Cloud Run
Backed by Knative Serving behind a Cloud Run v2 adapter
Deploys real containers. Configuration the adapter cannot map is refused with the field named.
CloudBurrow runs a local Kubernetes cluster that speaks Google Cloud APIs. Point the official Google client libraries at it and build without deploying for every change.
macOS and Linux, arm64 and amd64. Needs Docker, kind and kubectl. Windows is not supported. macOS binaries in v0.1.0 are not yet signed or notarized.
brew install cloudburrow/tap/cloudburrowcloudburrow up# in another shelleval "$(cloudburrow env)" Five services start by default. More start when you ask for them. Each card says what backs it, because that decides how far you can trust it.
Backed by Knative Serving behind a Cloud Run v2 adapter
Deploys real containers. Configuration the adapter cannot map is refused with the field named.
Backed by Google's own emulator
Topics, subscriptions, publish, pull, StreamingPull and push.
Backed by CloudBurrow's own server next release · v0.1.0 uses fake-gcs-server
Buckets, objects, versioning, lifecycle, CORS, XML multipart uploads and notifications to Pub/Sub.
Backed by CloudBurrow
Queues and tasks, pause and resume, HTTP dispatch with retry.
Backed by CloudBurrow
Secrets and versions over gRPC and JSON. Not a secret store: nothing is authenticated.
Start more with --services
Resource Manager projects are always on, so gcloud projects list and Terraform's
google_project work.
cloudburrow up creates a kind cluster in Docker. It starts Google's own emulators where
they exist and CloudBurrow's own services where they don't, then wires them together. Because it is
real Kubernetes, kubectl, Helm charts and operators work against it directly.
cloudburrow up serves a web console laid out after the Google Cloud console, with a
LOCAL badge on every screen. It is a view, not a second system: everything it shows is read through
the same APIs your SDK calls, and a control appears only where the backend can perform it.
It is not pixel-identical to Google's console, and it has no billing, quota or IAM screens.
Tour the console
CloudBurrow serves a subset of generateContent and streamGenerateContent,
verified with the official genai SDK on both the Vertex AI and Gemini API paths. It also
serves Google's custom prediction contract (AIP_* routes, instances in,
predictions out) on its own runtime.
One model runs today: a community conversion of Gemma (gemma-4-E2B-it), labelled as one
everywhere it appears. It is not Gemini, and output quality is not claimed. Text only, one turn, CPU
only. Embeddings are blocked (#41).
Compatibility is recorded per operation, not per service. An operation becomes Verified only through a
merged test that drives it through an official Google SDK. A curl script doesn't count. Everything else
is labelled: Refused with the field named, Unimplemented with a real UNIMPLEMENTED error,
Not served, or Unknown. The coverage table is generated from the APIs' proto definitions, and CI fails if
it goes stale.
"An emulator that quietly returns plausible responses is worse than one that returns a clear UNIMPLEMENTED."
| Service | Verified in v0.1.0 | Verified on main |
|---|---|---|
| Cloud Run | ||
| Pub/Sub | ||
| Cloud Storage | ||
| Cloud Tasks | ||
| Secret Manager |
Every step uses an official SDK. It runs on every merge.
A local emulator is for building and testing. These limits are deliberate or upstream. They are written down so you don't discover them in production.
Homebrew
brew install cloudburrow/tap/cloudburrowcloudburrow version Install script
curl -fsSL https://raw.githubusercontent.com/cloudburrow/cloudburrow/main/scripts/install.sh | sh It verifies the SHA-256 checksum and, when gh is installed, the GitHub build attestation. It refuses an archive it cannot verify.
From source
git clone https://github.com/cloudburrow/cloudburrow.gitcd cloudburrowmake build A plain go install build has no embedded Storage server, and up refuses it. Use make build.
Needs Docker (4 CPU / 6 GB), kind v0.33.0 and kubectl. macOS and Linux only; Windows is
unsupported and WSL2 is untested. macOS binaries in v0.1.0 are not yet signed or notarized
(#605). The console opens at http://127.0.0.1:9090 and
is labelled LOCAL.
cloudburrow doctor cloudburrow doctor changes nothing, and fails only on what would stop up.
cloudburrow up# in another shelleval "$(cloudburrow env)" import uuid
from google.cloud import storage
client = storage.Client()
bucket = client.create_bucket(f"example-{uuid.uuid4().hex[:12]}")
bucket.blob("hello.txt").upload_from_string("hello")
assert bucket.blob("hello.txt").download_as_text() == "hello"
bucket.delete(force=True)
This block is run by CloudBurrow's Python suite in CI. If it stops working, CI fails. docs/examples/python.md
import assert from 'node:assert/strict';
import { randomUUID } from 'node:crypto';
import { Storage } from '@google-cloud/storage';
const apiEndpoint = process.env.STORAGE_EMULATOR_HOST;
delete process.env.STORAGE_EMULATOR_HOST;
const storage = new Storage({ apiEndpoint, projectId: process.env.GOOGLE_CLOUD_PROJECT });
const [bucket] = await storage.createBucket(`example-${randomUUID()}`);
await bucket.file('hello.txt').save('hello', { resumable: false });
const [data] = await bucket.file('hello.txt').download();
assert.equal(data.toString(), 'hello');
await bucket.deleteFiles({ force: true });
await bucket.delete();
This block is run by CloudBurrow's Node.js suite in CI. If it stops working, CI fails. docs/examples/node.md
Go is tested through CloudBurrow's own compatibility suite. Java, .NET, Ruby and PHP are untested.
macOS binaries in v0.1.0 are not signed or notarized (#605). See Gatekeeper in docs/install.md.
Free and open source under Apache-2.0. No account, no sign-up, no Google Cloud bill.