Grant Cloud Access
grant_cloud_accessGive a workload credential-free access to AWS, GCP, or Azure resources through a cloud account: ensures the workload has an identity, binds the provider access to it (policyRefs or roleName for AWS, bindings or serviceAccount for GCP, roleAssignments for Azure), and waits until the identity reports it usable. The cloud account must exist already (create_cloud_account and how_to_create_cloud_account, full profile). Replaces this identity's existing provider configuration, so previous access can be revoked for every workload sharing the identity. No key passes through the chat.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| aws | No | With provider aws: policyRefs or roleName, one of the two. | |
| gcp | No | With provider gcp: bindings or serviceAccount, one of the two. | |
| gvc | Yes | GVC slug. If the user named none, list_resources (kind "gvc") and let them choose. | |
| org | No | Organization slug. | |
| azure | No | With provider azure. | |
| provider | Yes | ||
| workload | Yes | Workload that needs the access. | |
| waitSeconds | No | Seconds to wait on the server until the identity reports the access usable, 0 to 45. The call returns as soon as it is, or with the latest state when the time runs out. Use this instead of calling again and again. | |
| cloudAccount | Yes | An existing cloud account of that provider (create_cloud_account, full profile). |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ok | Yes | ||
| data | No | The full result. Read this, not only the summary. | |
| details | No | ||
| summary | Yes | ||
| nextSteps | No |