Skip to main content
Glama

Grant Workload Secret Access

grant_workload_secret_access
Destructive

Grant an EXISTING workload access to a secret: ensures it has an identity and a policy binding with reveal, and redeploys it when it is waiting on the secret. Use it rather than create_identity or create_policy. Never returns values. For a NEW workload, create_workload first; its deployment pauses on the reference until access is granted, then resumes. A missing secret: create_secret first. Does not edit env or volumes: reference the secret there as cpln://secret/NAME.KEY.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
gvcYesGVC slug. If the user named none, list_resources (kind "gvc") and let them choose.
orgNoOrganization slug.
policyNameNoOptional org-scoped policy resource name to create/use; pass the name only. Omit to default to {gvc}-{workloadName}-secrets-policy; another name adds a second policy for the same workload.
secretNameYesExisting org-scoped secret name to grant access to; pass the name only, not cpln://secret/... or //secret/... .
identityNameNoOptional identity resource name to create/use in this GVC; pass the name only. Omit to default to {gvc}-{workloadName}.
workloadNameYesExisting workload name that should receive secret access; pass the name only, not a link.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYes
dataNoThe full result. Read this, not only the summary.
detailsNo
summaryYes
nextStepsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed31 schema fields changed
    • removedInput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedInput schema / additionalProperties
      Removed value: -false
    • changedInput schema / properties / gvc / description
      Previous value: -"GVC slug (lowercase kebab-case). Use the GVC the user named; otherwise discover with list_resources (kind=\"gvc\") and let them choose — never guess (a wrong GVC targets the wrong environment)."New value: +"GVC slug. If the user named none, list_resources (kind \"gvc\") and let them choose."
    • removedInput schema / properties / gvc / maxLength
      Removed value: -63
    • removedInput schema / properties / gvc / minLength
      Removed value: -1
    • removedInput schema / properties / gvc / pattern
      Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
    • removedInput schema / properties / identityName / maxLength
      Removed value: -64
    • removedInput schema / properties / identityName / minLength
      Removed value: -2
    • removedInput schema / properties / identityName / pattern
      Removed value: -"^[a-z]([-a-z0-9])*[a-z0-9]$"
    • changedInput schema / properties / org / description
      Previous value: -"Organization slug (lowercase kebab-case). NEVER guess — if the user has not named one, ask. On org-not-found, stop and ask; do not retry variants."New value: +"Organization slug."
    • removedInput schema / properties / org / maxLength
      Removed value: -63
    • removedInput schema / properties / org / minLength
      Removed value: -1
    • removedInput schema / properties / org / pattern
      Removed value: -"^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$"
    • changedInput schema / properties / policyName / description
      Previous value: -"Optional org-scoped policy resource name to create/use; pass the name only. Omit to default to {gvc}-{workloadName}-secrets-policy."New value: +"Optional org-scoped policy resource name to create/use; pass the name only. Omit to default to {gvc}-{workloadName}-secrets-policy; another name adds a second policy for the same workload."
    • removedInput schema / properties / policyName / maxLength
      Removed value: -64
    • removedInput schema / properties / policyName / minLength
      Removed value: -2
    • removedInput schema / properties / policyName / pattern
      Removed value: -"^[a-z]([-a-z0-9])*[a-z0-9]$"
    • removedInput schema / properties / secretName / maxLength
      Removed value: -64
    • removedInput schema / properties / secretName / minLength
      Removed value: -2
    • removedInput schema / properties / secretName / pattern
      Removed value: -"^[a-z]([-a-z0-9])*[a-z0-9]$"
    • removedInput schema / properties / workloadName / maxLength
      Removed value: -64
    • removedInput schema / properties / workloadName / minLength
      Removed value: -2
    • removedInput schema / properties / workloadName / pattern
      Removed value: -"^[a-z]([-a-z0-9])*[a-z0-9]$"
    • changedInput schema / required
      Previous value: -[
      -  "org",
      -  "gvc",
      -  "workloadName",
      -  "secretName"
      -]New value: +[
      +  "gvc",
      +  "workloadName",
      +  "secretName"
      +]
    • removedOutput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedOutput schema / additionalProperties
      Removed value: -false
    • changedOutput schema / properties / data / description
      Previous value: -"The full machine-readable result — list rows, the resource object, query results. Read THIS, not just the summary."New value: +"The full result. Read this, not only the summary."
    • addedOutput schema / properties / details
      Added value: +{
      +  "type": "string"
      +}
    • removedOutput schema / properties / nextSteps / description
      Removed value: -"Recommended follow-up actions for this task, in order."
    • removedOutput schema / properties / ok / description
      Removed value: -"Whether the call succeeded."
    • removedOutput schema / properties / summary / description
      Removed value: -"One-line summary of the result."
  2. Added

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructive=true and idempotent=false, and the description adds real substance on top: it creates identity + policy side effects, redeploys a paused workload, and does not touch env/volumes. It also notes 'Never returns values' and the pause/resume lifecycle. Minor tension: an output schema exists despite the 'never returns values' claim.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Dense but front-loaded: purpose and sibling routing lead, prerequisites and caveats follow in short clauses. Every sentence carries information, though the run-on colon-clause style takes a second read.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a non-idempotent, destructive mutation with an output schema present, the description covers prerequisites, side effects, alternatives, and explicit non-effects. Nothing an agent needs to invoke it safely is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so defaults for policyName/identityName, the naming conventions, and the 'pass the name only' constraints are already fully documented in the schema. The description adds only one param-adjacent detail — the cpln://secret/NAME.KEY reference form — which is marginal given the thorough schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Grant an EXISTING workload access to a secret') and immediately enumerates the mechanics (creates identity, policy binding with reveal, redeploys). It also explicitly separates itself from create_identity, create_policy, create_workload, and create_secret, so the agent can route without opening sibling schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives explicit routing ('Use it rather than create_identity or create_policy') and ordered prerequisites for two edge cases: new workload (create_workload first) and missing secret (create_secret first). It also states what the tool does NOT do (no env/volume edits) and how to reference the secret instead.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.