Question
Cloud Run CLI default change for unauthenticated access in gcloud 2023.08.00
Tasadduq BurneyownerOwner · Founder
29K reputation · 07 Aug 2022, 13:37 UTC
66.8K views0
Teams using Cloud Run must decide whether to rely on the gcloud CLI default that marks services as private when the `--allow-unauthenticated` flag is omitted, or to explicitly declare `--no-allow-unauthenticated` in their deployment scripts. The CLI default changed in version 2023.08.00, shifting from an implicit public allowance to a private‑by‑default stance, but future releases could revert or alter this behavior.
Because infrastructure‑as‑code templates often omit the flag to keep scripts concise, there is uncertainty about whether the current default will remain stable across toolchain upgrades, and whether an inadvertent IAM binding to `allUsers` could override the intended privacy.
What are the recommended practices for declaring unauthenticated access in IaC to guard against CLI default shifts? How can teams verify that a service stays private after a CLI upgrade? Should IaC always set `allowUnauthenticated: false` to eliminate reliance on the CLI default?