Setup & auth
ReadCheck CLI installation
Display installed Google Cloud CLI versions.
gcloud versionInstall the Google Cloud CLI first; Cloud Shell already includes it.
Official referencegcloud / bq / Python / ADK / agents-cli
Google Cloud commands for authentication, agent development, AI hosting and data workflows.
Reference only; nothing runs here. Commands use your permissions and may change resources or incur charges in your own terminal. Bash syntax shown.
Enter your existing project ID, a supported region and an existing bucket name when prompted. These variables apply only to your terminal session; this block creates no Cloud resources.
read -r -p "Google Cloud project ID: " PROJECT_ID
read -r -p "Google Cloud region (e.g. us-central1): " REGION
read -r -p "Existing bucket name (without gs://): " BUCKET_NAME
export PROJECT_ID REGION BUCKET_NAMEDocument AI’s processor location is separate from REGION. Use the location returned for your processor and its matching regional endpoint.
57 / 57 commands
Setup & auth
ReadDisplay installed Google Cloud CLI versions.
gcloud versionInstall the Google Cloud CLI first; Cloud Shell already includes it.
Official referenceSetup & auth
Local setupAuthorize gcloud to act as your Google account.
gcloud auth loginThis does not configure Application Default Credentials for Python libraries. Avoid shared terminals.
Official referenceSetup & auth
ReadList CLI accounts and the active identity.
gcloud auth listAccount emails are sensitive; do not share terminal output publicly.
Official referenceSetup & auth
Local setupCreate local Application Default Credentials for Google Cloud client libraries.
gcloud auth application-default loginFor local development only. Deployed workloads should use an attached service identity or federation, not downloaded keys.
Official referenceSetup & auth
Local setupSelect the project used for supported API quota and billing attribution by local ADC.
gcloud auth application-default set-quota-project "$PROJECT_ID"Requires serviceusage.services.use on this project; this does not grant service-specific permissions.
Official referenceSetup & auth
ReadReview the current project, account and configured properties.
gcloud config listCommands with explicit --project or --region override defaults.
Official referenceProjects & APIs
Local setupSelect the default project for subsequent gcloud commands.
gcloud config set project "$PROJECT_ID"Check the project ID before any command that changes resources or incurs charges.
Official referenceProjects & APIs
Local setupSet the default region for Cloud Run commands.
gcloud config set run/region "$REGION"There is no universal region property: Vertex AI commands below specify --region explicitly. Document AI uses its processor location.
Official referenceProjects & APIs
ReadList projects visible to the active identity.
gcloud projects listVisibility depends on your permissions; missing projects may still exist.
Official referenceProjects & APIs
ReadInspect APIs currently enabled for your project.
gcloud services list --enabled --project="$PROJECT_ID"Enabling an API does not create a processor, model or bucket.
Official referenceProjects & APIs
Cloud changeEnable the services used by the portal’s Google Cloud learning examples.
gcloud services enable documentai.googleapis.com vision.googleapis.com aiplatform.googleapis.com bigquery.googleapis.com storage.googleapis.com --project="$PROJECT_ID"Requires service enablement permissions. Enable only services you need; subsequent usage can be billable.
Official referenceStorage
ReadList Cloud Storage buckets in the selected project.
gcloud storage buckets list --project="$PROJECT_ID"Requires bucket-list permissions; output can expose resource names.
Official referenceStorage
ReadInspect object paths in an existing bucket.
gcloud storage ls "gs://$BUCKET_NAME/"Storage request charges can apply, even to listing operations. Use consented documents only.
Official referenceStorage
Cloud changeUpload a local PDF to an existing bucket for a document-processing workflow.
gcloud storage cp ./sample_invoice.pdf "gs://$BUCKET_NAME/document-ai/input/sample_invoice.pdf"Creates or overwrites the target object and can incur charges. Confirm bucket access and data location first.
Official referenceStorage
Billable workCopy existing batch-processing output to a local directory.
gcloud storage cp --recursive "gs://$BUCKET_NAME/document-ai/output/" ./document-ai-results/Requires an already completed batch operation. Downloads can incur transfer charges and contain private text.
