Review OS Login disabling overrides on GCP VMs

Check that VM SSH policies follow the project’s IAM access-management requirements.

Description

Setting enable-oslogin = false in VM metadata disables OS Login for that VM even when the project enables it. Unnecessary overrides can leave separate key and account management outside the project standard.

Disabling OS Login does not remove all authentication. Review the actual SSH authentication method and approved access scope.

Potential impact

  • SSH accounts and keys on particular VMs may be managed outside central IAM policies.
  • Unknown exceptions or old keys can escape access reviews.

Remediation

  • On supported VMs, set enable-oslogin = true, or remove the disabling instance key after verifying that the project default enables OS Login.
  • Prepare required IAM login roles and service-account access, and test administrator connections. Enabling OS Login stops using metadata SSH keys.

Examples

These examples retain a historical image and network. Replace the old image and network name with an actually supported image and approved network, and configure the required connectivity.

Before

hcl
resource "google_compute_instance" "vm" {
  name         = "test"
  machine_type = "e2-medium"
  zone         = "us-central1-a"

  boot_disk {
    initialize_params {
      image = "debian-cloud/debian-9"
    }
  }

  network_interface {
    network = "default"

    access_config {}
  }

  metadata = {
    enable-oslogin = "FALSE"
  }
}

After

hcl
resource "google_compute_instance" "vm" {
  name         = "test"
  machine_type = "e2-medium"
  zone         = "us-central1-a"

  boot_disk {
    initialize_params {
      image = "debian-cloud/debian-9"
    }
  }

  network_interface {
    network = "default"

    access_config {}
  }

  metadata = {
    enable-oslogin = true
  }
}

Explanation:

  • Before: The VM setting can override a project setting that enables OS Login.
  • After: OS Login is enabled on the VM. A supported image and actual IAM login permissions are still required.

References