Google托管静态网站遭AccessDenied,需OWNER权限配置Bucket访问
Let me walk through how to resolve this issue since I've run into similar headaches with Uniform Bucket Level Access before.
First, let's break down what's going on here:
- You're hitting an
AccessDeniederror when visiting your static site because anonymous users don't have permission to read yourindex.htmlfile. - When trying to use
gsutil acl chto make the bucket public, you're getting "Failed to set acl" errors even though your account has Owner/Storage Admin-level permissions on both the project and bucket.
The Root Cause: Uniform Bucket Level Access Disables Traditional ACLs
Since you're using Uniform Bucket Level Access (the recommended default now), traditional ACL commands like gsutil acl ch are completely unsupported. Uniform mode replaces old-style ACLs with IAM policies as the sole source of permission truth. That's why even with full Owner access, your ACL modification attempts are failing—those commands just don't work in uniform mode.
Step-by-Step Fixes
1. Use IAM to Grant Public Read Access (Ditch ACLs)
Instead of messing with ACLs, use Google's IAM commands to give all anonymous users permission to view your bucket's objects. Run this in your terminal:
gcloud storage buckets add-iam-policy-binding gs://www.example.com --member=allUsers --role=roles/storage.objectViewer
This assigns the Storage Object Viewer role to all users, which lets anyone read the files in your bucket—exactly what you need for a public static website.
2. Double-Check Your Static Site Setup
Make sure your bucket is configured properly for hosting:
- Your bucket name must exactly match your domain (e.g.,
www.example.comfor yourwww.example.comdomain). - In the Google Cloud Console, go to your bucket > Permissions and confirm Uniform Bucket Level Access is enabled (it should be, since you mentioned using uniform storage).
- Head to Website configuration under your bucket settings:
- Set
index.htmlas your Main page suffix - Optionally set an error page (like
404.html) for missing content
- Set
3. Check for Organization Policy Restrictions
If your account is part of a Google Workspace or Cloud Identity organization, there might be policies blocking public bucket access:
- Ask your admin to check for policies like Domain Restricted Sharing or Restrict public bucket access—these can prevent
allUsersfrom accessing your bucket even if you set the correct IAM permissions.
4. Verify Your Account's Actual Bucket Permissions
If the IAM command still fails, confirm your account has the right permissions on the bucket:
- Run this to view your bucket's IAM policy:
gcloud storage buckets get-iam-policy gs://www.example.com - Look for your email in the bindings with roles like
roles/storage.adminorroles/owner. If it's missing, add it directly via the Cloud Console's IAM interface for the bucket.
Why Your Earlier ACL Commands Failed
Uniform Bucket Level Access explicitly disables all traditional ACL management. Even with full Owner access, tools like gsutil acl will throw permission errors because ACLs are no longer used to control access in this mode. IAM is the only valid way to manage permissions when uniform access is enabled.
内容的提问来源于stack exchange,提问作者Jake Durell

