Personal Gemini Journal is a production-oriented journaling and brainstorming app. Users sign in with Firebase Authentication, continue private multi-turn Gemini conversations, and save their own Insight Cards in Firestore. The Cloud Run server verifies Firebase ID tokens before every private operation.
users/{uid}/journals and users/{uid}/insights.GEMINI_API_KEY.docs/AI_STUDIO_CUSTOM_INSTRUCTIONS.md.DEPLOYMENT_GUIDE.md.firestore.rules.In the web app environment, set the public Firebase configuration:
VITE_FIREBASE_API_KEY
VITE_FIREBASE_AUTH_DOMAIN
VITE_FIREBASE_PROJECT_ID
VITE_FIREBASE_STORAGE_BUCKET
VITE_FIREBASE_MESSAGING_SENDER_ID
VITE_FIREBASE_APP_ID
FIREBASE_SERVICE_ACCOUNT_JSON through a secure local secret mechanism. Never commit it.GEMINI_API_KEY only in the server environment. The browser must never receive it.The container serves both the built web app and /api from one Cloud Run service.
For a copy/paste walkthrough, use DEPLOYMENT_GUIDE.md. Firebase web values are
passed as Docker build arguments because they are public browser configuration;
the Gemini key is never passed to the build and is injected at runtime from
Secret Manager.
gcloud builds submit --tag REGION-docker.pkg.dev/PROJECT_ID/journal/personal-gemini-journal
gcloud run deploy personal-gemini-journal \
--image REGION-docker.pkg.dev/PROJECT_ID/journal/personal-gemini-journal \
--region REGION \
--allow-unauthenticated \
--set-env-vars FIREBASE_PROJECT_ID=PROJECT_ID,WEB_ORIGIN=https://YOUR_CLOUD_RUN_HOSTNAME \
--set-secrets GEMINI_API_KEY=gemini-api-key:latest
Before deployment, create the secret and grant the Cloud Run runtime service account roles/secretmanager.secretAccessor:
printf '%s' 'YOUR_GEMINI_API_KEY' | gcloud secrets create gemini-api-key --data-file=-
gcloud secrets add-iam-policy-binding gemini-api-key \
--member="serviceAccount:PROJECT_NUMBER-compute@developer.gserviceaccount.com" \
--role="roles/secretmanager.secretAccessor"
Use the Google Cloud project service account’s Application Default Credentials for Firebase Admin SDK. Do not put a service-account JSON file in the image.
docs/AI_STUDIO_CUSTOM_INSTRUCTIONS.md.firestore.rules.GEMINI_API_KEY from Secret Manager.pnpm run typecheck
pnpm --filter @workspace/api-server run typecheck
pnpm --filter @workspace/personal-gemini-journal run build
The app intentionally shows a clear setup state when public Firebase configuration is absent; it never fabricates authentication or silently uses a shared demo account.