
google-cloud-solution-multi-agent-security
热门Designs, deploys, and secures Google Cloud Agent Gateway solutions. Use when the user needs to configure multi-agent security, ingress (CLIENT_TO_AGENT), or egress (AGENT_TO_ANYWHERE) patterns involving Model Armor, IAP, and Agent Registry. Don't use for general Cloud Load Balancing or basic VPC setup not related to Agent Gateways.
Designs, deploys, and secures Google Cloud Agent Gateway solutions. Use when the user needs to configure multi-agent security, ingress (CLIENT_TO_AGENT), or egress (AGENT_TO_ANYWHERE) patterns involving Model Armor, IAP, and Agent Registry. Don't use for general Cloud Load Balancing or basic VPC setup not related to Agent Gateways.
Agent Gateway multi-agent security
Critical Enforcement Rules & Rationale
- Gcloud Release Tracks: Always use the exact release tracks specified in
the commands (e.g.,gcloud beta network-services agent-gateways). Omitting
these prefixes causes commands to fail because Agent Gateway features are
located in specialized, non-default namespaces. - API Enablement: Include
modelarmor.googleapis.comin the API
enablement list when setting up guardrails. Excluding it prevents Model
Armor policies and filters from successfully attaching to the Gateway. - Egress Verification: Egress policy verification requires using the
Python script
(scripts/verify_egress_policies.py),
notcurl. Egress gateways rely on runtime SDK lifecycle handling and JWT
context that a standard curl command cannot simulate correctly. - Model Armor Keys: In
model-armor-config.yaml, always include both
piAndJailbreakFilterSettingsandsdpFilterSettings(filterEnforcement: ENFORCE). Invalid or missing filters cause deployment validation failures
or lead to silent bypasses of the guardrails. - Subnet Private Access: Any subnet hosting a Private Service Connect
network attachment for Egress Gateways must haveprivate_ip_google_access = trueenabled in Terraform. Disabling this blocks connectivity to
Google-managed endpoints, causing total routing failures for agents. - Direct Delivery: Immediately provide the requested architecture,
configuration files, CLI commands, scripts, and diagrams in full. Do not
stop at a planning phase, do not generate a plan artifact, and do not ask
for user confirmation before delivering outputs. - No Infrastructure Execution: Do not attempt to run deployment or
verification commands (such asgcloud,kubectl,terraform, orcurl)
against real cloud resources during design. You are generating plan
configurations, not executing them.
[!IMPORTANT] Just-In-Time (JIT) Resource Loading Protocol: Inspect
template files in assets/ and executable scripts in
scripts/ usingview_fileas needed for extended configurations,
deployment scripts, and test suites.
Quick Reference: Required Filenames
Always generate files with these exact names when requested:
agw-ingress-config.yaml
(assets/agw-ingress-config.yaml)agw-egress-config.yaml
(assets/agw-egress-config.yaml)agw-authz-extension.yaml
(assets/agw-authz-extension.yaml)agw-authz-policy.yaml
(assets/agw-authz-policy.yaml)model-armor-config.yaml
(assets/model-armor-config.yaml)sgp-policy.yaml(assets/sgp-policy.yaml)iap-policy.json(assets/iap-policy.json)model-armor-payload.json
(assets/model-armor-payload.json)
1. Dual Ingress & Egress Architecture Design (dual_ingress_egress_architecture_design)
-
Ingress Pattern:
CLIENT_TO_AGENTfronted by Ingress Control Plane
(Agent Gateway, Model Armor). -
Egress Pattern:
AGENT_TO_ANYWHEREutilizing Egress Control Plane
(Agent Gateway,roles/iap.egressorCEL policies, Cloud DNS) and Egress
Data Plane (PSC Interface, Cloud Run, PSC Google APIs Global Endpoint),
coordinated via Agent Registry & Agent Engine runtime. -
Mermaid Diagram:
