You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud Storage:如何拒绝指定存储桶内单个文件的访问权限

How to Deny Specific User Access to file_restricted.txt in Google Cloud Storage

First, let’s anchor ourselves to a critical GCP IAM rule you need to lean on here: Deny permissions always take precedence over Allow permissions. Even if the user inherits allow access from allusers (read-only) or group1 (read-write), a targeted deny rule for this specific file will override those grants entirely.

Here’s how to set this up, both via the Cloud Console and command line:

Option 1: Using Google Cloud Console

  1. Head to the Cloud Storage Browser, open your bucketxyz bucket, and locate file_restricted.txt.
  2. Click the three-dot menu next to the file, then select Edit permissions.
  3. In the permissions panel, click Add to create a new binding.
  4. Under Add principal, type in the email address of the user you want to block (e.g., blocked-user@example.com).
  5. Click the Role dropdown, then switch to the Deny tab at the top of the selector.
  6. Pick the right deny role to lock down access:
    • To stop the user from viewing or downloading the file content: Select Storage Object Viewer (this blocks the core storage.objects.get permission).
    • If you also want to hide the file’s existence from the user (prevent them from seeing it in the bucket list), you can additionally deny Storage Legacy Bucket Reader—just note this affects bucket-level visibility, so use only if needed.
  7. Click Save to apply the rule.

Option 2: Using gcloud Command Line

For automation or terminal-based workflows, use these steps:

  1. First, create a JSON policy file (name it deny-policy.json) with the deny binding:

    {
      "bindings": [
        {
          "type": "DENY",
          "role": "roles/storage.objectViewer",
          "members": [
            "user:blocked-user@example.com"
          ]
        }
      ]
    }
    

    Replace blocked-user@example.com with the actual user’s email.

  2. Apply this policy directly to the file with:

    gcloud storage objects set-iam-policy gs://bucketxyz/file_restricted.txt deny-policy.json
    

Or skip the JSON file and add the deny rule in one line:

gcloud storage objects add-iam-policy-binding gs://bucketxyz/file_restricted.txt \
  --member=user:blocked-user@example.com \
  --role=roles/storage.objectViewer \
  --deny

Key Notes to Keep in Mind

  • Deny Trumps All: This rule will override any allow permissions the user gets from allusers or group1—they won’t be able to access file_restricted.txt even if they’re part of those groups.
  • Stick to Granular Permissions: Only deny the specific permissions you need (like storage.objects.get for file content) instead of broad roles to avoid unintended side effects.
  • No Ownership Bypass Risk: Since group1 doesn’t have ownership permissions, the blocked user can’t use ownership rights to get around the deny rule.

内容的提问来源于stack exchange,提问作者SubZeno

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:22:33