An API router for Gemini proxy requests, deployable on Google Cloud Run. It provides API key management, request routing, usage metrics, and an administrative dashboard with Firebase Google Sign-In.
The Smart Router acts as a proxy for Gemini API requests, providing control over cost, access, and observability.
flowchart TD
A[Client Application] -->|Gemini API Protocol| B(Smart Router Backend - Port 8080)
A2[Admin User Browser] -->|HTML/HTMX UI| B2(Smart Router Frontend - Port 8081)
B2 -->|REST Admin API + OIDC| B
B -->|Validate API Key| C[(Firestore Native DB)]
B -->|Proxy Request| E[Official Gemini API / Vertex AI]
B2 -->|Google Sign-In| G[Firebase Authentication]
- Go (version 1.22 or higher)
- Google Cloud SDK (
gcloudCLI) - Terraform
- jq
- templ (Go HTML component compiler)
-
Copy the environment template:
cp .env.sample .env
-
Populate
.env:- Required User-Provided Variables:
PORT=8080 GOOGLE_CLOUD_PROJECT="your-gcp-project-id" GEMINI_LOCATION="us-central1"
- Firebase Web SDK Configurations (Keep default placeholders if planning to run automated deployment):
FIREBASE_API_KEY="AIzaSyYourFirebaseWebApiKey" FIREBASE_AUTH_DOMAIN="your-project-id.firebaseapp.com" FIREBASE_PROJECT_ID="your-gcp-project-id" FIREBASE_STORAGE_BUCKET="your-project-id.appspot.com" FIREBASE_MESSAGING_SENDER_ID="123456789" FIREBASE_APP_ID="1:1234:web:abcd"
- Required User-Provided Variables:
Tip
Don't fill out the Firebase configuration fields manually!
Running the automated ./deploy.sh script will automatically link Firebase, register a Web App, fetch these configuration values, and write them directly back into your local .env file. You only need to configure them manually if you are running local-only developer setups without GCP access.
If deploying to a new Google Cloud project:
- Enable Billing: Link your project to an active Billing Account.
- Configure OAuth Consent Screen: Go to APIs & Services > OAuth consent screen, select user type, and fill out the required fields.
- Enable Google Sign-In: Go to Identity Platform > Providers, add Google as a provider, and enable it.
gcloud auth login
gcloud config set project your-gcp-project-id
gcloud auth application-default login
gcloud auth application-default set-quota-project your-gcp-project-idFor security, there are no hardcoded default domains. You must explicitly set the allowed email domains or specific email addresses in your .env file before deployment:
ALLOWED_EMAIL_DOMAINS="yourcompany.com,operator@gmail.com"chmod +x deploy.sh
./deploy.sh- Loads
.envvariables. - Programmatically checks and configures Firebase Web App registration.
- Provisions infrastructure using Terraform (Cloud Run, Native Firestore, Secret Manager, Identity Toolkit).
- Generates HTML templates using
templ. - Builds and deploys the containers to Cloud Run.
- Runs post-deployment verification tests.
To manually configure Firebase credentials:
- Open the Firebase Console and select your Google Cloud Project.
- Register a new Web Application named
Smart Router Admin. - Copy the config values into
.env. - In Authentication > Sign-in method, enable the Google provider.
-
Download Go dependencies:
go mod download
-
Start the services:
./run_local.sh
- Backend:
http://localhost:8080 - Frontend Portal:
http://localhost:8081/login
- Backend:
Run integration and unit tests:
go test -v ./backend/proxy/... ./frontend/dashboard/...- Google GenAI SDK Coverage & Integration: Compatibility matrix, integration instructions, and key coverage gaps for the official
google-genaiSDKs. - API Key Integration: Client using HTTP Header (
x-goog-api-key) authentication. - Service Account IAM: Client using OIDC Token (
Authorization: Bearer) authentication.