Description
OS Login integrates SSH access to supported Linux VMs with IAM. Without it, other authentication paths, such as metadata SSH keys, require separate management, which can make it harder to revoke access consistently when users leave or no longer need it. Disabling OS Login does not itself permit unauthenticated SSH.
Potential impact
- Users can retain access through old keys or excessive permissions that have not been removed.
- Key management spread across projects and VMs can lead to missed revocations and difficulties reviewing access history.
Remediation
- Confirm OS Login support in the VM's operating system and guest environment, and first grant users and automation the required IAM login permissions.
- Set
enable-osloginto the stringTRUE, then test login and required administration tasks. Enabling OS Login stops SSH keys in project and instance metadata from being used for login, so plan to prevent loss of access. - In
google.cloud1.14.0,gcp_compute_instancedoes not update existing VM metadata. Use supported Console, gcloud, or API metadata updates for existing VMs. Restrict firewall access and administration paths separately.
Examples
These excerpts show metadata to supply when creating a VM. Other required inputs, including the name, project, machine and disk configuration, and credentials, are omitted.
Before
- name: oslogin-disabled
google.cloud.gcp_compute_instance:
metadata:
enable-oslogin: "FALSE"
zone: us-central1-a
auth_kind: serviceaccount
This disables OS Login for the VM. Actual SSH access depends on the remaining authentication methods and network settings.
After
- name: oslogin-enabled
google.cloud.gcp_compute_instance:
metadata:
enable-oslogin: "TRUE"
zone: us-central1-a
auth_kind: serviceaccount
This metadata enables OS Login for a new VM. Confirm the required IAM permissions and guest support; rerunning this task alone does not change an existing VM's metadata.