What runs, and what backs it.
Every Google Cloud service CloudBurrow runs, what backs it, which start by default, and what each one will not do.
Started by default
cloudburrow up starts these with no flags.
| Service | Backed by | Scope | Not supported |
|---|---|---|---|
| Cloud Run | Knative Serving v1.23.0 behind a Cloud Run v2 adapter Knative | Services, revisions and jobs on the Cloud Run v2 API, run as real containers on Knative Serving. | Refused, each with the field named: traffic splitting, service accounts, VPC, volumes, CMEK, Binary Authorization and session affinity |
| Pub/Sub | Google's Pub/Sub emulator Google's emulator | Topics, subscriptions, publish, pull, StreamingPull and push, on Google's own emulator. | State does not survive a restart, a limitation of Google's emulator, measured |
| Cloud Storage | CloudBurrow's own server (next release); v0.1.0 uses fake-gcs-server CloudBurrow next release | The Cloud Storage JSON and XML APIs: buckets, objects, uploads, versioning, lifecycle and notifications to Pub/Sub. | Signed URLs: v0.1.0 accepts signed URLs on shape alone; on main, CloudBurrow's Storage server verifies V2 and V4 signatures and fails closed next release |
| Cloud Tasks | CloudBurrow CloudBurrow | Queues and tasks over gRPC and JSON, with HTTP dispatch, retries and enforced rate limits. | No App Engine targets |
| Secret Manager | CloudBurrow CloudBurrow | Secrets and versions over gRPC and JSON on one port. Not a secret store: nothing is authenticated. | Not a secret store: nothing is authenticated. |
Opt-in
Start these with --services, named in each row.
| Service | Backed by | Scope | Not supported |
|---|---|---|---|
Firestore and Datastore --services firestore,datastore | Google's Firestore and Datastore emulators Google's emulator | Documents, entities, collections and kinds on Google's own emulators, opt-in with --services. | In memory, except Datastore in persistent mode |
Spanner and Bigtable --services spanner,bigtable | Google's Spanner emulator 1.5.58 and Bigtable emulator Google's emulator | Instances, databases, DDL and queries on Spanner; tables, column families and rows on Bigtable. Google's emulators, opt-in. | In memory: nothing survives a restart, whatever --mode says |
BigQuery --services bigquery | goccy/bigquery-emulator 0.8.1 Community emulator | Datasets, tables, streaming inserts, SELECT and the Storage Read API (Arrow) on goccy/bigquery-emulator. | One project only |
Cloud SQL and Memorystore --services cloudsql,cloudsql-mysql,memorystore | PostgreSQL 17.11, MySQL 8.4.11 and Valkey Real engine | Real database engines reached with ordinary drivers: PostgreSQL and MySQL for Cloud SQL, Valkey for Redis clients. | No Cloud SQL Admin API: no instances, connection names, IAM database authentication, backups or replicas |
Cloud KMS --services kms | CloudBurrow CloudBurrow | Key rings, symmetric keys and versions over gRPC and JSON. Key material is stored unencrypted. | Not a security boundary: key material is stored unencrypted |
Cloud Scheduler and Cloud Logging --services scheduler,logging | CloudBurrow CloudBurrow | Cron jobs to HTTP and Pub/Sub targets, and log write and read with a filter subset. | Scheduler: no App Engine targets and no OIDC or OAuth tokens |
Built by CloudBurrow, or integrated
Integrated from Google: the Pub/Sub, Firestore, Datastore, Bigtable and Spanner emulators. Community: goccy/bigquery-emulator 0.8.1 (MIT). Real engines: PostgreSQL 17.11, MySQL 8.4.11 and Valkey. CloudBurrow's own: Cloud Tasks, Secret Manager, Cloud Scheduler, Cloud Logging, Cloud KMS, Resource Manager, the Cloud Run adapter, and (next release) the Cloud Storage server. next release
What each one serves, per RPC and with the test that proves it, is on the compatibility matrix.
Build against Google Cloud APIs, locally
Free and open source under Apache-2.0. No account, no sign-up, no Google Cloud bill.