Inspect Cloud Storage protection settings safely
On this page
Use this procedure to inventory approved Cloud Storage bucket protection settings and identify buckets that merit separate object-level and billing-export investigation. Cloud Billing Reports do not prove which bucket caused a charge.
Why this is worth a look
Object Versioning preserves deleted objects as accessible, noncurrent versions until they are explicitly removed. Soft delete preserves deleted or overwritten objects and buckets in a soft-deleted state for a specified period, and soft-deleted objects continue to accrue storage charges until that period expires. Retention policies enforce a minimum retention time and cause attempts to overwrite or delete younger objects to fail. Cloud Billing Reports can analyze Cloud Storage costs, while the cost table adds project-level invoice details and the pricing table shows SKU prices for the selected Cloud Billing account.
Run this check
CHECKLISTA console-only checklist for recording bucket protection settings and reviewing Cloud Storage costs without changing bucket or object state.
Execution surface
- Google Cloud console only. Review the approved project and buckets in Cloud Storage, then open Cloud Billing Reports.
- Scope: buckets visible to the caller in the approved project scope and the selected Cloud Billing account.
- Units: record retention durations in the console's displayed time units. For the pricing table, record the selected Cloud Billing account currency.
- Time window: record the billing report period and report date used.
Required access
- For the documented Cloud Storage console workflow, confirm storage.buckets.get and storage.buckets.list.
- Confirm you are authorized to view the selected Cloud Billing account and its reports.
Read-only procedure
1. In Cloud Storage, open each approved bucket and record whether Object Versioning is enabled, whether soft delete is enabled, the soft delete retention duration if shown, and whether a retention policy exists.
2. For any retention policy, record its retention period and lock status. Read the permanent notice before treating the lock status as a compliance consideration. Do not select any edit, delete, or lock action.
3. In Cloud Billing Reports, select the approved billing scope and a stated time window. Filter the billing report to Cloud Storage to review service costs. Use the cost table report for project-level invoice details, or the pricing table report for SKU price context and the selected billing account currency.
4. Mark buckets whose settings warrant separate object-level or billing-export investigation. Do not attribute a report total to an individual bucket from these reports alone.
5. Save the bucket inventory, billing scope, report name, time window, displayed units, and review date for the follow-up record.How to confirm it
- 01
Set the review scope
Use the Google Cloud console only. Choose the approved projects and buckets, confirm the Cloud Billing account you may inspect, and write down the billing report time window.
- 02
Record bucket settings
For each approved bucket, record Object Versioning, soft delete, its displayed retention duration if shown, and any retention policy. Object Versioning preserves deleted objects as accessible noncurrent versions. Soft delete preserves deleted or overwritten resources in a soft-deleted state.
- 03
Inspect retention lock status
For each retention policy, record its retention period and lock status. Read the console's permanent notice and do not choose edit, delete, or lock actions during this review. The policy enforces a minimum retention time for objects and can cause deletion or overwrite attempts on younger objects to fail.
- 04
Review billing reports
In Cloud Billing Reports, filter the billing report to Cloud Storage for the selected scope and time window. Use the cost table for project-level invoice details or the pricing table for SKU price context. If you use the pricing table, record the selected Cloud Billing account currency.
- 05
Record follow-up candidates
Flag buckets whose protection settings merit object-level or billing-export investigation. Do not claim that a project-level billing report identifies an individual bucket's retained-data charge.
Before making changes
Assume the review is read-only, limited to approved buckets visible to the caller, and authorized for the selected Cloud Billing account. Record the billing report's time window and report date, retention-duration units, and, if used, the pricing table's selected billing account currency. This procedure does not list object generations, restore deleted data, calculate exact charges, or attribute billing totals to individual buckets. Soft delete is enabled by default for supported buckets with a default retention duration of 7 days, and its retention period is configurable.