Cloud Storage IAM binding permissions need review

Check that Cloud Storage roles are granted only to the principals that need them, and remove unnecessary public permissions.

Description

A Cloud Storage IAM binding grants its role to the principals in members. allUsers includes anyone, with or without a Google account, and allAuthenticatedUsers is not limited to users of your project. Roles granted to these principals can allow unintended data access when they exceed the required scope.

An empty member list does not itself grant anonymous access. Check whether the binding is needed and whether intended users are missing. Assess effective access across role permissions, inherited grants, IAM policies, ACLs, and Public access prevention.

Potential impact

  • Read permissions for public principals can expose files, backups, or logs more widely than intended.
  • Write or administrative permissions can permit unwanted object changes or deletion, or changes to bucket settings.

Remediation

  • If public access is unnecessary, remove allUsers and allAuthenticatedUsers and grant only the minimum roles to required users, groups, and service accounts. Do not add arbitrary principals just to fill an empty list; remove unneeded bindings.
  • Because google_storage_bucket_iam_binding manages the member list for its role, preserve required existing members and inspect the Terraform plan.
  • Review Public access prevention and other IAM policies and ACLs, then test required and denied access. Enabling uniform bucket-level access alone does not remove public IAM grants.

Examples

Define google_storage_bucket.default separately and replace the example account jane@example.com with the required actual account. Review the Terraform plan, including resource-name changes, when applying this to an existing configuration.

Before

hcl
resource "google_storage_bucket_iam_binding" "public_binding" {
  bucket  = google_storage_bucket.default.name
  role    = "roles/storage.admin"
  members = ["user:jane@example.com", "allUsers"]
}

The binding grants allUsers the roles/storage.admin role, which can manage the bucket and its objects. Unless other controls such as Public access prevention block access, this can grant public permissions far beyond those required.

After

hcl
resource "google_storage_bucket_iam_binding" "restricted_binding" {
  bucket  = google_storage_bucket.default.name
  role    = "roles/storage.admin"
  members = [
    "user:jane@example.com",
  ]
}

The public principal is removed, leaving one named user. That user still receives roles/storage.admin; check whether their work requires this role and use a narrower one where possible.

References