Review Shielded protection settings on GCP VMs

Check actual boot-protection settings and image compatibility together.

Description

Shielded VM Secure Boot restricts untrusted boot components, while vTPM and integrity monitoring help identify changes in boot measurements. The three features serve different purposes.

Omitting the configuration block does not disable all protection. On supported images, vTPM and integrity monitoring are enabled by default; enable Secure Boot after checking compatibility.

Potential impact

  • Failure to detect changed boot measurements can delay compromise investigations.
  • Enabling Secure Boot with unsigned kernels or drivers can prevent successful boot.

Remediation

  • Enable enable_vtpm and enable_integrity_monitoring, and review the trusted baseline and integrity reports.
  • Test image, kernel and driver compatibility before setting enable_secure_boot = true where supported. Plan required stops, restarts and recovery when changing existing VMs.

Examples

These excerpts show only boot-protection options. Configure a supported boot disk, networking and other required VM settings separately.

Before

hcl
resource "google_compute_instance" "vm" {
  name         = "primary-application-server"
  machine_type = "e2-medium"
  zone         = "us-central1-a"

  shielded_instance_config {
    enable_secure_boot        = true
    enable_vtpm               = true
    enable_integrity_monitoring = false
  }
}

After

hcl
resource "google_compute_instance" "vm" {
  name         = "primary-application-server"
  machine_type = "e2-medium"
  zone         = "us-central1-a"

  shielded_instance_config {
    enable_secure_boot         = true
    enable_vtpm                = true
    enable_integrity_monitoring = true
  }
}

Explanation:

  • Before: Secure Boot and vTPM are enabled, but integrity monitoring is disabled.
  • After: All three options are enabled. Verify successful boot and actual integrity reporting as well.

References