Cloud Storage buckets with no lifecycle rules (no findings until object-age data is measured)
What does ZopNight detect here?
A Cloud Storage bucket with no lifecycle configuration keeps every object in its original class until someone deletes it. ZopNight detects buckets whose lifecycle policy is confirmed empty, but raises no finding until it can measure how much Standard data is old enough for a `SetStorageClass` rule to move to a colder class, which it does not do yet.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-140 |
| Category | rightsizing |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | no lifecycle rules configured |
| Source | ZopNight |
| Permissions used | storage.buckets.list · storage.buckets.get |
Where it applies
What a bucket without lifecycle rules accumulates
Object Lifecycle Management is how Cloud Storage ages data without anyone touching it. Rules
match objects by conditions such as age or matchesStorageClass and then delete them, abort
incomplete multipart uploads, or apply SetStorageClass to move them to Nearline, Coldline or
Archive. Without a rule, logs, exports and build artifacts stay in Standard storage at the full
rate for as long as the bucket exists.
Google’s lifecycle documentation notes a
useful pricing detail: SetStorageClass does not rewrite the object, so the change itself carries
no retrieval or early deletion fees, and time already spent in the old class counts toward the
new class’s minimum storage duration.
Checking a bucket’s lifecycle configuration
gcloud storage buckets describe gs://BUCKET_NAME --format="default(lifecycle_config)"An empty result means no rules. The same command shape appears in Google’s lifecycle management guide.
Confirming that no rule exists
ZopNight reads whether the bucket has any lifecycle rule when it inventories Cloud Storage. It would act only when that value is present and says there are none, and today it raises nothing even then, as explained below. A bucket whose lifecycle status was never recorded is skipped, not assumed empty.
Why findings wait for age data
The honest saving depends on how many bytes are old enough to move, and bucket size alone does not say that. ZopNight will not treat all Standard data as eligible, and it will not reuse the Standard-to-Nearline estimate from GCS Bucket Standard Class with Low Access, because that would count the same bytes twice. ZopNight does not yet measure that age split, so for now the rule stays silent.
The saving once age-eligible bytes are known
saving = age-eligible Standard GB x (Standard rate - colder class rate) per GB-monthOnce the split is measured, a finding will be raised only when that figure is above $5 a month.
Writing a first lifecycle rule
-
Decide the age after which objects are rarely read, and whether they should move or be deleted.
-
Write the rule to a file, for example moving Standard objects older than 30 days to Nearline:
Terminal window {"rule": [{"action": {"type": "SetStorageClass", "storageClass": "NEARLINE"},"condition": {"age": 30, "matchesStorageClass": ["STANDARD"]}}]} -
Apply it:
gcloud storage buckets update gs://BUCKET_NAME --lifecycle-file=lifecycle.json. -
Allow up to 24 hours for the configuration to take effect.