Hide your staging environment from Google (in Rails)
shellycloud.com
shellycloud.com
I guess if you're gonna do some freaky A/B testing this might be a good idea. I dunno, though... it really depends where vulnerability testing occurs in your lifecycle (before, during or after staging).
EDIT: Right, you might make it accessible to the outside world to leverage cloud-based vulnerability-assessment or load-testing tools. All good then.
For those that work remotely, or use external integration tests for their staging environments, public access is OK.
I worked on one website where we made a pre-prod version public but restricted by IP. We had a load test vendor (whose IPs were whitelisted) hammer the site from locations worldwide. This let us compare latency from, say, APAC vs EMEA.