Lesson 13 / 25

Cloud Storage

Choose storage classes and locations, and secure buckets properly.

Object storage with classes and locations

Cloud Storage stores objects in buckets. Each bucket has a location type: region (lowest latency to compute in that region), dual-region or multi-region (geo-redundant). Storage classes trade storage price against access price: Standard for hot data, Nearline (minimum storage duration 30 days), Coldline (90 days) and Archive (365 days). Unlike some other clouds' archive tiers, even Archive objects are readable within milliseconds; you simply pay more per read and an early-deletion charge. Object Lifecycle Management changes class or deletes objects by age; Autoclass can move objects automatically by access pattern. For security, enable uniform bucket-level access (IAM only, no per-object ACLs), keep public access prevention on, and share objects temporarily with signed URLs. Object versioning and retention policies protect against deletion.

Classes by how often you read

The same API serves every class; only price and minimum duration change.

Four stacked shelves from bright to faded, each holding identical box icons, with a clock symbol growing larger toward the bottom shelf.
Figure 5.1 — Standard, Nearline, Coldline and Archive storage classes.

Lifecycle rules and a signed URL

Logs move to colder classes and are deleted after two years.

cat > lifecycle.json <<'EOF'
{
  "rule": [
    {"action": {"type": "SetStorageClass", "storageClass": "NEARLINE"},
     "condition": {"age": 30, "matchesPrefix": ["logs/"]}},
    {"action": {"type": "SetStorageClass", "storageClass": "ARCHIVE"},
     "condition": {"age": 180, "matchesPrefix": ["logs/"]}},
    {"action": {"type": "Delete"},
     "condition": {"age": 730, "matchesPrefix": ["logs/"]}}
  ]
}
EOF
gcloud storage buckets update gs://shop-dev-assets-123 --lifecycle-file=lifecycle.json

# a download link valid for 15 minutes (signed by impersonating a service account)
gcloud storage sign-url gs://shop-dev-assets-123/invoices/1001.pdf --duration=15m \
  --impersonate-service-account=signer@shop-dev-123456.iam.gserviceaccount.com

Minimum durations are billed

Deleting a Coldline object after 10 days still bills 90 days of storage. Put data you rewrite often in Standard, even if it is read rarely.

Quick check: How quickly can you read an object stored in the Archive class?

  • Within milliseconds, at a higher per-read cost
  • After a restore job that takes hours
  • Only after copying it to Standard manually
  • Never; Archive is write-only
Answer

Within milliseconds, at a higher per-read cost — All Cloud Storage classes offer millisecond access; colder classes cost more per read and have minimum durations.