Cloud Storage bucket ACLs need review

Review effective Cloud Storage ACL and IAM permissions and remove unnecessary public access. Omitting an ACL does not itself make a bucket public.

Description

In Cloud Storage, allUsers includes anonymous users, and allAuthenticatedUsers is not limited to users in the same project. Unnecessary grants to these entities can expose buckets or objects beyond the intended audience.

Allowed operations depend on the role and resource. A bucket's READER role allows object listing, which is different from permission to read object contents. defaultObjectAcl applies to new objects whose upload does not specify a separate ACL; changing it does not update existing object ACLs.

A bucket created without an explicit ACL uses projectPrivate by default, so omission alone does not mean public access. Uniform bucket-level access disables ACLs and uses IAM for permissions. Review the effective IAM policy and public access prevention settings as well.

Potential impact

  • Objects with public read permission can disclose their contents to unintended users. Bucket listing permission alone does not allow reading every object.
  • Public write permissions can let external users create, replace, or delete objects.
  • A public default object ACL can expose objects uploaded afterward.

Remediation

  • Review effective IAM policies and ACLs and remove unnecessary public grants. Apply public access prevention to buckets that do not need to be public.
  • Before enabling uniform bucket-level access, migrate required ACL-based permissions to IAM. Do not add ACLs to a bucket that already uses this feature.
  • If ACLs are necessary, grant only the required roles to specific entities and review both existing objects and the default object ACL. Test that required access still works and unwanted access is denied.

Examples

These are partial examples for existing Deployment Manager templates. Replace the bucket name for your environment and consult the service's deprecation and migration guidance.

Using the default ACL

yaml
resources:
  - name: storage-bucket
    type: storage.v1.bucket
    properties:
      name: my-bucket

This example creates a bucket without specifying an ACL. Review the effective IAM permissions and bucket access controls before deciding whether it is public.

Granting read access to one user

yaml
resources:
  - name: storage-bucket
    type: storage.v1.bucket
    properties:
      name: my-bucket
      acl:
        - entity: user-liz@example.com
          role: READER
      defaultObjectAcl:
        - entity: user-liz@example.com
          role: READER

For a bucket using ACLs, this grants the specified user permission to list objects and read newly uploaded objects. Replace the account with one that needs these permissions, and check that other IAM grants or existing object ACLs do not allow public access.

References