GCP Storage Bucket Uniform Bucket-Level Access needs review

Manage bucket and object access consistently through IAM.

Description

Without Uniform Bucket-Level Access on a GCP Storage Bucket, access management includes both IAM policies and bucket or object ACLs. Overlooked or inconsistent ACL permissions can allow unintended principals to access data.

Uniform bucket-level access disables ACLs and uses IAM for authorization. It does not itself prohibit public access, so public IAM grants and Public access prevention need separate review.

Potential impact

  • Unnecessary read permissions left in object ACLs can expose data.
  • Distributed permission settings can make access difficult to understand or revoke consistently.

Remediation

Identify ACL permissions used by applications and migrate required access to IAM policies first. Test compatibility, then set uniform_bucket_level_access to true and remove ACL dependencies. If public access is unnecessary, remove public IAM grants and consider Public access prevention. Verify that required access succeeds and unapproved requests are denied.

Examples

These examples enable uniform bucket-level access on the same bucket. Use an available unique bucket name; a domain-style name requires domain ownership verification.

Before

hcl
resource "google_storage_bucket" "artifact_bucket" {
  name                         = "image-store.com"
  location                     = "EU"
  uniform_bucket_level_access  = false
}

This configuration uses both ACLs and IAM. The setting alone does not establish that the bucket is public.

After

hcl
resource "google_storage_bucket" "artifact_bucket" {
  name                         = "image-store.com"
  location                     = "EU"
  uniform_bucket_level_access  = true
}

This disables ACLs and manages permissions through IAM. Migrate required access for users that relied on existing ACLs before enabling it.

References