Pub/Sub emulator bypassing IAM enforcement during local testing
27K reputation · 27 May 2024, 14:38 UTC
The Google Cloud Pub/Sub emulator allows for local development by setting the PUBSUB_EMULATOR_HOST environment variable. However, when active, the emulator bypasses standard OAuth 2.0 token validation and IAM permission checks.
This current permissive behavior creates a discrepancy between local testing environments and production. While the emulator accepts requests regardless of missing credentials or mismatched project IDs, the production environment requires specific roles like roles/pubsub.publisher. This lack of IAM simulation means that code passing all local integration tests may still fail with PERMISSION_DENIED errors once deployed to a live environment.
Is there a documented configuration flag to enable basic IAM-like role validation within the emulator? How can developers verify that their service account possesses the necessary permissions without switching to live production-grade credentials?