Description
A Cloud Storage bucket inventory documents data purpose and ownership. A bucket’s existence is not itself a vulnerability, and stored data is encrypted by default even without an explicit encryption block.
Potential impact
Broad permissions on a bucket that does not need public access can expose data or allow unwanted changes. An incomplete inventory can leave these settings unnoticed.
Remediation
Record the bucket owner and review whether ACL or IAM grants to allUsers and allAuthenticatedUsers are needed. Check encryption-key management and retention policies for the intended use.
Examples
These excerpts contrast public members with read access for a designated group. Supply full identifiers for actual KMS keys through the variable and resource references, and configure key permissions separately.
Before
resource "google_storage_bucket_access_control" "public_rule" {
bucket = google_storage_bucket.bucket.name
role = "READER"
entity = "allUsers"
}
resource "google_storage_bucket" "bucket" {
name = "static-content-bucket"
location = "US"
}
resource "google_storage_bucket_iam_binding" "binding" {
bucket = google_storage_bucket.bucket2.name
role = "roles/storage.admin"
members = [
"allUsers",
]
}
resource "google_storage_bucket" "bucket2" {
name = "static-content-bucket-2"
location = "US"
encryption {
default_kms_key_name = var.bucket_kms_key
}
}
After
resource "google_storage_bucket" "logs_bucket" {
name = "team-app-logs-prod"
location = "US"
uniform_bucket_level_access = true
encryption {
default_kms_key_name = google_kms_crypto_key.bucket_key.id
}
labels = {
service = "app"
env = "prod"
}
}
resource "google_storage_bucket_iam_member" "ops_reader" {
bucket = google_storage_bucket.logs_bucket.name
role = "roles/storage.objectViewer"
member = "group:ops@example.com"
}