Review Cloud Storage usage logging

Collect logs for the audit purpose and manage their access and retention.

Description

Without Cloud Storage usage logs, it may be harder to analyze bucket requests or storage usage. These logs are separate from Cloud Audit Logs, so an absent usage logging configuration does not mean that all audit records are missing.

Consider Cloud Audit Logs first for most API auditing. Usage logs can support additional request analysis, but their delivery timing and completeness are not guaranteed.

Potential impact

  • Missing required request records can limit investigation of faults or suspicious access.
  • Public or excessive retention of request information in logs can increase exposure and cost.

Remediation

Choose Cloud Audit Logs and usage logs according to the audit purpose. If usage logs are needed, set logging.log_bucket to a destination that meets the service requirements and grant the cloud-storage-analytics@google.com group roles/storage.objectCreator on that bucket. Restrict log access and retention, and verify actual delivery.

Examples

Replace bucket and project names with actual values and provide the path to a service account JSON file. Prepare the log bucket first and meet service requirements such as location and organization compatibility with the source bucket.

Before

yaml
- name: 버킷 생성
  google.cloud.gcp_storage_bucket:
    name: ansible-storage-module
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present

This task has no usage log delivery configuration. Check separately collected Cloud Audit Logs and actual audit requirements.

After

yaml
- name: 버킷 생성
  google.cloud.gcp_storage_bucket:
    name: ansible-storage-module
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    logging:
      log_bucket: a_bucket_for_logs
      log_object_prefix: log

This configures delivery to a_bucket_for_logs with the log prefix. The destination and write permissions must be ready; the configuration does not itself create alerts.

References