Review Shielded VM protection settings

Configure boot-integrity protection on supported VM images.

Description

Shielded VM’s vTPM and integrity monitoring record boot measurements and compare them with a baseline. Secure Boot blocks boot components without trusted signatures; check image and driver compatibility before enabling it.

Potential impact

Disabled protections reduce the safeguards available to block or detect tampering with boot components.

Remediation

Enable vTPM and integrity monitoring, and enable Secure Boot where compatible. Configure collection and investigation of integrity alerts.

Examples

The first excerpt leaves settings to image and platform defaults; the second disables integrity monitoring. The revised options require a compatible Shielded VM image.

Before

yaml
- name: create a instance1
  google.cloud.gcp_compute_instance:
    name: test-object1
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present

- name: create a instance5
  google.cloud.gcp_compute_instance:
    name: test-object5
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present
    shielded_instance_config:
      enable_integrity_monitoring: no
      enable_secure_boot: yes
      enable_vtpm: yes

After

yaml
- name: create a instance
  google.cloud.gcp_compute_instance:
    name: test-object
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present
    shielded_instance_config:
      enable_integrity_monitoring: yes
      enable_secure_boot: yes
      enable_vtpm: yes

References