Skip to main content
compliance · gcp

Cloud Storage buckets where public access prevention is not enforced

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

Cloud Storage buckets are flagged at critical severity when `publicAccessPrevention` on the bucket is not set to `enforced`. Until it is, anyone with IAM or ACL rights on the bucket can grant `allUsers` or `allAuthenticatedUsers` access, and one mistaken grant publishes every object in it to the internet.

Signal and threshold

How ZopNight evaluates Cloud Storage buckets where public access prevention is not enforced.
Field Value
Rule IDsRC-138
Categorycompliance
Severitycritical
Metricnone — pure configuration read
ThresholdpublicAccessPrevention not enforced on the bucket
SourceZopNight
Permissions usedstorage.buckets.list · storage.buckets.get · storage.buckets.getIamPolicy

What enforcement blocks that IAM alone does not

Public exposure of a bucket usually comes from one binding: allUsers (anyone on the internet) or allAuthenticatedUsers (any user or service account authenticated with a Google Account) added to the bucket’s IAM policy or an object ACL. Nothing stops that grant unless public access prevention is on.

With it enforced, Google’s public access prevention page describes the behaviour: requests authorised through allUsers or allAuthenticatedUsers fail with 401 or 403, attempts to add those principals fail with 412 Precondition Failed, and existing public grants stay in the policy but are overridden. It does not affect signed URLs, which are scoped to a service account.

Finding buckets that are not enforced

The setting reads either enforced or inherited:

Terminal window
gcloud storage buckets describe gs://BUCKET_NAME \
--format="default(public_access_prevention)"

Then look for public principals in the bucket policy:

Terminal window
gcloud storage buckets get-iam-policy gs://BUCKET_NAME | grep -E "allUsers|allAuthenticatedUsers"

The single setting ZopNight checks

ZopNight reads the bucket’s public access prevention value during inventory and fires when it is anything other than enforced. The finding means the guard rail is missing. It is not proof that a public binding exists today, which is why the fix starts with checking the IAM policy.

Buckets that are skipped or already safe

A bucket that was not fully inventoried produces nothing. The rule reads the bucket’s own value, so a bucket showing inherited is flagged even when the storage.publicAccessPrevention constraint applies from the project, folder or organization and already protects it. Buckets deliberately public for static website hosting are a legitimate exception; Google suggests handling them with a project-level exception rather than leaving everything open.

Exposure risk rather than spend

No saving is attached; the fixed estimate is $0. The risk is a data breach, which is why the severity is critical.

Locking the bucket down

  1. Check the IAM policy for allUsers and allAuthenticatedUsers and find out whether any application depends on them. Enforcing prevention will break those readers.
  2. Remove any public binding that is not intended.
  3. Enforce prevention on the bucket: gcloud storage buckets update gs://BUCKET_NAME --public-access-prevention.
  4. Set the constraints/storage.publicAccessPrevention organization policy at the highest level you can, so new buckets are covered from creation.
  5. If the bucket was public, review its contents and access logs for what may have been read.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·