graph TD Client["External Clients"] -->|HTTPS / MCP| GLB["Global Load Balancer"] GLB --> Ingress["Ingress Agent Gateway (CLIENT_TO_AGENT)"] Ingress --> MA["Model Armor (CONTENT_AUTHZ)"] MA --> Agent["Agent Engine Agents (BillingAgent, SupportAgent, FraudAgent)"] Agent --> Egress["Egress Agent Gateway (AGENT_TO_ANYWHERE)"] Egress --> PSC["Private Service Connect Network Attachment"] PSC --> Tools["Private MCP Tool Backends"]
2. Ingress & Egress Guardrail Policy Config (ingress_and_egress_guardrail_policy_config)
When requested for Ingress & Egress guardrail policy configs, you MUST generate
and create all required files in the workspace:
agw-ingress-config.yaml
(assets/agw-ingress-config.yaml): Declares
governedAccessPath: CLIENT_TO_AGENTwith protocolsHTTPandMCP.agw-egress-config.yaml
(assets/agw-egress-config.yaml): Declares
governedAccessPath: AGENT_TO_ANYWHEREwith protocolMCP.agw-authz-extension.yaml
(assets/agw-authz-extension.yaml):
Configures AuthzExtension service for IAP authorization.agw-authz-policy.yaml
(assets/agw-authz-policy.yaml): Configures
AuthzPolicyactionALLOWtargeting both Ingress and Egress gateways.iap-policy.json(assets/iap-policy.json): Binds
roles/iap.egressorwith CEL condition checking
iap.googleapis.com/mcp.toolName == 'get_account_balance' && iap.googleapis.com/mcp.tool.isReadOnly == true.model-armor-config.yaml
(assets/model-armor-config.yaml): Enables
piAndJailbreakFilterSettingsandsdpFilterSettingswith
filterEnforcement: ENFORCE.sgp-policy.yaml(assets/sgp-policy.yaml):
Implements Natural Language Constraints blocking transactions > $1000 and
sanitizing PII.
3. Ingress & Egress Infrastructure Deployment (ingress_and_egress_infrastructure_deployment)
Inspect and provide the step-by-step gcloud CLI commands from
scripts/deploy_infrastructure.sh:
- Enable Required APIs:
compute,networkservices,networksecurity,
modelarmor,iap,agentregistry,serviceextensions, andaiplatform. - Import Agent Gateways: Ingress (
agw-ingress-config.yaml) and Egress
(agw-egress-config.yaml) viagcloud alpha network-services agent-gateways import. - Import Authz Extension:
agw-authz-extension.yamlviagcloud beta service-extensions authz-extensions import. - Import Authz Policy:
agw-authz-policy.yamlviagcloud beta network-security authz-policies import.
4. Ingress & Egress Security Validation (ingress_and_egress_security_validation)
When validating security for Ingress and Egress:
- Ingress 403 Unauthenticated Test: Provide the copy-pasteable
verification curl command from
scripts/validate_ingress_unauth.sh
sending an unauthenticated POST request to the Reasoning Engine endpoint
expecting HTTP 403 Forbidden. - Python Egress Verification Script (MUST use Python script snippet, NOT
curl): Provide the Python verification script snippet from
scripts/verify_egress_policies.py
sending JSON-RPCtools/callrequests (get_account_balance) through the
Egress Gateway to verify HTTP 200 for allowed tools. - Model Armor Test Payload: Generate
model-armor-payload.json
(assets/model-armor-payload.json)
containing prompt injection/jailbreak instructions.
5. Troubleshooting Ingress & Egress Failures (troubleshooting_ingress_and_egress_failures)
-
Ingress 403 (Client-to-Agent):
- Root Cause: Unauthenticated client requests or missing/invalid OAuth
2.0 / IAP identity tokens. - OAuth Configuration Steps:
- Configure OAuth 2.0 Client ID credentials in Google Cloud Console.
- Grant the client identity / service account
roles/iap.httpsResourceAccessorpermission. - Exchange credentials with Google OAuth to acquire an OIDC / OAuth ID
token. - Pass the token in the
Authorization: Bearer <TOKEN>header.
- Verification Command: Provide the curl command from
scripts/verify_ingress_auth.sh.
- Root Cause: Unauthenticated client requests or missing/invalid OAuth
-
Egress 403 (Agent-to-Anywhere):
- Root Cause: Missing
roles/iap.egressorIAM bindings on the Agent
Identity, malformed principal ID, or mismatched CEL condition on tool
metadata. - Fix Command: Provide the exact
gcloudcommand from
scripts/fix_egress_iap.sh.
