AI code review for Google Cloud

Proofline runs AI code review against the Google Cloud project each pull request deploys to. It needs no stored Google key to read your services, databases, images, and builds.

What Proofline reads from Google Cloud

  • Cloud Run: revisions, readiness, traffic targets, scaling limits, container images and resources, and environment variable names.
  • Cloud SQL: instance state, database version, tier, availability, backups, replicas, and the database flags you set.
  • Artifact Registry: image digests and tags, and optionally the platforms inside a multi-platform image.
  • Cloud Build: build status, the source revision Cloud Build resolved, and the image digests it pushed.
  • Pub/Sub, Compute Engine, and GKE: subscription settings, instance configuration, and live cluster objects.

Proofline also reads OpenTofu or Terraform state from a Cloud Storage backend. Check the scope of each integration.

A build that never shipped

In this illustrative example, a pull request changes a deployment workflow to promote the image tagged stable to production.

The Artifact Registry evidence shows that stable points at a digest from an older Cloud Build run. The newest build pushed a different digest and never moved the tag.

The suggested fix deploys by digest, so production runs the image the build produced. The finding cites the tag, both digests, and the build record.

Access without a stored key

The Google Cloud setup gives you an installer to review and apply in your own project. It creates a workload identity pool and a service account with read permissions.

Proofline exchanges its own identity for a short-lived Google token each time it reads. It stores no Google key, and it never caches the token.

When a source cannot be read, Proofline marks the review incomplete and names that source.

Questions

Does Proofline store a Google Cloud service account key?

No. Proofline uses workload identity federation to get a short-lived token for each read, and keeps no key.

Can Proofline see secret values in Cloud Run?

No. Proofline reads Cloud Run environment variable names, and for secret-backed variables the secret and version they reference. It never reads the values.

Which Google Cloud services can Proofline read?

Proofline reads Cloud Run, Cloud SQL, Artifact Registry, Cloud Build, Pub/Sub, Compute Engine, GKE, and Terraform or OpenTofu state in Cloud Storage.

Connect a Google Cloud project.

Review Cloud Run deployments or review Kubernetes workloads.

Get Started with GitHub