Description
The interactive serial console provides a separate management path when SSH access or booting fails. Enabling it does not grant access to everyone; access requirements such as a valid SSH key still apply.
Potential impact
Leaving unnecessary console access enabled adds a management path that could be misused if an authorized key is exposed.
Remediation
Set the instance’s serial-port-enable metadata to the string FALSE when access is unnecessary. Restrict keys and permissions during troubleshooting and disable access afterward.
Examples
The examples compare string metadata values. Removing the instance setting can inherit the project setting, so disable it explicitly and verify the effective value.
Before
yaml
- name: serial_enabled
google.cloud.gcp_compute_instance:
metadata:
serial-port-enable: "TRUE"
zone: us-central1-a
auth_kind: serviceaccount
After
yaml
- name: serial_disabled
google.cloud.gcp_compute_instance:
metadata:
serial-port-enable: "FALSE"
zone: us-central1-a
auth_kind: serviceaccount