Review Shielded VM protection settings

Check effective Shielded VM protections and boot-image compatibility.

Description

Shielded VM uses Secure Boot, vTPM and integrity monitoring to help protect the boot chain and system integrity. Secure Boot restricts untrusted boot components, while vTPM and integrity monitoring help identify changes in boot measurements.

Supported images can have vTPM and integrity monitoring enabled by default even without shieldedInstanceConfig. Enable Secure Boot after checking image and driver compatibility.

Potential impact

  • Failing to detect changes in boot measurements can delay investigation of VM tampering.
  • Enabling Secure Boot with unsigned kernels or drivers can cause boot failures.

Remediation

  • Enable enableVtpm and enableIntegrityMonitoring, and verify the normal baseline and integrity reports.
  • Test image, kernel and driver compatibility before applying enableSecureBoot: true where supported. Plan any required stop, restart and recovery for existing VMs.

Examples

These protection-option excerpts use the retired Deployment Manager format. Supply omitted VM requirements, such as a supported boot image and network, through a supported tool.

Before

yaml
resources:
  - name: vm-template
    type: compute.v1.instance
    properties:
      canIpForward: false

After

yaml
resources:
  - name: vm-template
    type: compute.v1.instance
    properties:
      canIpForward: false
      shieldedInstanceConfig:
        enableSecureBoot: true
        enableVtpm: true
        enableIntegrityMonitoring: true

Explanation:

  • Before: Protection options are not specified. This alone does not establish that all Shielded features are disabled.
  • After: All three options are enabled. Verify successful booting and actual integrity reports as well.

References