Review Cloud Storage object versioning

Configure protection for object history and deletion recovery requirements.

Description

Without Object Versioning, previous generations of overwritten or deleted objects are not retained by versioning. If no other recovery mechanism exists, accidental or malicious changes may be difficult to reverse.

Google Cloud recommends soft delete for protection against accidental or malicious deletion. Consider versioning as well when previous generations must remain directly readable. Versioning does not prevent every bucket deletion or permanent deletion of a specific generation.

Potential impact

  • Object contents may be lost when no recoverable generation or backup remains.
  • Keeping previous generations without limits can increase storage costs.

Remediation

Define the required recovery period and change history, then configure soft delete and Object Versioning accordingly. Set versioning.enabled to true when previous generations are needed. Review lifecycle rules, delete permissions and storage costs together, and test object recovery.

Examples

These examples compare versioning on the same bucket. Replace the bucket and project names and service account JSON file path with actual values. Soft delete and lifecycle rules are omitted.

Before

yaml
- name: 버킷 생성
  google.cloud.gcp_storage_bucket:
    name: ansible-storage-module
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    versioning:
      enabled: no

This disables versioning for retaining new noncurrent generations. It does not itself delete previous generations that already exist.

After

yaml
- name: 버킷 생성
  google.cloud.gcp_storage_bucket:
    name: ansible-storage-module
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    versioning:
      enabled: yes

This enables versioning to retain noncurrent generations after subsequent replacements or deletions. It does not recover data already lost or prevent every deletion of a specific generation.

References