설명
Shielded VM의 vTPM과 무결성 모니터링은 부팅 측정값을 기록하고 기준과 비교합니다. Secure Boot는 신뢰할 수 없는 서명의 부팅 구성 요소를 차단하며, 이미지나 드라이버와의 호환성을 확인해야 합니다.
잠재적 영향
필요한 보호 기능이 꺼져 있으면 부팅 구성 요소의 변조를 차단하거나 발견할 수 있는 방어 수단이 줄어듭니다.
해결 방법
vTPM과 무결성 모니터링을 활성화하고, 호환되는 환경에서는 Secure Boot도 활성화하세요. 무결성 경고를 수집하고 조사할 수 있도록 구성하세요.
예시
첫 예시는 설정을 생략하므로 이미지와 플랫폼 기본값이 적용될 수 있고, 두 번째는 무결성 모니터링을 끕니다. 변경 후의 세 옵션은 호환되는 Shielded VM 이미지를 전제로 합니다.
변경 전
yaml
- name: create a instance1
google.cloud.gcp_compute_instance:
name: test-object1
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
- name: create a instance5
google.cloud.gcp_compute_instance:
name: test-object5
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
shielded_instance_config:
enable_integrity_monitoring: no
enable_secure_boot: yes
enable_vtpm: yes
변경 후
yaml
- name: create a instance
google.cloud.gcp_compute_instance:
name: test-object
machine_type: n1-standard-1
zone: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
shielded_instance_config:
enable_integrity_monitoring: yes
enable_secure_boot: yes
enable_vtpm: yes