Google Cloud Storage:如何拒绝指定存储桶内单个文件的访问权限
file_restricted.txt in Google Cloud Storage First, let’s anchor ourselves to a critical GCP IAM rule you need to lean on here: Deny permissions always take precedence over Allow permissions. Even if the user inherits allow access from allusers (read-only) or group1 (read-write), a targeted deny rule for this specific file will override those grants entirely.
Here’s how to set this up, both via the Cloud Console and command line:
Option 1: Using Google Cloud Console
- Head to the Cloud Storage Browser, open your
bucketxyzbucket, and locatefile_restricted.txt. - Click the three-dot menu next to the file, then select Edit permissions.
- In the permissions panel, click Add to create a new binding.
- Under Add principal, type in the email address of the user you want to block (e.g.,
blocked-user@example.com). - Click the Role dropdown, then switch to the Deny tab at the top of the selector.
- Pick the right deny role to lock down access:
- To stop the user from viewing or downloading the file content: Select Storage Object Viewer (this blocks the core
storage.objects.getpermission). - If you also want to hide the file’s existence from the user (prevent them from seeing it in the bucket list), you can additionally deny Storage Legacy Bucket Reader—just note this affects bucket-level visibility, so use only if needed.
- To stop the user from viewing or downloading the file content: Select Storage Object Viewer (this blocks the core
- Click Save to apply the rule.
Option 2: Using gcloud Command Line
For automation or terminal-based workflows, use these steps:
First, create a JSON policy file (name it
deny-policy.json) with the deny binding:{ "bindings": [ { "type": "DENY", "role": "roles/storage.objectViewer", "members": [ "user:blocked-user@example.com" ] } ] }Replace
blocked-user@example.comwith the actual user’s email.Apply this policy directly to the file with:
gcloud storage objects set-iam-policy gs://bucketxyz/file_restricted.txt deny-policy.json
Or skip the JSON file and add the deny rule in one line:
gcloud storage objects add-iam-policy-binding gs://bucketxyz/file_restricted.txt \ --member=user:blocked-user@example.com \ --role=roles/storage.objectViewer \ --deny
Key Notes to Keep in Mind
- Deny Trumps All: This rule will override any allow permissions the user gets from
allusersorgroup1—they won’t be able to accessfile_restricted.txteven if they’re part of those groups. - Stick to Granular Permissions: Only deny the specific permissions you need (like
storage.objects.getfor file content) instead of broad roles to avoid unintended side effects. - No Ownership Bypass Risk: Since
group1doesn’t have ownership permissions, the blocked user can’t use ownership rights to get around the deny rule.
内容的提问来源于stack exchange,提问作者SubZeno

