Google Cloud Auth Verification

by gemini-cli-extensions2df10e25bbf7Apache-2.0Listed Oct 8, 2026Updated Oct 8, 2026

Mandatory Step 0 pre-flight execution order and authentication verification for Google Cloud Platform (GCP), Application Default Credentials (ADC), gcloud CLI, Spark, Dataproc, BigQuery, GCS, and notebook runtimes. Use whenever interacting with GCP resources, running Spark/PySpark pipelines, BigQuery queries, GCS paths (gs://), or creating/running notebooks.

Instructions only

Google Cloud Authentication Guidelines

Mandatory Pre-Flight Execution & Auth Hierarchy

[!IMPORTANT] Pre-Flight Execution Priority Order: Before generating code, implementation plans, or executing tasks for any GCP or Notebook workload:

  1. Verify Shell, Script & Notebook Credentials: If shell-based commands, local Python scripts, or notebook kernels (gs://..., BigQuery, Dataproc) are required, verify credentials via bundled probe (gcloud auth list && gcloud config list) or Application Default Credentials (ADC).
  2. Distinguish Authentication vs. IAM Permissions:
    • If gcloud auth list returns No credentialed accounts, HARD STOP immediately and instruct the user to run gcloud auth login and gcloud auth application-default login.
    • If Python throws google.auth.exceptions.DefaultCredentialsError, explicitly direct the user to run gcloud auth application-default login.
    • If gcloud auth list shows an active credentialed account but a BigQuery/GCP call returns 403 Forbidden: Access Denied, DO NOT tell the user to log in again with gcloud auth login. Diagnose missing IAM roles (e.g., roles/bigquery.dataEditor) on the active account.
  3. HARD STOP if Unauthenticated: If no active GCP credentials or valid gcloud authentication are detected, STOP IMMEDIATELY. Prompt the user to run gcloud auth login and gcloud auth application-default login. Do NOT attempt local virtualenv creation, package installation, or local binary/JDK setup loops as workarounds.

Common Error Messages

  1. gcloud/bq CLI:
    • ERROR: (bq) You do not currently have an active account selected.
    • No credentialed accounts.
    • Configuration error: No account is currently active.
  2. Execution Failures (Python/Notebooks):
    • google.auth.exceptions.DefaultCredentialsError: Could not automatically determine credentials.
    • Forbidden: 403 Access Denied (when it's clearly an auth issue).

Verification Step

Before asking the user to log in, independently verify authentication status using a single bundled probe command:

bash
gcloud auth list --format="json" && gcloud config list --format="json"
  • If the output contains No credentialed accounts. or missing active account, proceed to Corrective Action.
  • If an account is listed but the user still receives a 403 Access Denied error, the issue is likely IAM permissions (e.g., missing BigQuery roles) on their active account, rather than missing authentication. In this case, investigate permissions rather than asking them to log in again.

Corrective Action

When missing credentials are confirmed, DO NOT attempt to fix credentials via code or local virtualenv workarounds. Credentials must be established by the user.

Stop and ask the user to run the following commands in their terminal:

  1. To authenticate the gcloud CLI: gcloud auth login
  2. To set up Application Default Credentials (ADC) (required for BQ CLI AND most libraries/notebooks): gcloud auth application-default login

Post-Login Verification

After the user confirms they have logged in, verify with: gcloud auth list Then proceed with the original task.

Source and attribution

Source:gemini-cli-extensions/data-agent-kit-starter-packinskills/google-cloud-auth-verificationat commit2df10e2

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from gemini-cli-extensions/data-agent-kit-starter-pack

Schema Mapping

gemini-cli-extensions

Plans source-to-target schema mappings for ETL, ELT, or data integration work, producing a documented Mapping Manifesto.

Data & AnalyticsOct 8, 2026

Resolving Mcp Region Configs

gemini-cli-extensions

Fixes unreplaced region placeholders in regional Google Cloud MCP server configs so missing MCP tools register.

DevOps & CloudOct 8, 2026

Notebook Guidance

gemini-cli-extensions

This skill guides the use of Jupyter notebooks for data analysis, exploration, and visualization, particularly with BigQuery. It outlines best practices for notebook execution and validation (supporting both cell-by-cell execution and full notebook generation depending on tool availability), library installation, and structuring notebooks for clarity. It also covers specific rules for data cleaning, plotting, and integrating with BigQuery SQL and machine learning workflows. Relevant when any of the following conditions are true: 1. The user request involves a data analysis, data exploration, data visualization, or data insights task that requires multiple steps, queries, or visualizations to answer. 2. The user explicitly requests a notebook (.ipynb). 3. You are creating, editing, or executing cells in a Jupyter notebook. 4. You need to query BigQuery from within a notebook. DO NOT use the Python BigQuery client library; instead, you MUST use the `%%bqsql` magics explained in this skill.

Awaiting classificationOct 8, 2026

Ml Best Practices

gemini-cli-extensions

Guides machine learning notebooks with step-by-step plans for clustering, forecasting, classification, regression and model comparison.

Data & AnalyticsOct 8, 2026

Managing Python Dependencies

gemini-cli-extensions

Guides agents to detect a Python project's dependency manager and install packages correctly instead of using global pip.

Software DevelopmentOct 8, 2026

Google Cloud Storage Fuse

gemini-cli-extensions

Mounts Cloud Storage buckets as a POSIX file system with Cloud Storage FUSE (gcsfuse). Use when you need to interact with gcsfuse — decide whether FUSE, native gs:// reads, or Filestore/Managed Lustre fits a workload, deploy tuned mounts on GKE, Compute Engine, or Cloud Run, enable and size the file, stat, and list caches, tune mount flags or config-file settings, apply workload profiles, keep ML checkpointing safe (rename atomicity, hierarchical namespace, close-time finalization, concurrent writers), or diagnose slow training, low throughput, or GCS bill spikes on existing mounts with gcsfuse metrics. Covers mount semantics, the gcsfuse CLI and config file, the GKE gcsfuse CSI driver (Workload Identity principal:// bindings, profile StorageClasses, sidecar sizing), and Cloud Run volume mounts. Don't use for bucket administration or data management without a mount (google-cloud-storage-basics) or for fully POSIX-compliant shared file systems (Filestore, Managed Lustre).

Awaiting classificationOct 8, 2026