Google Cloud Storage (GCS) is a globally accessible, unified object store for unstructured data (images, database backups, log archives, state files).
Unlike AWS S3 (where different storage classes have different API behaviors), GCS uses a single unified API across all storage classes, letting you change storage classes seamlessly via automated lifecycle rules.
Topic 1: Storage Classes & Financial SLAs
GCS offers four main storage classes:
| Storage Class | Min Retention | Target Access Frequency | Typical Use Case |
|---|---|---|---|
| Standard | None | Frequently accessed (>1x/month) | Static web assets, active app data, state files |
| Nearline | 30 days | Accessed less than 1x/month | Monthly reports, fresh database backups |
| Coldline | 90 days | Accessed less than 1x/quarter | Quarterly compliance snapshots, DR backups |
| Archive | 365 days | Accessed less than 1x/year | Multi-year regulatory archives (lowest storage rate) |
[!WARNING] Minimum Billable Duration: If you transition or delete an object in Nearline before 30 days (or Archive before 365 days), GCS charges an early deletion fee for the remaining days!
Topic 2: Automated Object Lifecycle Management
Bucket Lifecycle Policies consist of Rules containing Conditions and Actions:
- Conditions:
age(days since creation),createdBefore,isLive(current vs non-current versions),numNewerVersions,matchesStorageClass. - Actions:
SetStorageClass(e.g., transition to Coldline) orDelete.
{
"rule": [
{
"action": {
"type": "SetStorageClass",
"storageClass": "NEARLINE"
},
"condition": {
"age": 30,
"matchesStorageClass": ["STANDARD"]
}
},
{
"action": {
"type": "Delete"
},
"condition": {
"numNewerVersions": 3,
"isLive": false
}
}
]
}
# Apply the lifecycle policy to a GCS bucket
gcloud storage buckets update gs://prod-logs-archive-847291 \
--lifecycle-file=lifecycle.json
Topic 3: Security: Uniform Bucket-Level Access vs. ACLs
Historically, GCS supported per-object Access Control Lists (ACLs) in parallel with Cloud IAM. Managing permissions per object creates severe security oversights where individual objects become publicly readable.
Production Standard: Uniform Bucket-Level Access:
Uniform Bucket-Level Access disables legacy object-level ACLs completely. All access to the bucket and its objects is evaluated strictly through Cloud IAM roles (roles/storage.objectViewer, roles/storage.objectAdmin).
# Enable Uniform Bucket-Level Access (Security Best Practice)
gcloud storage buckets update gs://prod-logs-archive-847291 \
--uniform-bucket-level-access
Topic 4: Bucket Lock & WORM Compliance
For financial or legal compliance (e.g., SEC or FINRA requirements), data must be preserved immutably without risk of deletion even by a compromise of root credentials.
- Retention Policy: Specifies a minimum retention duration (e.g., 7 years) during which objects cannot be deleted or overwritten.
- Bucket Lock (Irreversible): Once you lock the retention policy, it can NEVER be removed or reduced, not even by Google Support or the Organization Owner! The bucket can only be deleted after every object inside it naturally exceeds the retention period.
Common mistake: Writing a lifecycle rule that moves everything to Coldline or Archive after 30 days without checking object size and age distribution. Nearline, Coldline and Archive each carry a minimum storage duration — 30, 90 and 365 days — billed whether or not the object survives that long, plus a retrieval fee. On a bucket of short-lived logs, the rule increases the bill.