, validation is REQUIRED:
- name: Post-Deployment Validation
run: |
python scripts/validate-deployment.py \
--agent-id=production-agentValidation Checklist:
- ✅ Agent state is RUNNING
- ✅ Code Execution Sandbox enabled (7-14 day TTL)
- ✅ Memory Bank configured
- ✅ A2A Protocol compliant (AgentCard accessible)
- ✅ Model Armor enabled (prompt injection protection)
- ✅ VPC Service Controls configured
- ✅ Service account has minimal permissions
- ✅ Monitoring and alerting configured
5. Security Scanning
Recommended (warnings if missing):
- name: Scan for secrets
uses: trufflesecurity/trufflehog@main
- name: Vulnerability scanning
uses: aquasecurity/trivy-action@masterWorkflow Templates
Template 1: Vertex AI Agent Engine Deployment
name: Deploy Vertex AI Agent
on:
push:
branches: [main]
paths:
- 'agent/**'
permissions:
contents: read
id-token: write
env:
AGENT_ID: 'production-agent'
REGION: 'us-central1'
jobs:
deploy:
…Template 2: WIF Setup (One-Time)
name: Setup Workload Identity Federation
on:
workflow_dispatch:
permissions:
contents: read
jobs:
setup-wif:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Authenticate (one-time setup key)
uses: google-github-actions/auth@v2
…Template 3: Security Validation
name: Security Checks
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
security-events: write
jobs:
security:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
… Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Jeremy Github Actions Gcp?
Jeremy Github Actions Gcp is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. GitHub Actions CI/CD workflows for Google Cloud and Vertex AI deployments
How do I install Jeremy Github Actions Gcp in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install jeremy-github-actions-gcp@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Jeremy Github Actions Gcp in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Jeremy Github Actions Gcp in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Jeremy Github Actions Gcp safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Sugar Orchestrator Coordinates Sugar's autonomous development workflows with strategic oversight Subagent · jeremylongshore/tons-of-skills-marketplace
- Sugar Review Review and manage pending Sugar tasks interactively Slash Command · jeremylongshore/tons-of-skills-marketplace
- Sugar Thinking View Claude's thinking logs for task execution Slash Command · jeremylongshore/tons-of-skills-marketplace
- Sugar Status View Sugar system status, task queue, and execution metrics Slash Command · jeremylongshore/tons-of-skills-marketplace
- Jeremy Google Adk Google Agent Development Kit (ADK) SDK starter kit for building Claude-powered AI agents with React patterns, multi-agent orchestration, and tool integration Plugin · jeremylongshore/tons-of-skills-marketplace
- Jeremy Genkit Terraform Terraform modules for Firebase Genkit infrastructure and deployments Plugin · jeremylongshore/tons-of-skills-marketplace
- Jeremy Vertex Ai Comprehensive Vertex AI integration plugin for building generative AI agents with Gemini, Vertex AI Studio, and production deployment on Google Cloud Plugin · jeremylongshore/tons-of-skills-marketplace
- Jeremy Genkit Pro Firebase Genkit expert for production-ready AI workflows with RAG and tool calling Plugin · jeremylongshore/tons-of-skills-marketplace