Bucket versioning is not configured

Configure object versioning and other recovery controls to meet data retention needs.

Description

Cloud Storage Object Versioning helps recover earlier versions after files are overwritten or deleted. Review the required recovery coverage for buckets containing production data, deployment artifacts or backups.

Soft delete or separate backups may provide recovery even without versioning. Versioning itself does not prevent bucket deletion or an authorized user from deleting earlier versions.

Potential impact

  • Without the required earlier versions or other recovery options, accidental overwrites and deletions can be difficult to undo.
  • Incorrect retention and deletion policies can remove recovery points or increase storage costs.

Remediation

  • Set versioning.enabled: true for buckets that need to retain earlier versions.
  • Review soft delete, object lifecycle and retention policies together, restrict deletion permissions and test restoration.

Examples

These are excerpts in the retired Deployment Manager format. Apply the same retention policy through a supported management tool, and supply environment-specific names and omitted required settings.

Before

yaml
resources:
  - name: bucket
    type: storage.v1.bucket
    properties:
      name: my-bucket

After

yaml
resources:
  - name: bucket
    type: storage.v1.bucket
    properties:
      name: my-bucket
      versioning:
        enabled: true

Explanation:

  • Before: Object versioning is not specified. Check the effective versioning and other recovery policies on an existing bucket.
  • After: Versioning is enabled. This does not recover objects that were permanently deleted earlier.

References