Skip to main content
Glama

Grant Workload Secret Access

grant_workload_secret_access
Idempotent

Grant an EXISTING workload access to a secret: ensures the workload has an identity and creates/updates a policy binding with the reveal permission. Never returns secret values. The workload must already exist — for a NEW workload, call create_workload first, then this (a deployment referencing a secret stays paused until access is granted, then resumes). The secret must exist too — if missing, draft its manifest with placeholder values for the user to fill in and apply themselves (setup-secret skill), then re-run. Does NOT modify workload env/volumes — reference the secret there via cpln://secret/ in the spec. Recommended reading before first use: get_cpln_skill("setup-secret") — the runbook for this tool family (read once per session).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
gvcYesGVC slug (lowercase kebab-case). Use the GVC the user named; otherwise discover with list_resources (kind="gvc") and let them choose — never guess (a wrong GVC targets the wrong environment).
orgYesOrganization slug (lowercase kebab-case). NEVER guess — if the user has not named one, ask. On org-not-found, stop and ask; do not retry variants.
policyNameNoOptional org-scoped policy resource name to create/use; pass the name only. Omit to default to {gvc}-{workloadName}-secrets-policy.
secretNameYesExisting org-scoped secret name to grant access to; pass the name only, not cpln://secret/... or //secret/... .
identityNameNoOptional identity resource name to create/use in this GVC; pass the name only. Omit to default to {gvc}-{workloadName}.
workloadNameYesExisting workload name that should receive secret access; pass the name only, not a link.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYesWhether the call succeeded.
dataNoThe full machine-readable result — list rows, the resource object, query results. Read THIS, not just the summary.
summaryYesOne-line summary of the result.
nextStepsNoRecommended follow-up actions for this task, in order.

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond annotations (readOnlyHint=false, idempotentHint=true), the description adds valuable disclosures: never returns secret values, does NOT modify workload env/volumes, and creates/updates policy binding. It also explains the resume behavior of paused deployments. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is front-loaded with the core purpose, then proceeds through prerequisites, safety, non-behaviors, and resource pointers. Every sentence earns its place—no filler. The length is appropriate for a tool with 6 parameters and important caveats.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity (mutation, prerequisites, security considerations) and presence of output schema and annotations, the description is complete. It covers identity creation, policy binding, secret existence, non-modification of env/volumes, and references the skill runbook. No critical gaps remain.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description does not add parameter-specific meaning beyond the schema; it mentions 'pass the name only' indirectly through schema descriptions but not in the tool description itself. Schema already handles parameter semantics thoroughly.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb+resource+scope: "Grant an EXISTING workload access to a secret" and explains the mechanism (ensures identity, creates/updates policy binding with reveal permission). It clearly distinguishes this from sibling tools like create_identity or create_policy by framing it as a composite grant operation, not just identity or policy creation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states prerequisites and alternatives: workload must already exist (call create_workload first for new workloads), secret must exist (use setup-secret skill if missing), and points to get_cpln_skill("setup-secret") as recommended reading. It also mentions the behavioral consequence of deployment pausing until access is granted, giving clear when-to-use guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.1/5.0
Disambiguation5/5

Every tool targets a distinct resource/action pair (e.g., get_resource vs get_resource_schema, list_deployments vs list_workload_replicas) and descriptions clearly differentiate purposes. No two tools appear to do the same thing.

Naming Consistency5/5

All tools follow a verb_noun snake_case pattern (create_gvc, update_workload, list_resources, query_metrics) with consistent verbs. The few imperative verbs (browse, build, mount) still maintain the same verb-first structure.

Tool Count1/5

With 55 tools, this server far exceeds the typical well-scoped 3-15 tool range. While each tool appears purposeful, the sheer number creates selection overhead and falls into the extreme 50+ category on the rubric.

Completeness4/5

The surface covers nearly the full Control Plane lifecycle: CRUD for GVC, workload, identity, policy, volumeset, and domain, plus observability, templates, image builds, and Terraform. Minor gaps include referenced but missing configure_workload_* tools and no secret creation/deletion (by design).