Interactive serial console is enabled for a VM

Disable interactive serial-console access when it is unnecessary.

Description

The interactive serial console provides a separate management path when SSH access or booting fails. Enabling it does not grant access to everyone; access requirements such as a valid SSH key still apply.

Potential impact

Leaving unnecessary console access enabled adds a management path that could be misused if an authorized key is exposed.

Remediation

Set the instance’s serial-port-enable metadata to the string FALSE when access is unnecessary. Restrict keys and permissions during troubleshooting and disable access afterward.

Examples

The examples compare string metadata values. Removing the instance setting can inherit the project setting, so disable it explicitly and verify the effective value.

Before

yaml
- name: serial_enabled
  google.cloud.gcp_compute_instance:
    metadata:
      serial-port-enable: "TRUE"
    zone: us-central1-a
    auth_kind: serviceaccount

After

yaml
- name: serial_disabled
  google.cloud.gcp_compute_instance:
    metadata:
      serial-port-enable: "FALSE"
    zone: us-central1-a
    auth_kind: serviceaccount

References