Official referenceStorage
ReadPreview copying a local directory to Cloud Storage without making changes.
gcloud storage rsync ./documents "gs://$BUCKET_NAME/document-ai/input/" --recursive --dry-runRemoving --dry-run performs writes and can overwrite objects. This preview does not delete unmatched objects.
Official referenceAI & documents
Cloud changeEnable the Document AI API before creating a processor in the Google Cloud console.
gcloud services enable documentai.googleapis.com --project="$PROJECT_ID"Create the processor separately, then record its ID and supported location. Enabling the API alone does not process documents.
Official referenceAI & documents
Local setupPrepare an isolated Python environment for the uploaded online-processing example.
python -m venv .venv
source .venv/bin/activate
python -m pip install google-cloud-documentaiBash/macOS/Linux activation shown. Windows PowerShell uses .venv\Scripts\Activate.ps1. Configure ADC separately.
Official referenceAI & documents
Local setupInstall the client used by the image-labeling example into your active environment.
python -m pip install google-cloud-visionInstallation does not make API calls. Running image annotation requires credentials, enabled API and billing.
Official referenceAI & documents
ReadList registered models in a Vertex AI region.
gcloud ai models list --project="$PROJECT_ID" --region="$REGION"This is your regional model registry, not a list of every foundation model in Model Garden.
Official referenceAI & documents
ReadInspect existing regional prediction endpoints.
gcloud ai endpoints list --project="$PROJECT_ID" --region="$REGION"Listing does not deploy a model or stop charges for an already deployed endpoint.
Official referenceBigQuery
ReadList datasets accessible within your project using the bq CLI.
bq ls --project_id="$PROJECT_ID"bq is a separate command bundled with the Google Cloud CLI; dataset visibility depends on IAM.
Official referenceBigQuery
ReadValidate GoogleSQL without running a query job.
bq query --project_id="$PROJECT_ID" --use_legacy_sql=false --dry_run 'SELECT 1 AS ready'This literal query is a connectivity-free syntax example. For table queries, dry runs estimate bytes; they do not guarantee the final billed cost.
Official referenceBigQuery
Billable workSubmit a minimal query job and display its result.
bq query --project_id="$PROJECT_ID" --use_legacy_sql=false 'SELECT 1 AS ready'Requires bigquery.jobs.create. This query scans no tables; replacing it with data queries can incur charges.
Official referenceOperations
ReadInspect up to 20 error-level entries from the last hour.
gcloud logging read 'severity>=ERROR' --project="$PROJECT_ID" --limit=20 --freshness=1h --format=jsonLogs can contain personal data, document text or secrets. Redact before sharing; an empty result is not proof of health.
Official referenceOperations
ReadInspect existing Cloud Run services in a region.
gcloud run services list --project="$PROJECT_ID" --region="$REGION" --platform=managedDoes not deploy or invoke a service. Existing running resources may remain billable.
Official referenceOperations
ReadInspect supported flags and examples for your installed CLI version.
gcloud storage cp --helpUse --help on any command before changing unfamiliar resources.
Official referenceSetup & auth
Local setupInstall preview commands where your CLI installation supports the component manager.
gcloud components install betaPackage-manager installations may require OS packages instead. Installing beta does not add an undocumented Document AI or pipelines command group.
Official referenceProjects & APIs
Cloud changeEnable the API used for custom training, pipelines and model serving.
gcloud services enable aiplatform.googleapis.com --project="$PROJECT_ID"Requires service enablement permissions; does not create a job or endpoint. Training and serving usage can incur charges.
Official referenceCustom training
Billable workSubmit containerized training using worker pools defined in a local CustomJobSpec YAML file.
read -r -p "Training job display name: " JOB_NAME
read -r -p "Existing CustomJobSpec YAML path: " CONFIG_YAML
gcloud ai custom-jobs create --display-name="$JOB_NAME" --config="$CONFIG_YAML" --project="$PROJECT_ID" --region="$REGION"Review machine types, replica counts, images, identity and budget before submitting. The configuration must exist; compute and storage are billable. This is a managed job, not free serverless compute.
