Description
Shielded VM’s vTPM and integrity monitoring record boot measurements and compare them with a baseline. Secure Boot blocks boot components without trusted signatures; check image and driver compatibility before enabling it.
Potential impact
Disabled protections reduce the safeguards available to block or detect tampering with boot components.
Remediation
Enable vTPM and integrity monitoring, and enable Secure Boot where compatible. Configure collection and investigation of integrity alerts.
Examples
The first excerpt leaves settings to image and platform defaults; the second disables integrity monitoring. The revised options require a compatible Shielded VM image.
Before
yaml
- name: create a instance1
google.cloud.gcp_compute_instance:
name: test-object1
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
- name: create a instance5
google.cloud.gcp_compute_instance:
name: test-object5
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
shielded_instance_config:
enable_integrity_monitoring: no
enable_secure_boot: yes
enable_vtpm: yes
After
yaml
- name: create a instance
google.cloud.gcp_compute_instance:
name: test-object
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
shielded_instance_config:
enable_integrity_monitoring: yes
enable_secure_boot: yes
enable_vtpm: yes