Description
A Cloud Storage IAM binding grants its role to the principals in members. allUsers includes anyone, with or without a Google account, and allAuthenticatedUsers is not limited to users of your project. Roles granted to these principals can allow unintended data access when they exceed the required scope.
An empty member list does not itself grant anonymous access. Check whether the binding is needed and whether intended users are missing. Assess effective access across role permissions, inherited grants, IAM policies, ACLs, and Public access prevention.
Potential impact
- Read permissions for public principals can expose files, backups, or logs more widely than intended.
- Write or administrative permissions can permit unwanted object changes or deletion, or changes to bucket settings.
Remediation
- If public access is unnecessary, remove
allUsersandallAuthenticatedUsersand grant only the minimum roles to required users, groups, and service accounts. Do not add arbitrary principals just to fill an empty list; remove unneeded bindings. - Because
google_storage_bucket_iam_bindingmanages the member list for its role, preserve required existing members and inspect the Terraform plan. - Review Public access prevention and other IAM policies and ACLs, then test required and denied access. Enabling uniform bucket-level access alone does not remove public IAM grants.
Examples
Define google_storage_bucket.default separately and replace the example account jane@example.com with the required actual account. Review the Terraform plan, including resource-name changes, when applying this to an existing configuration.
Before
resource "google_storage_bucket_iam_binding" "public_binding" {
bucket = google_storage_bucket.default.name
role = "roles/storage.admin"
members = ["user:jane@example.com", "allUsers"]
}
The binding grants allUsers the roles/storage.admin role, which can manage the bucket and its objects. Unless other controls such as Public access prevention block access, this can grant public permissions far beyond those required.
After
resource "google_storage_bucket_iam_binding" "restricted_binding" {
bucket = google_storage_bucket.default.name
role = "roles/storage.admin"
members = [
"user:jane@example.com",
]
}
The public principal is removed, leaving one named user. That user still receives roles/storage.admin; check whether their work requires this role and use a narrower one where possible.