Uniform bucket-level access is disabled

Migrate required ACL permissions before consolidating Cloud Storage access in IAM.

Description

When uniform bucket-level access is disabled in Cloud Storage, IAM policies and bucket/object ACLs both apply. Multiple access-control locations make effective permissions harder to review.

uniformBucketLevelAccess.enabled: true disables ACLs and uses IAM for access management. It does not remove public IAM grants by itself.

Potential impact

  • Object ACLs can retain unintended public access or excessive permissions.
  • Enabling the feature before migrating ACL-dependent permissions can interrupt required access.

Remediation

  • Identify identities that depend on ACLs and prepare their required least-privilege IAM access first.
  • Set iamConfiguration.uniformBucketLevelAccess.enabled to true and test required access. It cannot be disabled after 90 consecutive days of enablement.
  • Review public IAM grants too, and use Public access prevention when public access is unnecessary.

Examples

Deployment Manager support has ended. These are legacy bucket-setting excerpts; supply the actual name, location and other required configuration separately. Plan migration to a supported management tool.

Before

yaml
resources:
  - name: bucket
    type: storage.v1.bucket
    properties:
      iamConfiguration:
        uniformBucketLevelAccess:
          enabled: false

This permits ACLs and IAM to be used together.

After

yaml
resources:
  - name: bucket
    type: storage.v1.bucket
    properties:
      iamConfiguration:
        uniformBucketLevelAccess:
          enabled: true

This disables ACLs and uses IAM for access management. Migrating required permissions and reviewing public access remain separate tasks.

References