| name | using-cloud-cli |
| description | Cloud CLI patterns for GCP and AWS. Use when running bq queries, gcloud commands, aws commands, or making decisions about cloud services. Covers BigQuery cost optimization and operational best practices. |
| allowed-tools | Read, Bash, Grep, Glob |
Cloud CLI Patterns
Credentials are pre-configured. Use --help or Context7 for syntax.
BigQuery
bq query --dry_run --use_legacy_sql=false 'SELECT ...'
bq query --use_legacy_sql=false --format=json 'SELECT ...'
bq ls project:dataset
bq show --schema --format=json project:dataset.table
Cost awareness: Charged per bytes scanned. Use --dry_run, partition tables, specify columns.
GCP (gcloud)
gcloud compute instances list --format=json
gcloud compute instances describe INSTANCE --zone=ZONE --format=json
gcloud compute instances create NAME --project=PROJECT --zone=ZONE
gcloud compute instances delete NAME --quiet
AWS
aws ec2 describe-instances --output json
aws ec2 describe-instances --query 'Reservations[].Instances[].InstanceId' --output text
aws s3 ls s3://bucket --region us-west-2
aws ec2 run-instances --dry-run ...
References
- GCP.md - GCP service patterns and common commands
- AWS.md - AWS service patterns and common commands
- scripts/ - Helper scripts for common operations
Gotchas
gcloud auth login and gcloud auth application-default login are DIFFERENT credentials — a script working for the user can 401 in CI because CI only has the latter.
- AWS CLI v1 vs v2 have different config formats — both may be installed;
aws --version reveals which is the default aws binary.
- BigQuery cost estimation requires
--dry_run — without it, you can run a $100 query thinking it's free. Always estimate first.
- Precedence:
AWS_PROFILE vs --profile flag vs AWS_ACCESS_KEY_ID direct env — three-way precedence is order-dependent and rarely documented.
- gcloud impersonation chains via
--impersonate-service-account need IAM token-creator on EACH hop — missing one hop returns 403 with vague "permission denied".
aws sts get-caller-identity is the cheapest way to verify which credential you're actually using — always check first.