VM instance allows project-wide SSH keys

For VMs using metadata-based SSH, review the need for project-wide keys and allow only required instance access.

Description

Allowing project-wide keys on a VM that uses metadata-based SSH lets users log in with a project key without registering it individually on that VM. Avoid extending access to users who do not need every VM. VMs with OS Login enabled do not use SSH keys from project or instance metadata for login, so confirm the authentication method first.

Potential impact

  • A leaked or unnecessarily retained project key can grant access to multiple VMs that accept it.
  • Sharing keys without separating VM purposes and user roles can expand the impact of compromise and make access revocation harder.

Remediation

  1. On VMs that need metadata-based SSH, set block-project-ssh-keys to the string TRUE and manage only required instance keys. Consider OS Login with least-privilege IAM where supported.
  2. Before blocking project keys, prepare alternative authentication for operators and automation and test actual access. Review instance keys and other login paths separately.
  3. In google.cloud 1.14.0, gcp_compute_instance does not update existing VM metadata. Use supported Console, gcloud, or API metadata updates for existing VMs and verify the result.

Examples

These excerpts show only metadata for a new VM. Other inputs, including the name, project, machine, disks, and credentials, are omitted.

Before

yaml
- name: ssh_keys_unblocked
  google.cloud.gcp_compute_instance:
    metadata:
      block-project-ssh-keys: "FALSE"
    zone: us-central1-a
    auth_kind: serviceaccount

- name: no_metadata
  google.cloud.gcp_compute_instance:
    zone: us-central1-a
    auth_kind: serviceaccount

These configurations explicitly permit project keys or omit the blocking setting. Actual access depends on OS Login, available keys, and network settings.

After

yaml
- name: ssh_keys_blocked
  google.cloud.gcp_compute_instance:
    metadata:
      block-project-ssh-keys: "TRUE"
    zone: us-central1-a
    auth_kind: serviceaccount

This prevents the VM from using project-wide keys for metadata-based SSH. It does not delete keys from the project or block instance-level keys. Existing VMs require a separate metadata update.

References