Description
Shielded VM uses Secure Boot, vTPM and integrity monitoring to help protect the boot chain and system integrity. Secure Boot restricts untrusted boot components, while vTPM and integrity monitoring help identify changes in boot measurements.
Supported images can have vTPM and integrity monitoring enabled by default even without shieldedInstanceConfig. Enable Secure Boot after checking image and driver compatibility.
Potential impact
- Failing to detect changes in boot measurements can delay investigation of VM tampering.
- Enabling Secure Boot with unsigned kernels or drivers can cause boot failures.
Remediation
- Enable
enableVtpmandenableIntegrityMonitoring, and verify the normal baseline and integrity reports. - Test image, kernel and driver compatibility before applying
enableSecureBoot: truewhere supported. Plan any required stop, restart and recovery for existing VMs.
Examples
These protection-option excerpts use the retired Deployment Manager format. Supply omitted VM requirements, such as a supported boot image and network, through a supported tool.
Before
yaml
resources:
- name: vm-template
type: compute.v1.instance
properties:
canIpForward: false
After
yaml
resources:
- name: vm-template
type: compute.v1.instance
properties:
canIpForward: false
shieldedInstanceConfig:
enableSecureBoot: true
enableVtpm: true
enableIntegrityMonitoring: true
Explanation:
- Before: Protection options are not specified. This alone does not establish that all Shielded features are disabled.
- After: All three options are enabled. Verify successful booting and actual integrity reports as well.