OFICIAL Google Cloud Blog

Empower your agents with the Google Cloud CLI remote MCP server

What happened
Based on Google Cloud Blog · Sep 30, 2026

Google Cloud launches a new remote MCP server in preview, enabling AI agents to securely execute gcloud and bq commands via a managed cloud sandbox, simplifying infrastructure management and BigQuery workflows.

Empower your agents with the Google Cloud CLI remote MCP server
Google Cloud Blog — Google
Key points
·
Google Cloud CLI remote MCP server in preview enables AI agents to execute gcloud and bq commands securely in a cloud sandbox.
·
Server enforces zero ambient credentials and integrates with Model Armor for prompt injection protection and audit logging.
·
Public preview available today with no additional charge; users pay only for GCP resources and data transfer costs.

Google Cloud has introduced the Google Cloud CLI remote MCP server in preview, expanding its ecosystem of managed remote MCP servers. The new server allows AI agents to securely access and execute gcloud and bq commands directly from a cloud-based sandbox, eliminating the need for local CLI installations. This addresses challenges in standardizing agent interactions with backend systems by packaging hundreds of CLI commands into unified, high-level operations. The server leverages the pre-trained knowledge of LLMs on command-line documentation, making CLI invocation more intuitive and accurate for models.

The Cloud CLI remote MCP server provides an isolated execution environment on Google Cloud infrastructure, solving key operational challenges for teams. It simplifies dependency and runtime management by removing the need to maintain local CLI versions across development, testing, and production environments. Additionally, it enables secure access to Google Cloud CLI operations from web-hosted agent platforms, such as Gemini Enterprise, where local package installation is not possible. The server supports standard authentication and authorization frameworks, including Agent Identity, OAuth 2.0, and IAM, ensuring enterprise-grade security.

Security is a core focus of the new remote MCP server, which enforces strict policies to protect cloud environments. It operates with zero ambient credentials, running commands under the authenticated caller's identity and enforcing IAM permissions and organization policy constraints. The server integrates with Model Armor to screen prompts and responses for risks like prompt injection, while cloud audit logging provides visibility into tool invocations without exposing sensitive data.

The Google Cloud CLI remote MCP server implements the standard Model Context Protocol, allowing any MCP-compatible agent platform to connect immediately. It exposes two tools, run_gcloud_command and run_bq_command, enabling agents to manage Google Cloud infrastructure and perform advanced BigQuery tasks such as resource allocation, job monitoring, and scheduled query automation. The server is available today in public preview at no additional cost, with users only paying for the GCP resources they create and any applicable data transfer fees.

Original source → Deals on Clipraptor.com →