Run app-agent in your own Google Cloud. Deployed in one click.
AAD provisions a production app-agent stack — GKE, Cloud Build, Artifact Registry, Secret Manager — inside your GCP project. You keep the data, the bill, and the off switch. We keep the automation.
# AppAgentDeployer — connect this# GCP project (keyless).→ enabling required APIs…→ creating deployer service account (aad-deployer@your-project.iam…)…→ granting provisioning roles (v2)…→ letting AAD's platform identities impersonate the deployer SA…✅ Done. No keys were created. Revoke anytime by deleting the SA.
Three steps, all in the open.
Connect
Run a short, readable script in your Cloud Shell. It creates an aad-deployer service account in your project and grants AAD's platform identity permission to mint short-lived tokens for it. No keys are created. None are exchanged. The whole script fits on one screen — read it before you run it.
Verify
Before touching anything, AAD impersonates that service account and proves the access actually works: a live IAM permission check and an enabled-API diff, shown to you as a checklist. The page turns green when your project is ready.
Deploy
Terraform and Cloud Build run inside your project: a GKE cluster, VPC and NAT, a Docker registry, your secrets in your Secret Manager. You watch every step stream live in the console.
Not another PaaS.
Your cloud, your bill.
Infrastructure lands in your GCP project at GCP prices. No marked-up compute, no resale margin, no surprise egress line-items — your invoice comes from Google.
No lock-in.
It's plain Terraform, GKE, and Cloud Build in your account — not a proprietary runtime. Delete one service account and AAD is locked out completely; everything already deployed keeps running, and it's yours.
No keys, ever.
Access is short-lived token impersonation — revocable with one command, visible in your audit logs. Read the full security model →
Bring your cloud. We'll bring the automation.
Design-partner slots are open now.