Review GCP project OS Login settings

Manage SSH access to supported VMs through IAM and check instance overrides.

Description

OS Login connects Google IAM to SSH access, simplifying account management and auditing. Enabling it at project level helps maintain consistent access policies.

An instance can enable OS Login when the project disables it, or disable it when the project enables it. Check each VM’s effective setting; disabling OS Login does not mean anonymous SSH access.

Potential impact

  • Centrally managing user SSH permissions through IAM can become harder.
  • Old metadata SSH keys or separately managed accounts may remain in use.

Remediation

  • For supported Linux VMs, set enable-oslogin = true in project metadata and review instance exceptions.
  • Prepare the required OS Login IAM roles and service-account access first. Enabling OS Login stops using project and instance metadata SSH keys, so test approved administrators’ logins.

Examples

These excerpts show project metadata. Preserve other metadata managed by the resource, and use appropriate separate controls for images that do not support OS Login.

Before

hcl
resource "google_compute_project_metadata" "project_metadata" {
  metadata = {
    enable-oslogin = false
  }
}

After

hcl
resource "google_compute_project_metadata" "project_metadata" {
  metadata = {
    enable-oslogin = true
  }
}

Explanation:

  • Before: The project default disables OS Login. Check individual VM settings separately.
  • After: The project default enables OS Login. Verify instance-level disabling overrides and actual login permissions.

References