Skip to content

Services Overview

floci-gcp serves its emulated GCP APIs on a single port (4588) using real GCP wire protocols. Supported SDK and gcloud operations work after the client is configured to use the emulator endpoint.

Service Matrix

Service Protocol Endpoint
Compute Engine REST JSON /compute/v1/projects/{project}/...
Cloud Storage (GCS) gRPC v2 + REST XML + REST JSON google.storage.v2.Storage, /{bucket}/{object}, /storage/v1/b/{bucket}
Pub/Sub gRPC + REST JSON google.pubsub.v1.Publisher, google.pubsub.v1.Subscriber, /v1/projects/{project}/topics
Firestore gRPC google.firestore.v1.Firestore
Datastore gRPC + HTTP/protobuf google.datastore.v1.Datastore, /v1/projects/{project}:{method}
Secret Manager gRPC + REST JSON google.cloud.secretmanager.v1.SecretManagerService, /v1/projects/{project}/secrets
Cloud Logging gRPC + REST JSON google.logging.v2.LoggingServiceV2, /v2/entries:write, /v2/entries:list
Cloud KMS gRPC + REST JSON google.cloud.kms.v1.KeyManagementService, /v1/projects/{project}/locations/{location}/keyRings
IAM REST JSON /v1/projects/{project}/serviceAccounts
IAM Credentials REST JSON /v1/projects/-/serviceAccounts/{sa}:generateAccessToken
Security Token Service (STS) REST JSON /v1/token
Managed Kafka REST JSON /v1/projects/{project}/locations/{location}/clusters
GKE (Kubernetes Engine) REST JSON container.* host or /container/v1/projects/{project}/locations/{location}/clusters
Cloud SQL (PostgreSQL, MySQL) REST JSON /v1/projects/{project}/instances
Cloud Run REST JSON /v2/projects/{project}/locations/{location}/{services,jobs,workerPools,instances}
Cloud Functions REST JSON /v2/projects/{project}/locations/{location}/functions
Cloud Tasks gRPC google.cloud.tasks.v2.CloudTasks
Cloud Scheduler gRPC + REST JSON google.cloud.scheduler.v1.CloudScheduler, /v1/projects/{project}/locations/{location}/jobs
Cloud Monitoring gRPC + REST JSON google.monitoring.v3.MetricService, /v3/projects/{project}
Service Usage REST JSON /v1/projects/{project}/services
Resource Manager REST JSON /v1/projects/{projectId}, IAM policy mixins
Eventarc REST JSON /v1/projects/{project}/locations/{location}/triggers
Firebase Auth REST JSON /identitytoolkit.googleapis.com/v1/accounts:*, /securetoken.googleapis.com/v1/token
BigQuery REST JSON /bigquery/v2/projects/{project}

Single-Port Design

All emulated API endpoints, including gRPC, REST, and binary HTTP/protobuf, are available on port 4588 via ALPN negotiation:

  • http2=true: enables HTTP/2 support
  • grpc.server.use-separate-server=false: gRPC and HTTP APIs share the same port

Clients using plain HTTP/1.1 are served REST or binary HTTP/protobuf endpoints. Clients using HTTP/2 (gRPC) are served gRPC endpoints. Docker-backed Kafka, PostgreSQL, and Kubernetes data planes expose separate generated endpoints for their native protocols.

Common Setup

Before calling any service, set the appropriate emulator environment variable:

export PUBSUB_EMULATOR_HOST=localhost:4588
export FIRESTORE_EMULATOR_HOST=localhost:4588
export DATASTORE_EMULATOR_HOST=localhost:4588
export STORAGE_EMULATOR_HOST=http://localhost:4588
export SECRET_MANAGER_EMULATOR_HOST=localhost:4588

GCP SDKs automatically bypass credential validation when these variables are set. Some REST management SDKs, including Cloud Run and Cloud Functions, do not have emulator environment variables; configure their client endpoint explicitly as http://localhost:4588 and use no credentials.

For gcloud CLI:

gcloud config set project floci-local

Auth Bypass

With the default IAM authorization mode, floci-gcp does not cryptographically validate credentials. Requests with no credential, external credentials, and Floci-issued OAuth or impersonated tokens are accepted. Floci-issued downscoped GCS tokens are constrained by their Credential Access Boundary (CAB); in enforce mode, supported GCS REST bucket and object operations also evaluate stored bucket IAM allow policies using the retained source principal. This otherwise matches the behavior of GCP official emulators when *_EMULATOR_HOST is set. See the IAM service guide for scope and exclusions.

Multi-Project Isolation

All resources are namespaced by GCP project ID. Resources in project-a are invisible to project-b. See Multi-Project Isolation.