Official referenceCustom training
ReadInspect up to 20 custom jobs in a region, including jobs in terminal states.
gcloud ai custom-jobs list --project="$PROJECT_ID" --region="$REGION" --limit=20Regional listing is not a global inventory or a full cost report. Requires access to the selected project.
Official referenceCustom training
ReadRead job state, configuration and available error details for an existing job.
read -r -p "Existing custom job ID: " JOB_ID
gcloud ai custom-jobs describe "$JOB_ID" --project="$PROJECT_ID" --region="$REGION"Description output is not a comprehensive compute metrics report; use monitoring and logs for execution diagnostics.
Official referenceCustom training
ReadFollow available logs from the training workers.
read -r -p "Existing custom job ID: " JOB_ID
gcloud ai custom-jobs stream-logs "$JOB_ID" --project="$PROJECT_ID" --region="$REGION"Ctrl+C stops local streaming, not the training job. Logs may expose sensitive data; never log credentials or private training records.
Official referenceCustom training
Cloud changeRequest cancellation of a running custom training job.
read -r -p "Custom job ID to cancel: " JOB_ID
gcloud ai custom-jobs cancel "$JOB_ID" --project="$PROJECT_ID" --region="$REGION"Check the exact job first. Cancellation is asynchronous, not instant; inspect state until cancellation completes. Work already performed remains billable, and stored artifacts are not automatically removed.
Official referencePipelines
Local setupInstall the SDK used by the pipeline submission and inspection examples in your active Python environment.
python -m pip install google-cloud-aiplatformConfigure ADC separately. Install into an isolated environment; SDK installation does not compile or execute a pipeline.
Official referencePipelines
Billable workSubmit an already compiled pipeline with the Vertex AI SDK, not the unsupported gcloud ai pipelines runs syntax.
read -r -p "Pipeline display name: " PIPELINE_NAME
read -r -p "Existing compiled pipeline JSON/YAML path: " PIPELINE_SPEC
read -r -p "Pipeline service account email: " PIPELINE_SERVICE_ACCOUNT
export PIPELINE_NAME PIPELINE_SPEC PIPELINE_SERVICE_ACCOUNT
python - <<'PY'
import os
from google.cloud import aiplatform
aiplatform.init(project=os.environ["PROJECT_ID"], location=os.environ["REGION"])
job = aiplatform.PipelineJob(
display_name=os.environ["PIPELINE_NAME"],
template_path=os.environ["PIPELINE_SPEC"],
pipeline_root=f"gs://{os.environ['BUCKET_NAME']}/pipeline-root",
enable_caching=False,
)
job.submit(service_account=os.environ["PIPELINE_SERVICE_ACCOUNT"])
print(job.resource_name)
PYUse a spec with no unsupplied required parameters; otherwise add parameter_values. Review every component, identity permission and bucket location. Submission can launch billable training or other work; the caller needs permission to act as the specified service account.
Official referencePipelines
ReadDisplay up to 20 recent regional pipeline jobs through the Python SDK.
python - <<'PY'
import os
from itertools import islice
from google.cloud import aiplatform
aiplatform.init(project=os.environ["PROJECT_ID"], location=os.environ["REGION"])
for job in islice(aiplatform.PipelineJob.list(order_by="create_time desc"), 20):
print(job.resource_name, job.state.name)
PYThe SDK list method may retrieve more results before local slicing; avoid this convenience snippet for large inventories. Results are regional, not global; inspect full details in the console or SDK.
Official referenceModel serving
Cloud changeCreate an endpoint resource before deploying a compatible registered model.
read -r -p "Endpoint display name: " ENDPOINT_NAME
gcloud ai endpoints create --display-name="$ENDPOINT_NAME" --project="$PROJECT_ID" --region="$REGION"This command does not deploy a model or set up private networking. A standard endpoint requires authorized prediction calls. Review networking requirements before creation.
