How can I prevent users from locking a bucket retention policy in GCP's Google Cloud Storage but still allow them to create/manage buckets?

Viewed 70

Reading about Bucket Locks in Cloud Storage made me think of something very evil and bad that one could do:

  1. Create a Cloud Storage Bucket.
  2. Set a retention policy of 100 years on the bucket.
  3. Lock the retention policy to the bucket.
  4. Upload many petabytes of objects to the bucket.

The project is now stuck with a bucket that cannot be deleted for 100 years and the project can never be deleted either due to a "lien". And theoretically, someone is stuck paying the bill to store the petabytes. For 100 years.

Is there any way, preferably programmatically or through configuration, to prevent users from locking a retention policy on a bucket but still permitting them to create and manage other aspects of Cloud Storage buckets that can't be bucket locked?

The more blunt permission system doesn't seem like it's fine grained enough to permit or deny locking:

https://cloud.google.com/storage/docs/access-control/iam-json

I'm thinking there's some way to use IAM Conditions to accomplish what I want, but I'm not sure how.


Update: I'm looking for a solution that does not force a retention policy to be set. John Hanley's organization policy contraint solution is interesting, but it forces a retention policy to be set with at least a 1 second retention across all applicable projects and it also disables the option to have bucket versioning enabled in the bucket.

A forced retention of 1 second can cause certain issues with applications that write and delete objects at the same key multiple times a second.


FWIW, AWS identifies these kinds of radioactive waste creation actions and lets policies be set on them accordingly.

1 Answers

Method 1:

Select or create a custom role for bucket users that does not have the permission resourcemanager.projects.updateLiens. That permission is required to create a Retention Policy.

Method 2:

This method has side effects such as not supporting object versioning but can prevent a long bucket lock such as 100 years.

You can set an Organization Policy Constraint to limit the maximum duration of a Retention Policy.

Name:

constraints/storage.retentionPolicySeconds

Description:

Retention policy duration in seconds

Related