Description
Cloud Storage IAM allUsers includes anonymous users, while allAuthenticatedUsers includes authenticated Google accounts outside the organization. The assigned role and applicable restrictions determine whether data can be read or changed.
Potential impact
- Internal data or backups can be exposed externally.
- Public write or delete permissions can cause data damage or service disruption.
Remediation
- Remove unnecessary public principals and grant approved users, groups or service accounts only the roles they need. Consider Public access prevention for private buckets.
- Separate intentionally public content into a dedicated bucket and allow only required operations, such as reads. Check other IAM and ACL grants and actual access.
Examples
These settings manage a member on an existing bucket. Replace the sample identity with an approved account. The revised example retains the broad roles/storage.admin role, which should be reduced to match the task.
Before
hcl
resource "google_storage_bucket_iam_member" "example" {
bucket = google_storage_bucket.default.name
role = "roles/storage.admin"
member = "allUsers"
}
After
hcl
resource "google_storage_bucket_iam_member" "example" {
bucket = google_storage_bucket.default.name
role = "roles/storage.admin"
member = "user:jane@example.com"
}
Explanation:
- Before: The administrator role is granted to everyone. Other controls, including Public access prevention, also affect access.
- After: The principal is restricted to one user. Other public grants are not removed and the role is not reduced by this change.