Skip to main content

Frequently Asked Questions

Why does every object need to belong to exactly one bucket?

Buckets are the unit of configuration in Cloud Storage — they set the default storage class (Standard, Nearline, Coldline, Archive), the geographic location, and the IAM/ACL permissions inherited by everything inside. Requiring one bucket per object simplifies access control and cost management: you can apply a lifecycle rule or a uniform bucket-level access policy once and know it governs everything underneath, rather than tracking settings per object.

What's a common Cloud Storage bucket mistake that causes a public data leak?

Granting allUsers or allAuthenticatedUsers read access at the bucket level for what was meant to be a temporary or internal share, then forgetting to revoke it. GCP now warns and can enforce public access prevention at the org level, but plenty of buckets were exposed before that existed. Best practice: use uniform bucket-level access instead of per-object ACLs, and use signed URLs for temporary external sharing instead of making objects public.