Cloud KMS agent testing

Cloud KMS local testing for AI agents

Use LocalCloud when an agent needs to create, exercise, and reset Cloud KMS resources without touching a real Google Cloud project. The same SDK shape points at localhost through CLOUD_KMS_EMULATOR_HOST=http://localhost:24080.

Fact

Endpoint: CLOUD_KMS_EMULATOR_HOST=http://localhost:24080.

Fact

Endpoints: HTTP/REST :24080.

Fact

Evidence state: partial; Local development coverage is partial. Known limits: [prod_only] HSM (physical FIPS 140-2 Level 3 hardware) and EKM (external key manager providers)., Import jobs and Cloud HSM level enforcement are not implemented..

Fact

Registry default: off; assembled default: off (verified); minimum tier: pro.

Fact

Persistence: metadata (verified). Audited metadata survives restart while the LocalCloud volume is retained

Agent quickstart

Route the SDK before writing code

Start LocalCloud, export CLOUD_KMS_EMULATOR_HOST=http://localhost:24080, and make the agent perform one Cloud KMS operation before changing application logic. That catches accidental production routing early.

Validation example

Prefer one representative behavior over broad smoke tests

A useful agent check creates local Cloud KMS state, reads it back with the project SDK, and records which feature was covered. It should not require a GCP account, service-account key, or billing project.

State setup

Use only documented setup paths

Create deterministic state through a contract-documented seed registrar or through an operation listed on this page. Do not assume every service supports seed data, reset, or persistent state.

Copy-ready setup

Commands and prompts

Use these snippets as starting points, then keep the checks scoped to localhost until you intentionally validate against real Google Cloud.

Environment
eval "$(localcloud env)"
# Verify that the generated environment includes CLOUD_KMS_EMULATOR_HOST; do not replace a CLI-remapped value with a hard-coded port.
Compatibility

Local check versus release validation

AreaLocalCloud local checkReal GCP still needed for
SDK routingCLOUD_KMS_EMULATOR_HOST=http://localhost:24080 points clients at localhost.Production endpoint, auth, IAM, quota, and regional behavior.
Supported featureskey rings, crypto keys, versions (partial) — Local REST facade exists.; encrypt/decrypt/sign/verify (partial) — Crypto operation parity needs SDK and IAM tests.[prod_only] HSM (physical FIPS 140-2 Level 3 hardware) and EKM (external key manager providers).; Import jobs and Cloud HSM level enforcement are not implemented.
Agent safetyNo default cloud account, credentials, or billing project required.Final release validation in the target GCP project.
Limitations

Use the sandbox deliberately

  • Permitted workflows use local endpoint values and should stop rather than fall back to real Google Cloud or real credentials. The Public Preview License permits individuals and organizations, including for-profit companies, to use LocalCloud for non-production internal development, testing, CI, evaluation, and pilots.
  • LocalCloud emulates bounded local development workflows. Validate application behavior against real Google Cloud before production deployment.
  • Before production deployment, unset LocalCloud emulator environment variables and validate behavior against real Google Cloud.
  • Local development coverage is partial. Known limits: [prod_only] HSM (physical FIPS 140-2 Level 3 hardware) and EKM (external key manager providers)., Import jobs and Cloud HSM level enforcement are not implemented..
Next routes

Keep the agent on the supported path

  • Cloud KMS service page — Service-specific supported and unsupported capability list.
  • Compatibility matrix — Check current support boundaries before relying on a local-only test.
  • Service catalog — Review every LocalCloud service, endpoint, and limitation.
  • SDK examples — Use standard Google Cloud SDKs pointed at localhost.
  • Seed data — Load deterministic fixtures for repeatable agent and CI runs.
Sources and review

Claims are tied to current sources