Description
Cloud Storage Object Versioning helps recover earlier versions after files are overwritten or deleted. Review the required recovery coverage for buckets containing production data, deployment artifacts or backups.
Soft delete or separate backups may provide recovery even without versioning. Versioning itself does not prevent bucket deletion or an authorized user from deleting earlier versions.
Potential impact
- Without the required earlier versions or other recovery options, accidental overwrites and deletions can be difficult to undo.
- Incorrect retention and deletion policies can remove recovery points or increase storage costs.
Remediation
- Set
versioning.enabled: truefor buckets that need to retain earlier versions. - Review soft delete, object lifecycle and retention policies together, restrict deletion permissions and test restoration.
Examples
These are excerpts in the retired Deployment Manager format. Apply the same retention policy through a supported management tool, and supply environment-specific names and omitted required settings.
Before
yaml
resources:
- name: bucket
type: storage.v1.bucket
properties:
name: my-bucket
After
yaml
resources:
- name: bucket
type: storage.v1.bucket
properties:
name: my-bucket
versioning:
enabled: true
Explanation:
- Before: Object versioning is not specified. Check the effective versioning and other recovery policies on an existing bucket.
- After: Versioning is enabled. This does not recover objects that were permanently deleted earlier.