Description
Without Object Versioning, previous generations of overwritten or deleted objects are not retained by versioning. If no other recovery mechanism exists, accidental or malicious changes may be difficult to reverse.
Google Cloud recommends soft delete for protection against accidental or malicious deletion. Consider versioning as well when previous generations must remain directly readable. Versioning does not prevent every bucket deletion or permanent deletion of a specific generation.
Potential impact
- Object contents may be lost when no recoverable generation or backup remains.
- Keeping previous generations without limits can increase storage costs.
Remediation
Define the required recovery period and change history, then configure soft delete and Object Versioning accordingly. Set versioning.enabled to true when previous generations are needed. Review lifecycle rules, delete permissions and storage costs together, and test object recovery.
Examples
These examples compare versioning on the same bucket. Replace the bucket and project names and service account JSON file path with actual values. Soft delete and lifecycle rules are omitted.
Before
- name: 버킷 생성
google.cloud.gcp_storage_bucket:
name: ansible-storage-module
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
versioning:
enabled: no
This disables versioning for retaining new noncurrent generations. It does not itself delete previous generations that already exist.
After
- name: 버킷 생성
google.cloud.gcp_storage_bucket:
name: ansible-storage-module
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
versioning:
enabled: yes
This enables versioning to retain noncurrent generations after subsequent replacements or deletions. It does not recover data already lost or prevent every deletion of a specific generation.