Description
Allowing project-wide keys on a VM that uses metadata-based SSH lets users log in with a project key without registering it individually on that VM. Avoid extending access to users who do not need every VM. VMs with OS Login enabled do not use SSH keys from project or instance metadata for login, so confirm the authentication method first.
Potential impact
- A leaked or unnecessarily retained project key can grant access to multiple VMs that accept it.
- Sharing keys without separating VM purposes and user roles can expand the impact of compromise and make access revocation harder.
Remediation
- On VMs that need metadata-based SSH, set
block-project-ssh-keysto the stringTRUEand manage only required instance keys. Consider OS Login with least-privilege IAM where supported. - Before blocking project keys, prepare alternative authentication for operators and automation and test actual access. Review instance keys and other login paths separately.
- In
google.cloud1.14.0,gcp_compute_instancedoes not update existing VM metadata. Use supported Console, gcloud, or API metadata updates for existing VMs and verify the result.
Examples
These excerpts show only metadata for a new VM. Other inputs, including the name, project, machine, disks, and credentials, are omitted.
Before
- name: ssh_keys_unblocked
google.cloud.gcp_compute_instance:
metadata:
block-project-ssh-keys: "FALSE"
zone: us-central1-a
auth_kind: serviceaccount
- name: no_metadata
google.cloud.gcp_compute_instance:
zone: us-central1-a
auth_kind: serviceaccount
These configurations explicitly permit project keys or omit the blocking setting. Actual access depends on OS Login, available keys, and network settings.
After
- name: ssh_keys_blocked
google.cloud.gcp_compute_instance:
metadata:
block-project-ssh-keys: "TRUE"
zone: us-central1-a
auth_kind: serviceaccount
This prevents the VM from using project-wide keys for metadata-based SSH. It does not delete keys from the project or block instance-level keys. Existing VMs require a separate metadata update.