personal-gemini-journal-H2S-

Personal Gemini Journal

Personal Gemini Journal is a production-oriented journaling and brainstorming app. Users sign in with Firebase Authentication, continue private multi-turn Gemini conversations, and save their own Insight Cards in Firestore. The Cloud Run server verifies Firebase ID tokens before every private operation.

What is included

Local setup

  1. Create a Firebase project and enable Email/Password sign-in and Firestore.
  2. Publish firestore.rules.
  3. In the web app environment, set the public Firebase configuration:

    VITE_FIREBASE_API_KEY
    VITE_FIREBASE_AUTH_DOMAIN
    VITE_FIREBASE_PROJECT_ID
    VITE_FIREBASE_STORAGE_BUCKET
    VITE_FIREBASE_MESSAGING_SENDER_ID
    VITE_FIREBASE_APP_ID
    
  4. For local server development, use Application Default Credentials or set FIREBASE_SERVICE_ACCOUNT_JSON through a secure local secret mechanism. Never commit it.
  5. Set GEMINI_API_KEY only in the server environment. The browser must never receive it.
  6. Start the API and web workflows from the project controls.

Cloud Run deployment

The container serves both the built web app and /api from one Cloud Run service. For a copy/paste walkthrough, use DEPLOYMENT_GUIDE.md. Firebase web values are passed as Docker build arguments because they are public browser configuration; the Gemini key is never passed to the build and is injected at runtime from Secret Manager.

gcloud builds submit --tag REGION-docker.pkg.dev/PROJECT_ID/journal/personal-gemini-journal
gcloud run deploy personal-gemini-journal \
  --image REGION-docker.pkg.dev/PROJECT_ID/journal/personal-gemini-journal \
  --region REGION \
  --allow-unauthenticated \
  --set-env-vars FIREBASE_PROJECT_ID=PROJECT_ID,WEB_ORIGIN=https://YOUR_CLOUD_RUN_HOSTNAME \
  --set-secrets GEMINI_API_KEY=gemini-api-key:latest

Before deployment, create the secret and grant the Cloud Run runtime service account roles/secretmanager.secretAccessor:

printf '%s' 'YOUR_GEMINI_API_KEY' | gcloud secrets create gemini-api-key --data-file=-
gcloud secrets add-iam-policy-binding gemini-api-key \
  --member="serviceAccount:PROJECT_NUMBER-compute@developer.gserviceaccount.com" \
  --role="roles/secretmanager.secretAccessor"

Use the Google Cloud project service account’s Application Default Credentials for Firebase Admin SDK. Do not put a service-account JSON file in the image.

Security submission checklist

Verification commands

pnpm run typecheck
pnpm --filter @workspace/api-server run typecheck
pnpm --filter @workspace/personal-gemini-journal run build

The app intentionally shows a clear setup state when public Firebase configuration is absent; it never fabricates authentication or silently uses a shared demo account.