Description
A Cloud Storage bucket inventory identifies object-storage assets and supports review of public access, encryption keys and access controls. A bucket's presence is not itself a vulnerability.
Cloud Storage encrypts stored data by default. Customer-managed encryption keys (CMEK) address separate key-management requirements. Uniform bucket-level access disables ACL use but does not automatically remove public IAM grants.
Potential impact
- Buckets missing from the inventory can escape public-permission and protection reviews.
- Data locations, costs and operational ownership can become harder to manage.
Remediation
Include buckets in the asset inventory and review public IAM or ACL grants, retention and recovery policies, and responsible teams. If CMEK is required, choose a key in a location matching the bucket and manage service-agent permissions and key availability.
Examples
These excerpts use the historical Deployment Manager format, whose support has ended. Set bucket names and keys for your environment. Both examples encrypt stored data; the after example specifies access-control and key-management choices.
Before
resources:
- name: sample-input3
type: storage.v1.bucket
properties:
storageClass: STANDARD
location: EUROPE-WEST3
acl:
- entity: allUsers
role: READER
After
resources:
- name: sample-input
type: storage.v1.bucket
properties:
storageClass: STANDARD
location: EUROPE-WEST3
iamConfiguration:
uniformBucketLevelAccess:
enabled: true
encryption:
defaultKmsKeyName: projects/example/locations/europe-west3/keyRings/ring/cryptoKeys/key
Explanation:
- Before: A bucket
READERACL forallUsersallows anonymous listing of objects in the bucket. Reading object contents requires separate permission. - After: IAM replaces ACLs, and CMEK uses the same region as the bucket. Check public IAM grants separately; changing the default key alone does not re-encrypt existing objects.