Services Overview
floci-gcp serves its emulated GCP APIs on a single port (4588) using real GCP wire protocols. Supported SDK and gcloud operations work after the client is configured to use the emulator endpoint.
Service Matrix
| Service | Protocol | Endpoint |
|---|---|---|
| Compute Engine | REST JSON | /compute/v1/projects/{project}/... |
| Cloud Storage (GCS) | gRPC v2 + REST XML + REST JSON | google.storage.v2.Storage, /{bucket}/{object}, /storage/v1/b/{bucket} |
| Pub/Sub | gRPC + REST JSON | google.pubsub.v1.Publisher, google.pubsub.v1.Subscriber, /v1/projects/{project}/topics |
| Firestore | gRPC | google.firestore.v1.Firestore |
| Datastore | gRPC + HTTP/protobuf | google.datastore.v1.Datastore, /v1/projects/{project}:{method} |
| Secret Manager | gRPC + REST JSON | google.cloud.secretmanager.v1.SecretManagerService, /v1/projects/{project}/secrets |
| Cloud Logging | gRPC + REST JSON | google.logging.v2.LoggingServiceV2, /v2/entries:write, /v2/entries:list |
| Cloud KMS | gRPC + REST JSON | google.cloud.kms.v1.KeyManagementService, /v1/projects/{project}/locations/{location}/keyRings |
| IAM | REST JSON | /v1/projects/{project}/serviceAccounts |
| IAM Credentials | REST JSON | /v1/projects/-/serviceAccounts/{sa}:generateAccessToken |
| Security Token Service (STS) | REST JSON | /v1/token |
| Managed Kafka | REST JSON | /v1/projects/{project}/locations/{location}/clusters |
| GKE (Kubernetes Engine) | REST JSON | container.* host or /container/v1/projects/{project}/locations/{location}/clusters |
| Cloud SQL (PostgreSQL, MySQL) | REST JSON | /v1/projects/{project}/instances |
| Cloud Run | REST JSON | /v2/projects/{project}/locations/{location}/{services,jobs,workerPools,instances} |
| Cloud Functions | REST JSON | /v2/projects/{project}/locations/{location}/functions |
| Cloud Tasks | gRPC | google.cloud.tasks.v2.CloudTasks |
| Cloud Scheduler | gRPC + REST JSON | google.cloud.scheduler.v1.CloudScheduler, /v1/projects/{project}/locations/{location}/jobs |
| Cloud Monitoring | gRPC + REST JSON | google.monitoring.v3.MetricService, /v3/projects/{project} |
| Service Usage | REST JSON | /v1/projects/{project}/services |
| Resource Manager | REST JSON | /v1/projects/{projectId}, IAM policy mixins |
| Eventarc | REST JSON | /v1/projects/{project}/locations/{location}/triggers |
| Firebase Auth | REST JSON | /identitytoolkit.googleapis.com/v1/accounts:*, /securetoken.googleapis.com/v1/token |
| BigQuery | REST JSON | /bigquery/v2/projects/{project} |
Single-Port Design
All emulated API endpoints, including gRPC, REST, and binary HTTP/protobuf, are available on port 4588 via ALPN negotiation:
http2=true: enables HTTP/2 supportgrpc.server.use-separate-server=false: gRPC and HTTP APIs share the same port
Clients using plain HTTP/1.1 are served REST or binary HTTP/protobuf endpoints. Clients using HTTP/2 (gRPC) are served gRPC endpoints. Docker-backed Kafka, PostgreSQL, and Kubernetes data planes expose separate generated endpoints for their native protocols.
Common Setup
Before calling any service, set the appropriate emulator environment variable:
export PUBSUB_EMULATOR_HOST=localhost:4588
export FIRESTORE_EMULATOR_HOST=localhost:4588
export DATASTORE_EMULATOR_HOST=localhost:4588
export STORAGE_EMULATOR_HOST=http://localhost:4588
export SECRET_MANAGER_EMULATOR_HOST=localhost:4588
GCP SDKs automatically bypass credential validation when these variables are set. Some REST management SDKs, including Cloud Run and Cloud Functions, do not have emulator environment variables; configure their client endpoint explicitly as http://localhost:4588 and use no credentials.
For gcloud CLI:
Auth Bypass
With the default IAM authorization mode, floci-gcp does not cryptographically validate credentials. Requests with no credential, external credentials, and Floci-issued OAuth or impersonated tokens are accepted. Floci-issued downscoped GCS tokens are constrained by their Credential Access Boundary (CAB); in enforce mode, supported GCS REST bucket and object operations also evaluate stored bucket IAM allow policies using the retained source principal. This otherwise matches the behavior of GCP official emulators when *_EMULATOR_HOST is set. See the IAM service guide for scope and exclusions.
Multi-Project Isolation
All resources are namespaced by GCP project ID. Resources in project-a are invisible to project-b. See Multi-Project Isolation.