Description
Setting enable-oslogin = false in VM metadata disables OS Login for that VM even when the project enables it. Unnecessary overrides can leave separate key and account management outside the project standard.
Disabling OS Login does not remove all authentication. Review the actual SSH authentication method and approved access scope.
Potential impact
- SSH accounts and keys on particular VMs may be managed outside central IAM policies.
- Unknown exceptions or old keys can escape access reviews.
Remediation
- On supported VMs, set
enable-oslogin = true, or remove the disabling instance key after verifying that the project default enables OS Login. - Prepare required IAM login roles and service-account access, and test administrator connections. Enabling OS Login stops using metadata SSH keys.
Examples
These examples retain a historical image and network. Replace the old image and network name with an actually supported image and approved network, and configure the required connectivity.
Before
hcl
resource "google_compute_instance" "vm" {
name = "test"
machine_type = "e2-medium"
zone = "us-central1-a"
boot_disk {
initialize_params {
image = "debian-cloud/debian-9"
}
}
network_interface {
network = "default"
access_config {}
}
metadata = {
enable-oslogin = "FALSE"
}
}
After
hcl
resource "google_compute_instance" "vm" {
name = "test"
machine_type = "e2-medium"
zone = "us-central1-a"
boot_disk {
initialize_params {
image = "debian-cloud/debian-9"
}
}
network_interface {
network = "default"
access_config {}
}
metadata = {
enable-oslogin = true
}
}
Explanation:
- Before: The VM setting can override a project setting that enables OS Login.
- After: OS Login is enabled on the VM. A supported image and actual IAM login permissions are still required.