Review VM instance OS Login settings

Check effective OS Login settings together with SSH access permissions.

Description

OS Login centralizes SSH access management through IAM. Setting a VM's enable-oslogin metadata to "false" disables OS Login on that VM even when it is enabled at the project level. Omitting the VM setting can instead allow the project setting to apply.

Disabling OS Login does not remove all SSH authentication. Verify that the actual account and key management method meets organizational access policies.

Potential impact

  • Distributed SSH key and account management can delay the removal of obsolete access.
  • Changing authentication methods without preparation can interrupt required administrator access.

Remediation

  • On supported VMs, set enable-oslogin to "true", or remove the disabling override so that an enabled project setting applies.
  • Prepare the necessary IAM login roles and service account access, then test administrator connections. Metadata SSH keys are no longer used when OS Login is enabled.

Examples

These metadata excerpts use the retired Deployment Manager format. Apply the same settings through a supported tool and supply omitted requirements such as a supported image and network. Metadata values are strings.

Before

yaml
resources:
  - name: vm
    type: compute.v1.instance
    properties:
      metadata:
        items:
          - key: enable-oslogin
            value: "false"

After

yaml
resources:
  - name: vm
    type: compute.v1.instance
    properties:
      metadata:
        items:
          - key: enable-oslogin
            value: "true"

Explanation:

  • Before: OS Login is explicitly disabled on the VM.
  • After: OS Login is enabled on the VM. This setting alone does not grant a particular user permission to log in.

References