Description
Shielded VM Secure Boot restricts untrusted boot components, while vTPM and integrity monitoring help identify changes in boot measurements. The three features serve different purposes.
Omitting the configuration block does not disable all protection. On supported images, vTPM and integrity monitoring are enabled by default; enable Secure Boot after checking compatibility.
Potential impact
- Failure to detect changed boot measurements can delay compromise investigations.
- Enabling Secure Boot with unsigned kernels or drivers can prevent successful boot.
Remediation
- Enable
enable_vtpmandenable_integrity_monitoring, and review the trusted baseline and integrity reports. - Test image, kernel and driver compatibility before setting
enable_secure_boot = truewhere supported. Plan required stops, restarts and recovery when changing existing VMs.
Examples
These excerpts show only boot-protection options. Configure a supported boot disk, networking and other required VM settings separately.
Before
hcl
resource "google_compute_instance" "vm" {
name = "primary-application-server"
machine_type = "e2-medium"
zone = "us-central1-a"
shielded_instance_config {
enable_secure_boot = true
enable_vtpm = true
enable_integrity_monitoring = false
}
}
After
hcl
resource "google_compute_instance" "vm" {
name = "primary-application-server"
machine_type = "e2-medium"
zone = "us-central1-a"
shielded_instance_config {
enable_secure_boot = true
enable_vtpm = true
enable_integrity_monitoring = true
}
}
Explanation:
- Before: Secure Boot and vTPM are enabled, but integrity monitoring is disabled.
- After: All three options are enabled. Verify successful boot and actual integrity reporting as well.