- Root Cause: Missing
6. Hybrid VPN Connectivity & Egress Routing (hybrid_vpn_connectivity_egress_routing)
- Terraform HCL: Refer to baseline Terraform config in
assets/main.tf for VPC, subnets
(private_ip_google_access = true), PSC network attachment, Cloud DNS
private forwarding foraws.internal., and HA VPN gateway/router. - Egress Gateway Config (
agw-egress-config.yaml): Generate configuration
declaringgovernedAccessPath: AGENT_TO_ANYWHERE, pointing to the PSC
network attachment, and referencingaws.internal.indnsPeeringConfig
(see assets/agw-egress-config.yaml). - Python SDK Deployment Script: Refer to
scripts/hybrid_vpn_agent.py for the complete
script initializing Vertex AI withagent_to_anywhere_configreferencing
the Egress Gateway, enabling telemetry, and deployingHybridAgentusing
types.IdentityType.AGENT_IDENTITY.
7. Private Egress GKE Internal Load Balancer (private_egress_gke_internal_load_balancer)
- Expose GKE internal MCP tool server via an Internal Load Balancer (ILB) at
literal IP10.0.1.50, connecting via Agent Gateway PSC Interface + Cloud
DNS Private zone. - Cloud DNS Record Mapping: Provide the command from
scripts/create_gke_dns_record.sh mapping
the private domain to GKE's private ILB IP10.0.1.50. - Explicit TLS Warning: Agent Gateway egress does not natively trust
self-signed certificates or private enterprise CAs. You must use
publicly trusted TLS certificates signed by a trusted Certificate Authority
(e.g., Let's Encrypt).
8. Governance Controls Model Armor SGP (governance_controls_model_armor_sgp)
When configuring dual safety layers with Model Armor on Ingress and SGP on
Egress:
- Model Armor Config: Generate
model-armor-config.yaml
(assets/model-armor-config.yaml) with
piAndJailbreakFilterSettingsandsdpFilterSettings(filterEnforcement: ENFORCE). - Semantic Governance Policy: Generate
sgp-policy.yaml
(assets/sgp-policy.yaml) with Natural Language
Constraints blocking transactions > $1000 and sanitizing PII. - Curl PATCH Command: Provide the curl command from
scripts/enforce_sgp_patch.sh to update
authzExtensionswithsgpEnforcementModeset toENFORCE.
9. Multi-Agent Cloud Run Egress Routing (multi_agent_cloud_run_egress_routing)
Do NOT produce a plan artifact or stop at planning. When configuring multi-agent
Cloud Run egress routing, you MUST directly provide and generate ALL required
components:
- Egress Gateway Config (
agw-egress-config-run.yaml): Generate
configuration declaringgovernedAccessPath: AGENT_TO_ANYWHERE, PSC network
attachment, and DNS peering for*.run.app(see
assets/agw-egress-config-run.yaml). - Register Cloud Run Services in Agent Registry: Provide the registration
commands from
scripts/register_cloud_run_services.sh
registering all 3 Cloud Run services (marketing-tool-service,
sales-tool-service,support-tool-service) in theus-east4Agent
Registry. iap-policy.json(Multi-Agent): Generateiap-policy.json
(assets/iap-policy-multi-agent.json)
containing all 3principal://bindings in thememberslist under
roles/iap.egressor.- Python SDK Deployment Script: Refer to
scripts/multi_agent_cloud_run.py for the
complete GenAI SDK deployment script.
10. Advanced Model Armor Filtering (advanced_model_armor_filtering)
For custom keyword matching, configure userDefinedFilterSettings (see
assets/model-armor-advanced.yaml).
11. Known Traps & Gotchas (known_traps_and_gotchas)
network_attachmentisForceNew: Enabling Semantic Governance
Policies (SGP) or modifying network attachments after the initial Terraform
apply will force-recreate the gateway resource. If not managed carefully,
this can cause dependency deadlocks during destroy operations. Plan
infrastructure sequencing accordingly.- Authz Policy Limit: An Agent Gateway allows at most 4 custom
authorization policies attached concurrently. Ensure your security posture
consolidates rules within this limit.





