Configure private bucket access

This page provides an overview of private bucket access and instructions for using it for Cloud Storage buckets with Cloud CDN.

For Cloud Storage buckets

Implementing private bucket access for your Cloud CDN backend bucket lets content in your storage buckets be accessed only through Cloud CDN and not directly by using the Cloud Storage XML API path-style endpoint or bucket-bound hostname.

To prevent direct access to your private Cloud Storage buckets, Cloud Storage uses Identity and Access Management permissions, which helps limit the access to Cloud CDN or Cloud Load Balancing traffic only without having to enable signed URLs or signed cookies for this route.

To configure private bucket access for Cloud Storage, use the following instructions:

  1. Create a Cloud Storage bucket

  2. Move content into the bucket

  3. Create an external Application Load Balancer that connects your private Cloud Storage bucket to the backend bucket.

  4. Enable access for your service account