Review public Cloud Storage ACL principals

Review the permissions granted to public ACL principals and the resulting data access.

Description

In Cloud Storage ACLs, allUsers includes anonymous users, while allAuthenticatedUsers includes authenticated users and service accounts beyond your organization. Avoid granting these principals access unless public distribution is intended.

Exposure depends on the granted role and whether it applies to a bucket or an object. A bucket READER ACL permits listing objects in that bucket; permissions to read object contents must be checked separately.

Potential impact

  • Broad listing access can disclose object names and storage structure.
  • Public object-read permissions can expose files or permit unauthorized downloads.

Remediation

  • Remove unnecessary allUsers and allAuthenticatedUsers grants from ACLs and IAM, and grant approved principals only the required roles.
  • Consider Public Access Prevention for private buckets. When disabling ACLs through uniform bucket-level access, migrate required access to IAM and verify the effective permissions.

Examples

These excerpts compare only ACL principals in the retired Deployment Manager format. Required settings such as the target bucket and role are omitted. Configure actual principals and minimum permissions through a supported tool.

Before

yaml
resources:
  - name: bucket-access-control
    type: storage.v1.bucketAccessControl
    properties:
      entity: allUsers

After

yaml
resources:
  - name: bucket-access-control
    type: storage.v1.bucketAccessControl
    properties:
      entity: user-example@example.com

Explanation:

  • Before: The principal includes anonymous users. The role determines which operations are allowed.
  • After: The principal is restricted to one user. Replace the example address with an approved user and remove public grants from other ACLs and IAM as well.

References