01 — enoki — the pitch
Agentic ChatOps for Google Cloud.
enoki turns a Slack message into a typed, identity-aware GCP action — reads run instantly under your own IAM, and anything consequential waits for a one-click approval.
01 — enoki — the pitch
enoki turns a Slack message into a typed, identity-aware GCP action — reads run instantly under your own IAM, and anything consequential waits for a one-click approval.
02 — The problem
Answering "what is running, and who can touch it?" means leaving the thread the team already works in for consoles, CLIs, and runbooks.
03 — The idea
enoki is a Slack agent that runs Google Cloud in plain language. Every call executes under the asker’s own Google identity — their IAM is the only boundary.
04 — Two identities
The model runs as enoki’s own service account and only ever calls Vertex. Every data action runs under the user’s OAuth identity, refreshed at the point of use.
05 — The control
Every capability is an enumerated, validated tool — no run_gcloud, no raw SQL. Consequential writes pause for a one-click Approve / Deny in the thread.
06 — The coverage
BigQuery, Cloud Storage, Compute, Pub/Sub, Cloud SQL, Monitoring, Logging, plus IAM and billing reads — thirty-plus typed tools, and growing.
07 — Private by construction
enoki holds no Slack messages or cloud data outside your own project. Every GCP action is written to a structured, append-only audit trail.
08 — Where it runs
Deploy enoki to Cloud Run in your own GCP project. Shared state is Firestore, secrets sit in Secret Manager, and the runtime service account holds no data-plane access at all.
09 — The ask
enoki is ready to install to a Slack workspace and connect to Google Cloud. Add it, link your identity, and operate GCP from the thread you are already in.