Description
When a VM accepts project-wide keys for metadata-based SSH, access intended for particular instances can extend to other VMs. Limit key scope to the instance’s purpose.
VMs with OS Login enabled do not use SSH keys from project or instance metadata. Check the actual authentication method and distinguish metadata key blocking from IAM-based access management.
Potential impact
- Project-level keys can apply to more VMs than required.
- Compromised or poorly managed keys can increase the risk to reachable instances.
Remediation
- If project-wide keys are unnecessary for metadata-based SSH, set instance metadata
block-project-ssh-keysto the string"true". Prepare required management access before changing it. - Consider OS Login with least-privilege IAM and remove unnecessary keys. Blocking project keys does not remove instance keys, local accounts or existing sessions.
Examples
Deployment Manager support has ended; use supported management tooling. These excerpts show only part of the instance metadata and omit other VM settings. Compute Engine metadata value fields are strings.
Before
yaml
resources:
- name: vm
type: compute.v1.instance
properties:
description: my-vm
After
yaml
resources:
- name: vm
type: compute.v1.instance
properties:
description: my-vm
metadata:
items:
- key: block-project-ssh-keys
value: "true"
Explanation:
- Before: Project-wide key blocking is not explicit. Check effective OS Login and metadata settings.
- After: Project-wide keys are blocked for metadata-based SSH. Manage permissions for other authentication paths separately.