Official referenceModel serving
Billable workDeploy a compatible model with one serving replica and route all endpoint traffic to the new deployment.
read -r -p "Existing endpoint ID: " ENDPOINT_ID
read -r -p "Compatible registered model ID: " MODEL_ID
read -r -p "Deployment display name: " DEPLOYED_NAME
gcloud ai endpoints deploy-model "$ENDPOINT_ID" --model="$MODEL_ID" --display-name="$DEPLOYED_NAME" --machine-type=n1-standard-4 --min-replica-count=1 --max-replica-count=1 --traffic-split=0=100 --project="$PROJECT_ID" --region="$REGION"Changes existing traffic. The example machine must suit your model; registry membership does not certify quality or compatibility. Provisioned replicas can remain billable without requests. Undeploy separately when no longer needed.
Official referenceModel serving
Billable workSend a JSON prediction request to a supported endpoint with a deployed model.
read -r -p "Existing deployed endpoint ID: " ENDPOINT_ID
read -r -p "Model-compatible JSON request path: " PAYLOAD_FILE
gcloud ai endpoints predict "$ENDPOINT_ID" --json-request="$PAYLOAD_FILE" --project="$PROJECT_ID" --region="$REGION"Use the model’s required instances/parameters schema and consented inputs. Calls can incur charges and send data to the endpoint; output is not guaranteed accurate. Dedicated or private endpoints may require another prediction interface.
Official referenceAI & documents
ReadList up to 20 existing processors with the official Document AI Python client and matching location endpoint.
read -r -p "Processor location (e.g. us or eu): " DOC_LOCATION
export DOC_LOCATION
python - <<'PY'
import os
from itertools import islice
from google.api_core.client_options import ClientOptions
from google.cloud import documentai
location = os.environ["DOC_LOCATION"]
client = documentai.DocumentProcessorServiceClient(
client_options=ClientOptions(api_endpoint=f"{location}-documentai.googleapis.com")
)
parent = f"projects/{os.environ['PROJECT_ID']}/locations/{location}"
processors = client.list_processors(request={"parent": parent, "page_size": 20})
for processor in islice(processors, 20):
print(processor.name, processor.display_name, processor.type_, processor.state.name)
PYInstall google-cloud-documentai and configure ADC first. Use a supported processor location, not the Vertex AI region. Processor creation is documented in the console/API; gcloud beta document-ai processors is not an official command group.
Official referenceAgent development
Local setupInitialize Google agents-cli and its coding-agent skill definitions.
uvx google-agents-cli setupInstall uv first. This downloads and runs third-party tooling locally; review the source and installation changes. It does not create a Cloud agent or grant Cloud permissions.
Official referenceAgent development
Local setupScaffold a local prototype; the project name is positional, not --name.
read -r -p "New agent project directory: " AGENT_NAME
agents-cli create "$AGENT_NAME" --prototypeChoose a new directory. Prototype mode avoids deployment scaffolding; it does not sandbox arbitrary tools or guarantee the generated agent is production-ready.
Official referenceAgent development
Local setupInstall dependencies from an existing agents-cli project directory.
agents-cli installRun inside the generated project, after reviewing its dependency definitions. Installation executes local package tooling; do not install untrusted projects.
Official referenceAgent development
Billable workLaunch the local development playground for an existing configured agent project.
agents-cli playgroundLocal web hosting is not a containerized security sandbox. Conversations can call real models and tools with your configured access and incur charges. Use draft-only tools and keep the server private.
Official referenceAgent development
Billable workRun the project’s evaluation datasets against its configured agent.
agents-cli eval runRequires prepared datasets and model authentication. Evaluation may call models and tools repeatedly; use synthetic data and safe tool stubs. Passing tests is not a safety or accuracy certification.
Official referenceAgent hosting
ReadPreview the deployment pipeline from a deployment-ready agents-cli project.
agents-cli deploy --dry-runReview the configured deployment target, project, region and infrastructure plan. A prototype must first gain deployment scaffolding. Previewing is not a cost estimate or permission guarantee.
Official referenceAgent hosting
Billable workDeploy the project to its configured Cloud hosting target.
agents-cli deploy --project="$PROJECT_ID" --region="$REGION"Review the dry run first. May create or update billable infrastructure and change serving behavior; the target is set by project configuration. Deployment and publishing to Gemini Enterprise are separate lifecycle steps, not automatic dashboard access.
