Downloads · 30 days
0
benthomasson/gcp-expert
gcp-expert is a machine learning model from benthomasson. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as mit.
Expert knowledge base for Google Cloud Platform service behavior, defaults, and operational pitfalls. Contains 863 justified beliefs covering GCE, GCS, Cloud Run, GKE, Cloud SQL, Pub/Sub, Secret Manager, VPC networkin…
Downloads · 30 days
0
Access
Public
Updated May 31, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.md500 KB · 51%
From the Hugging Face model README
Expert knowledge base for Google Cloud Platform service behavior, defaults, and operational pitfalls. Contains 863 justified beliefs covering GCE, GCS, Cloud Run, GKE, Cloud SQL, Pub/Sub, Secret Manager, VPC networking, IAM, KMS, and cross-service interactions.
This is an External Epistemic Memory (EEM) — a model-agnostic knowledge base that any LLM can use via the reasons CLI or tool calling. Unlike a LoRA or fine-tune, this knowledge is not baked into model weights. It is external, inspectable, correctable, and works with any model.
| Metric | Value |
|---|---|
| Total beliefs | 863 |
| Status | 863 IN / 0 OUT |
| Premises (observations) | 709 |
| Derived (justified conclusions) | 154 |
| Nogoods (contradictions) | 0 |
| Retraction rate | 0% |
| Max derivation depth | 8 |
| Topic | Beliefs |
|---|---|
| gce | 77 |
| vpc | 73 |
| gcs | 70 |
| cloudrun | 67 |
| gke | 64 |
| cloud | 60 |
| gcp | 58 |
| cloudsql | 50 |
| iam | 43 |
| pubsub | 43 |
| secretmanager | 43 |
| interconnect | 36 |
| kms | 35 |
| cloudbuild | 30 |
| private | 27 |
| dns | 24 |
reasons init
reasons import-json network.json
reasons search "Cloud SQL private networking"
reasons explain cmek-single-control-plane-for-data-governance
reasons show gcp-security-requires-upfront-architectural-commitment
Any LLM agent that can call reasons search, reasons show, and reasons explain can use this knowledge base. The agent does not need to be told it is an expert — the knowledge base speaks for itself.
| Node | Summary |
|---|---|
cmek-single-control-plane-for-data-governance | CMEK key lifecycle serves as the single control plane for data governance across GCP |
gcp-security-requires-upfront-architectural-commitment | GCP's dual security governance (IAM + CMEK) compounds with cross-layer interactions |
secretmanager-rotation-notification-only | Secret Manager rotation is notification-only: it sends a Pub/Sub message rather than rotating |
vpc-peering-limited-connectivity-model | VPC peering is non-transitive, never exchanges IAM policies, and has a 25 peering limit |
cloudsql-private-networking-doubly-constrained-by-peering | Cloud SQL private IP inherits VPC peering constraints (non-transitivity, 25 peering limit) |
cloudsql-production-architecture-requires-triple-investment | Production Cloud SQL requires concurrent HA, backup, and private networking investment |
cloud-armor-operates-at-edge | Cloud Armor filters traffic at the Google Cloud edge before it reaches backends |
cloud-armor-auto-ddos-global-external-alb | DDoS protection is automatic for global external Application Load Balancers |
kms-rotation-decoupled-from-reencryption | KMS key rotation creates new versions without re-encrypting existing data |
secretmanager-production-access-pattern | Production secret access should use the API directly, pin to specific versions |
Built from exploration of GCP documentation, API behavior, and operational experience across GCE, GCS, Cloud Run, GKE, Cloud SQL, Pub/Sub, Secret Manager, VPC, IAM, KMS, and 15+ additional GCP services.
| File | Description |
|---|---|
network.json | Full belief network (machine-readable, portable) |
reasons.db | SQLite database (gitignored, regenerate with reasons import-json network.json) |
CLAUDE.md | Agent instructions for using this knowledge base |
entries/ | 114 exploration entries — raw observations behind the premises |
mit