Enabling Cloud Storage end-to-end checksums for improved data integrity and durability

Google Cloud updated all Cloud Storage SDKs to calculate and transmit CRC32 checksums by default during uploads. This change closes a previous gap where in-flight data could suffer bit flips before server-side verification. The SDKs now verify download checksums and utilize gRPC range checksums for partial reads. Developers should update their dependencies to enable these integrity protections without manual configuration.

Google Cloud notes that data can experience bit flips throughout its path, so it has begun providing end‑to‑end checksumming automatically in every Cloud Storage SDK. The updated SDKs now compute a CRC32 checksum for any upload that lacks one, send that value to the service, and also verify the stored checksum when downloading objects; when range reads are performed via the gRPC API, the SDK uses gRPC’s built‑in range checksum to validate the returned bytes. Internally, Cloud Storage protects data by encrypting incoming bytes, checksumming the ciphertext, decrypting it, and discarding it if the plaintext checksum differs, then splitting uploads into chunks each with its own CRC, aggregating chunks into shard files whose CRCs are derived from the chunk CRCs, and storing those shards in Colossus where Reed‑Solomon encoding and block‑level inline checksums further guard integrity. The team advises upgrading to the latest SDK releases to activate these protections.