March 2019
Beginner to intermediate
778 pages
34h 20m
English
While IAM and ACLs provide a large degree of flexibility for bucket and object access control, they both use concentric models of control. This can make it hard to restrict access to a subset of resources, as broader, more permissive policies will always trump more granular, restrictive policies. This is especially true in situations where the vast majority of resources should be more permissive and a small subset should be restrictive.
For example, suppose an organization grants all developers of a team the Project Viewer role in order to enable support and diagnostics over their production systems. Because the Project Viewer role grants read access to all Cloud Storage data, no additional IAM policy ...
Read now
Unlock full access