Google Cloud Storage (GCS) & Lifecycle Policies

Master GCS object storage classes, automated lifecycle transitions, bucket retention locks for WORM compliance, and Uniform Bucket-Level Access.

intermediate 20 min lesson hands-on task included

Google Cloud Storage (GCS) is a globally accessible, unified object store for unstructured data (images, database backups, log archives, state files).

Unlike AWS S3 (where different storage classes have different API behaviors), GCS uses a single unified API across all storage classes, letting you change storage classes seamlessly via automated lifecycle rules.


Topic 1: Storage Classes & Financial SLAs

CLOUD STORAGE (GCS) CLASSES, LIFECYCLES & RETENTION LOCKS STORAGE CLASS TIERING (SINGLE API FOR ALL CLASSES) Standard SLA: 99.99% 0 days High storage / Free access Nearline SLA: 99.9% 30 days min Access <1x/month Coldline SLA: 99.9% 90 days min Access <1x/quarter Archive SLA: 99.9% 365 days min Access <1x/year (lowest rate) AUTOMATED LIFECYCLE RULES (Age, NumNewerVersions, MatchesStorageClass) BUCKET LOCK (WORM COMPLIANCE) & UNIFORM BUCKET ACCESS Retention Policy Lock (Irreversible!) • Enforces retention period (up to 100 yrs) • Cannot be unlocked or deleted until expiration Uniform Bucket-Level Access • Disables legacy per-object ACLs • Standardizes access strictly through Cloud IAM CLI UTILITIES: gsutil -m cp (parallel multi-threaded transfer) & Storage Transfer Service (for bulk AWS S3 to GCS migrations).
GCS Storage Class tiering: Standard -> Nearline -> Coldline -> Archive lifecycle transitions, Bucket Lock WORM retention, and Uniform Bucket Access.

GCS offers four main storage classes:

Storage ClassMin RetentionTarget Access FrequencyTypical Use Case
StandardNoneFrequently accessed (>1x/month)Static web assets, active app data, state files
Nearline30 daysAccessed less than 1x/monthMonthly reports, fresh database backups
Coldline90 daysAccessed less than 1x/quarterQuarterly compliance snapshots, DR backups
Archive365 daysAccessed less than 1x/yearMulti-year regulatory archives (lowest storage rate)

[!WARNING] Minimum Billable Duration: If you transition or delete an object in Nearline before 30 days (or Archive before 365 days), GCS charges an early deletion fee for the remaining days!


Topic 2: Automated Object Lifecycle Management

Bucket Lifecycle Policies consist of Rules containing Conditions and Actions:

  • Conditions: age (days since creation), createdBefore, isLive (current vs non-current versions), numNewerVersions, matchesStorageClass.
  • Actions: SetStorageClass (e.g., transition to Coldline) or Delete.
{
  "rule": [
    {
      "action": {
        "type": "SetStorageClass",
        "storageClass": "NEARLINE"
      },
      "condition": {
        "age": 30,
        "matchesStorageClass": ["STANDARD"]
      }
    },
    {
      "action": {
        "type": "Delete"
      },
      "condition": {
        "numNewerVersions": 3,
        "isLive": false
      }
    }
  ]
}
# Apply the lifecycle policy to a GCS bucket
gcloud storage buckets update gs://prod-logs-archive-847291 \
  --lifecycle-file=lifecycle.json

Topic 3: Security: Uniform Bucket-Level Access vs. ACLs

Historically, GCS supported per-object Access Control Lists (ACLs) in parallel with Cloud IAM. Managing permissions per object creates severe security oversights where individual objects become publicly readable.

Production Standard: Uniform Bucket-Level Access: Uniform Bucket-Level Access disables legacy object-level ACLs completely. All access to the bucket and its objects is evaluated strictly through Cloud IAM roles (roles/storage.objectViewer, roles/storage.objectAdmin).

# Enable Uniform Bucket-Level Access (Security Best Practice)
gcloud storage buckets update gs://prod-logs-archive-847291 \
  --uniform-bucket-level-access

Topic 4: Bucket Lock & WORM Compliance

For financial or legal compliance (e.g., SEC or FINRA requirements), data must be preserved immutably without risk of deletion even by a compromise of root credentials.

  • Retention Policy: Specifies a minimum retention duration (e.g., 7 years) during which objects cannot be deleted or overwritten.
  • Bucket Lock (Irreversible): Once you lock the retention policy, it can NEVER be removed or reduced, not even by Google Support or the Organization Owner! The bucket can only be deleted after every object inside it naturally exceeds the retention period.

Common mistake: Writing a lifecycle rule that moves everything to Coldline or Archive after 30 days without checking object size and age distribution. Nearline, Coldline and Archive each carry a minimum storage duration — 30, 90 and 365 days — billed whether or not the object survives that long, plus a retrieval fee. On a bucket of short-lived logs, the rule increases the bill.