Description
Without Cloud Storage usage logs, it may be harder to analyze bucket requests or storage usage. These logs are separate from Cloud Audit Logs, so an absent usage logging configuration does not mean that all audit records are missing.
Consider Cloud Audit Logs first for most API auditing. Usage logs can support additional request analysis, but their delivery timing and completeness are not guaranteed.
Potential impact
- Missing required request records can limit investigation of faults or suspicious access.
- Public or excessive retention of request information in logs can increase exposure and cost.
Remediation
Choose Cloud Audit Logs and usage logs according to the audit purpose. If usage logs are needed, set logging.log_bucket to a destination that meets the service requirements and grant the cloud-storage-analytics@google.com group roles/storage.objectCreator on that bucket. Restrict log access and retention, and verify actual delivery.
Examples
Replace bucket and project names with actual values and provide the path to a service account JSON file. Prepare the log bucket first and meet service requirements such as location and organization compatibility with the source bucket.
Before
- name: 버킷 생성
google.cloud.gcp_storage_bucket:
name: ansible-storage-module
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
This task has no usage log delivery configuration. Check separately collected Cloud Audit Logs and actual audit requirements.
After
- name: 버킷 생성
google.cloud.gcp_storage_bucket:
name: ansible-storage-module
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
logging:
log_bucket: a_bucket_for_logs
log_object_prefix: log
This configures delivery to a_bucket_for_logs with the log prefix. The destination and write permissions must be ready; the configuration does not itself create alerts.