This module configures keyless access from approved AWS workloads to Google-hosted native MCP servers. It creates a Google service account, enables the configured Google Cloud APIs, grants project IAM roles, and establishes AWS Workload Identity Federation without service-account keys.
| Name | Version |
|---|---|
| Terraform | >= 1.5.0 |
| Google provider | >= 6.46.0 |
The identity applying this module must be allowed to enable Google Cloud APIs, create service accounts and Workload Identity Federation resources, and manage the relevant project IAM bindings.
| Name | Source | Version |
|---|---|---|
google |
hashicorp/google |
>= 6.46.0 |
The module inherits the caller's Google provider configuration. It does not configure credentials or a provider alias.
Pin the module to a release tag when consuming it from GitHub:
module "gcp_mcp" {
source = "git::https://github.com/unblocked/terraform-google-cloud-integration.git?ref=v0.1.0"
project_id = "customer-project"
manage_required_services = true
native_mcp_service_account_id = "unblocked-gcp-access"
native_mcp_service_account_display_name = "Unblocked access to GCP MCP"
native_mcp_allowed_services = [
"compute.googleapis.com",
"logging.googleapis.com",
"monitoring.googleapis.com",
]
native_mcp_roles = [
"roles/logging.viewer",
"roles/monitoring.viewer",
"roles/serviceusage.serviceUsageConsumer",
"roles/viewer",
]
aws_account = {
account_id = "UNBLOCKED_AWS_ACCOUNT_ID"
role_names = [
"UNBLOCKED_GCP_BROKER_ROLE_NAME",
]
}
}All inputs intentionally have no defaults. This makes the APIs, IAM permissions, resource names, and trusted AWS identities visible in the customer's Terraform configuration.
The integration requires these foundational APIs:
| API | Purpose |
|---|---|
iam.googleapis.com |
Creates the service account, Workload Identity Pool, and AWS provider. |
iamcredentials.googleapis.com |
Generates short-lived access tokens for the Google service account. |
sts.googleapis.com |
Exchanges AWS credentials for Google federated tokens. |
Set manage_required_services = true for the normal self-contained installation. The module enables these APIs and internally waits for them before creating dependent IAM and WIF resources. The customer does not need to define separate google_project_service resources or add a module-level depends_on block.
module "gcp_mcp" {
source = "git::https://github.com/unblocked/terraform-google-cloud-integration.git?ref=v0.1.0"
manage_required_services = true
# Remaining inputs omitted from this example.
}Set manage_required_services = false only when the same Terraform configuration already manages all three APIs. In that case, the caller owns API lifecycle and ordering and should make the dependency explicit:
resource "google_project_service" "iam" {
project = var.project_id
service = "iam.googleapis.com"
}
resource "google_project_service" "iamcredentials" {
project = var.project_id
service = "iamcredentials.googleapis.com"
}
resource "google_project_service" "sts" {
project = var.project_id
service = "sts.googleapis.com"
}
module "gcp_mcp" {
source = "git::https://github.com/unblocked/terraform-google-cloud-integration.git?ref=v0.1.0"
manage_required_services = false
# Remaining inputs omitted from this example.
depends_on = [
google_project_service.iam,
google_project_service.iamcredentials,
google_project_service.sts,
]
}The module sets disable_on_destroy = false for APIs it enables. Removing the module therefore stops managing those API resources without disabling APIs that another workload might use.
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
project_id |
Google Cloud project in which to configure native MCP access. | string |
n/a | yes |
manage_required_services |
Whether the module enables the IAM, IAM Credentials, and Security Token Service APIs. Use false only when the caller already manages them. |
bool |
n/a | yes |
native_mcp_service_account_id |
Account ID for the native MCP service account and the basis of the WIF resource IDs. After removing one leading gcp-, the value must be 4–27 characters and must not still start with gcp-. |
string |
n/a | yes |
native_mcp_service_account_display_name |
Human-readable display name for the native MCP service account. | string |
n/a | yes |
native_mcp_allowed_services |
Google Cloud service hostnames whose native MCP tools may be called. The module enables these APIs and restricts roles/mcp.toolUser to this set. Must contain at least one service. |
set(string) |
n/a | yes |
native_mcp_roles |
Project IAM roles granted to the MCP service account for access to underlying Google Cloud data. May be empty, but MCP tools will only succeed when the account has the permissions they require. | set(string) |
n/a | yes |
aws_account |
Trusted Unblocked AWS account ID and the non-empty set of exact broker role names allowed to federate. | object({ account_id = string, role_names = set(string) }) |
n/a | yes |
The module derives the WIF pool and provider IDs from native_mcp_service_account_id. For example, unblocked-gcp-access creates service account unblocked-gcp-access, pool unblocked-gcp-access-pool, and provider unblocked-gcp-access. Because Google reserves the gcp- prefix for WIF IDs, the module removes that prefix when deriving WIF names. Keep the service-account ID stable after the initial apply because changing it replaces these resources, which changes the service_account_email and aws_workload_identity_provider outputs and requires re-sending them to Unblocked.
native_mcp_allowed_services and native_mcp_roles control two independent authorization layers, and a native MCP tool call succeeds only when both permit it:
native_mcp_allowed_servicesenables each service's API and scopes theroles/mcp.toolUsercondition to that set. This governs only whether the service account may invoke the native MCP tools for those services.native_mcp_rolesgrants the IAM roles the service account uses to read data. When a tool runs, it calls the underlying Google Cloud API as the service account, and that call is checked against these roles.
Adding a service to native_mcp_allowed_services enables its API and permits the tool call, but does not by itself let the service account read that service's data. Add a role that covers it to native_mcp_roles as well. Basic roles/viewer already covers most resource metadata, but data-plane content — log entries, monitoring data, storage objects, secret payloads — requires the service's specific viewer role (for example roles/logging.viewer for Cloud Logging). Without a covering role, the tool is callable but the underlying read is denied.
| Name | Description |
|---|---|
service_account_email |
Native MCP service account email to provide to Unblocked. |
aws_workload_identity_provider |
WIF provider resource name (projects/{number}/locations/global/workloadIdentityPools/{pool}/providers/{provider}) to provide to Unblocked. |
Terraform does not automatically promote a child module's outputs to the root module. Re-export the two identifiers from the customer's configuration:
output "unblocked_service_account_email" {
value = module.gcp_mcp.service_account_email
description = "Service account email to provide to Unblocked after onboarding."
}
output "unblocked_aws_workload_identity_provider" {
value = module.gcp_mcp.aws_workload_identity_provider
description = "WIF provider resource name to provide to Unblocked after onboarding."
}After applying, retrieve them with:
terraform output -raw unblocked_service_account_email
terraform output -raw unblocked_aws_workload_identity_providerDepending on the inputs, the module creates:
- The configured Google Cloud API service resources.
- One Google service account for native MCP access.
- Project IAM bindings for
native_mcp_roles. - A conditional
roles/mcp.toolUserbinding restricted tonative_mcp_allowed_services. - One AWS Workload Identity Pool.
- One AWS WIF provider and service-account
roles/iam.workloadIdentityUserbinding for the configured AWS account.
- Authentication uses short-lived AWS and Google credentials; the module does not create service-account keys.
roles/mcp.toolUseris conditioned on the configured Google Cloud service allowlist.native_mcp_rolescontrols which underlying Google Cloud resources and data the MCP service account can read.