Review VM access through project-wide SSH keys

Restrict project-wide keys on VMs that use metadata-based SSH authentication.

Description

When a VM accepts project-wide keys for metadata-based SSH, access intended for particular instances can extend to other VMs. Limit key scope to the instance’s purpose.

VMs with OS Login enabled do not use SSH keys from project or instance metadata. Check the actual authentication method and distinguish metadata key blocking from IAM-based access management.

Potential impact

  • Project-level keys can apply to more VMs than required.
  • Compromised or poorly managed keys can increase the risk to reachable instances.

Remediation

  • If project-wide keys are unnecessary for metadata-based SSH, set instance metadata block-project-ssh-keys to the string "true". Prepare required management access before changing it.
  • Consider OS Login with least-privilege IAM and remove unnecessary keys. Blocking project keys does not remove instance keys, local accounts or existing sessions.

Examples

Deployment Manager support has ended; use supported management tooling. These excerpts show only part of the instance metadata and omit other VM settings. Compute Engine metadata value fields are strings.

Before

yaml
resources:
  - name: vm
    type: compute.v1.instance
    properties:
      description: my-vm

After

yaml
resources:
  - name: vm
    type: compute.v1.instance
    properties:
      description: my-vm
      metadata:
        items:
          - key: block-project-ssh-keys
            value: "true"

Explanation:

  • Before: Project-wide key blocking is not explicit. Check effective OS Login and metadata settings.
  • After: Project-wide keys are blocked for metadata-based SSH. Manage permissions for other authentication paths separately.

References