Official referenceAgent development
Local setupInstall the official Python Agent Development Kit into an isolated environment.
python -m venv .venv
source .venv/bin/activate
python -m pip install google-adkBash activation shown; Windows uses its corresponding activation script. Installation does not authenticate a model. Keep any provider credentials outside code and shared terminal history.
Official referenceAgent development
Local setupGenerate a Python ADK agent project through the interactive CLI.
read -r -p "New ADK agent directory: " AGENT_DIR
adk create "$AGENT_DIR"Use a new directory, review generated code and configure model access separately. Do not paste private API keys into command flags or publish generated credential files.
Official referenceAgent development
Billable workStart a terminal conversation with an existing ADK agent.
read -r -p "Existing ADK agent directory: " AGENT_DIR
adk run "$AGENT_DIR"This executes agent code locally and may invoke real tools and billable model calls. Keep external actions approval-gated; Ctrl+C ends this local process, not previously submitted Cloud jobs.
Official referenceAgent development
Billable workServe the ADK web interface from the parent directory containing your agent folders.
adk web . --host=127.0.0.1 --port=8501Development-only local server, not a container or production sandbox. Do not expose it to public networks. Agent interactions can call paid models and real tools. In a uv-managed project with google-adk installed, uv run adk web . --port 8501 is an alternative.
Official referenceAgent development
Billable workEvaluate the configured agent against an existing ADK evaluation set.
read -r -p "Existing agent module path: " AGENT_MODULE
read -r -p "Existing evaluation set JSON path: " EVAL_FILE
adk eval "$AGENT_MODULE" "$EVAL_FILE" --print_detailed_resultsEvaluation sets must match the ADK format. Calls can be billable and tool actions real; isolate tools and use consented synthetic cases. Detailed output can contain sensitive conversation text.
Official referenceAgent hosting
Billable workPackage and deploy an existing ADK agent to the managed Agent Engine runtime.
read -r -p "Existing ADK agent directory: " AGENT_DIR
read -r -p "Agent display name: " AGENT_DISPLAY_NAME
adk deploy agent_engine --project="$PROJECT_ID" --region="$REGION" --display_name="$AGENT_DISPLAY_NAME" "$AGENT_DIR"Creates a new instance unless an update ID is supplied. Requires supported region, enabled API, billing, compatible dependencies and deployment permissions. Review runtime identity and tool access; hosted execution can incur charges. Gemini Enterprise publication is separate.
Official referenceAgent hosting
Cloud changeEnable the Vertex AI API used for Agent Engine resources.
gcloud services enable aiplatform.googleapis.com --project="$PROJECT_ID"Corrects the malformed ://googleapis.com service name in the upload. API activation alone does not provision a runtime, enable every deployment dependency or grant IAM roles.
Official referenceAgent hosting
ReadInspect regional hosted resources using Google’s documented preview Python SDK sample.
python - <<'PY'
import os
from itertools import islice
import vertexai
from vertexai.preview import reasoning_engines
vertexai.init(project=os.environ["PROJECT_ID"], location=os.environ["REGION"])
for engine in islice(reasoning_engines.ReasoningEngine.list(), 20):
print(engine.resource_name)
PYInstall google-cloud-aiplatform and configure ADC first. The SDK can retrieve more results before local slicing; use paginated API reads for large inventories. The uploaded gcloud alpha ai reasoning-engines group has no verified official command reference; use this SDK alternative.
Official referenceAgent hosting
ReadResolve an existing hosted agent resource with the documented preview SDK.
read -r -p "Existing agent engine resource ID: " ENGINE_ID
export ENGINE_ID
python - <<'PY'
import os
import vertexai
from vertexai.preview import reasoning_engines
vertexai.init(project=os.environ["PROJECT_ID"], location=os.environ["REGION"])
engine = reasoning_engines.ReasoningEngine(os.environ["ENGINE_ID"])
print(engine.resource_name)
PYRequires the matching project, region and read permissions. This prints resource identity, not a complete audit of tool access or runtime IAM. Preview SDK interfaces may change; inspect full configuration in the console before any deletion.
Official reference