firebase
Installation
SKILL.md
Firebase — Firestore, Rules, Auth, Functions, Storage
The Firebase product surface that sits on top of GCP, on the modular Web SDK (v12) and the Admin SDK. The whole skill exists to stop two failure modes: dragging relational/SQL habits into a NoSQL document store, and leaving the database open to the internet.
Two facts drive everything below:
- It is a NoSQL document store, shaped for the read path. No joins, no server-side
ORacross different fields without a composite index, noSELECT *across collections. Denormalize and fan-out so a screen is one cheap query — reads are what you pay for and what users wait on. - Rules ARE the access control. Firestore is reachable directly from untrusted clients. There is
no app server in the trust path by default —
firestore.rules(CEL) is the only thing between a browser and your data. App Check attests the request even came from your app before Rules evaluate.
Not this skill: