Skip to content

GCP Storage Bucket does not have Access and Storage Logging enabled

Description

Some resources require a record of who access them and when.

Code Example

go
resource "google_storage_bucket" "logging" {
  name     = "jgwloggingbucket"
  location = var.location
  uniform_bucket_level_access = true
+  logging {
+    log_bucket = "mylovelybucket"
+  }
}

Remediation

Terraform

  • Resource: google_storage_bucket
  • Arguments: logging/log_bucket to specify a Bucket to store access log in.

Rule Details

FieldValue
IDIAC-0921
SeverityINFO
IaC TypeTerraform
FrameworksTerraform, TerraformPlan
Checkov IDCKV_GCP_62

References