A media company uses Cloud Storage to archive video footage. They need to restrict access to these archival buckets so that only specific service accounts, used by their video processing pipeline, can read and write objects. Additionally, they want to prevent accidental deletion of the buckets themselves. Which IAM roles and Cloud Storage features should be configured?
- AGrant `storage.objectViewer` and `storage.objectCreator` to service accounts, and set a bucket retention policy.
- BGrant `storage.objectAdmin` to service accounts and enable Object Versioning.
- CGrant `storage.admin` to service accounts and enable uniform bucket-level access.
- DGrant `storage.objectUser` to service accounts, and enable Bucket Lock.
Show answer & explanationAnswer & explanation
Correct answer: A. Grant `storage.objectViewer` and `storage.objectCreator` to service accounts, and set a bucket retention policy.
To allow read/write access to objects, `storage.objectViewer` (for read) and `storage.objectCreator` (for write, including overwrite) are appropriate roles for service accounts, following the principle of least privilege. To prevent accidental bucket deletion and ensure data immutability, a bucket retention policy is the most effective Cloud Storage feature, as it locks objects for a specified duration and prevents deletion/modification during that period, thereby indirectly protecting the bucket from deletion if it contains locked objects.
Why the other options are wrong
- B. `storage.objectAdmin` grants broader permissions than typically needed (e.g., manage ACLs). Object Versioning helps recover deleted objects but doesn't prevent bucket deletion or enforce immutability directly in the same way a retention policy does.
- C. `storage.admin` is a very broad role that grants full control over buckets and objects, violating the principle of least privilege. Uniform bucket-level access simplifies permissions but doesn't prevent bucket deletion.
- D. `storage.objectUser` is a legacy role. Bucket Lock is a WORM feature that applies to individual objects, not directly to preventing bucket deletion (though it makes it harder to delete an empty bucket). A retention policy is more comprehensive for protecting against accidental data deletion and indirectly bucket deletion if it's not empty.
Cloud Storage Retention Policy & Object Roles
Configuring Cloud Storage with specific IAM roles for granular object access and a bucket retention policy to prevent accidental data deletion and enforce immutability.
- IAM roles (e.g., `objectViewer`, `objectCreator`) ensure least privilege.
- Bucket retention policy locks objects for a specified duration.
- Helps prevent accidental data loss and ensures compliance.
Memory trick: Roles for access, retention for keeping data from being lost forever.