Description
OS Login connects Google IAM to SSH access, simplifying account management and auditing. Enabling it at project level helps maintain consistent access policies.
An instance can enable OS Login when the project disables it, or disable it when the project enables it. Check each VM’s effective setting; disabling OS Login does not mean anonymous SSH access.
Potential impact
- Centrally managing user SSH permissions through IAM can become harder.
- Old metadata SSH keys or separately managed accounts may remain in use.
Remediation
- For supported Linux VMs, set
enable-oslogin = truein projectmetadataand review instance exceptions. - Prepare the required OS Login IAM roles and service-account access first. Enabling OS Login stops using project and instance metadata SSH keys, so test approved administrators’ logins.
Examples
These excerpts show project metadata. Preserve other metadata managed by the resource, and use appropriate separate controls for images that do not support OS Login.
Before
hcl
resource "google_compute_project_metadata" "project_metadata" {
metadata = {
enable-oslogin = false
}
}
After
hcl
resource "google_compute_project_metadata" "project_metadata" {
metadata = {
enable-oslogin = true
}
}
Explanation:
- Before: The project default disables OS Login. Check individual VM settings separately.
- After: The project default enables OS Login. Verify instance-level disabling overrides and actual login permissions.