Google Cloud Strawberry

The cross-service audit nobody has an afternoon for

Which buckets are publicly readable, which Cloud Run services cold-start into a timeout, which projects have billing attached and no owner. One pass, one list, owners found afterwards in the browser.

The Google Cloud questions worth asking span services, which is why nobody asks them. Which buckets are publicly readable. Which Cloud Run services have no minimum instances and cold-start into a timeout. Which projects have billing attached and no owner listed.

Each produces a genuinely useful list and each costs an afternoon of console navigation. A companion runs all three in one pass through an account you connect, and the service account behind the key decides what any of it reaches.

What should the service account look like?

New, single-purpose, and living in the project you want visible.

Not the default compute service account, which accumulates roles nobody remembers granting. Give it named predefined roles rather than `roles/editor`, and if the job is read-only, the viewer roles for the specific services are enough.

One detail worth planning for: a service account key does not expire. Put a calendar note to rotate it, because otherwise it is still valid in three years when nobody remembers what it was for.

  • A purpose-built service account, not the default compute or App Engine identity.
  • Predefined roles on named services, scoped to one project.
  • Viewer roles only, unless a specific workflow needs a write.
  • A rotation reminder, because the key itself has no expiry.

What is the connection good for?

Audit questions that span services.

Which buckets are publicly readable. Which Cloud Run services cold-start into a timeout. Which projects have billing attached and no owner listed. These produce a useful list and never get asked, because the answer costs an afternoon.

The Available tools section on the Google Cloud entry under `strawberry://settings/integrations` names every tool the connection exposes and marks the read-only ones. Read it, then set each action in the Permissions block to Ask every time, Always allow, or off. For a cloud project, switching off anything that creates or deletes resources is a comfortable default. If your estate spans providers, ai for it admins is the audience page.

A finding is worth more with its history attached

A public bucket is a fact.

Whether it is a mistake depends on what is in it and who put it there, and both live in a repository, a ticket, or a Slack thread from eight months ago.

A companion reads the cloud facts and then reads all three, in the accounts you are already signed into, and writes the finding up with the history attached. That is operations work rather than infrastructure work, and if the output is a ticket, product engineering is the neighbouring pattern.

Experience Strawberry for free

Download

Trusted by fast-growing companies worldwide

Frequently asked questions

It can use the actions Google Cloud’s API exposes, bounded by the roles on the service account behind the key. The Available tools list under Settings, Integrations shows the current set.

Strawberry is free to download and includes AI credits to start. Paid plans begin at $20/month. See pricing. · Reviewed · Canonical facts for AI agents

Experience Strawberry for free

Download

Trusted by fast-growing companies worldwide