Description
When uniform bucket-level access is disabled in Cloud Storage, IAM policies and bucket/object ACLs both apply. Multiple access-control locations make effective permissions harder to review.
uniformBucketLevelAccess.enabled: true disables ACLs and uses IAM for access management. It does not remove public IAM grants by itself.
Potential impact
- Object ACLs can retain unintended public access or excessive permissions.
- Enabling the feature before migrating ACL-dependent permissions can interrupt required access.
Remediation
- Identify identities that depend on ACLs and prepare their required least-privilege IAM access first.
- Set
iamConfiguration.uniformBucketLevelAccess.enabledtotrueand test required access. It cannot be disabled after 90 consecutive days of enablement. - Review public IAM grants too, and use Public access prevention when public access is unnecessary.
Examples
Deployment Manager support has ended. These are legacy bucket-setting excerpts; supply the actual name, location and other required configuration separately. Plan migration to a supported management tool.
Before
resources:
- name: bucket
type: storage.v1.bucket
properties:
iamConfiguration:
uniformBucketLevelAccess:
enabled: false
This permits ACLs and IAM to be used together.
After
resources:
- name: bucket
type: storage.v1.bucket
properties:
iamConfiguration:
uniformBucketLevelAccess:
enabled: true
This disables ACLs and uses IAM for access management. Migrating required permissions and reviewing public access remain separate tasks.