Shielded VM 보호 설정 점검

지원되는 VM 이미지에서 부팅 무결성 보호를 구성하세요.

설명

Shielded VM의 vTPM과 무결성 모니터링은 부팅 측정값을 기록하고 기준과 비교합니다. Secure Boot는 신뢰할 수 없는 서명의 부팅 구성 요소를 차단하며, 이미지나 드라이버와의 호환성을 확인해야 합니다.

잠재적 영향

필요한 보호 기능이 꺼져 있으면 부팅 구성 요소의 변조를 차단하거나 발견할 수 있는 방어 수단이 줄어듭니다.

해결 방법

vTPM과 무결성 모니터링을 활성화하고, 호환되는 환경에서는 Secure Boot도 활성화하세요. 무결성 경고를 수집하고 조사할 수 있도록 구성하세요.

예시

첫 예시는 설정을 생략하므로 이미지와 플랫폼 기본값이 적용될 수 있고, 두 번째는 무결성 모니터링을 끕니다. 변경 후의 세 옵션은 호환되는 Shielded VM 이미지를 전제로 합니다.

변경 전

yaml
- name: create a instance1
  google.cloud.gcp_compute_instance:
    name: test-object1
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present

- name: create a instance5
  google.cloud.gcp_compute_instance:
    name: test-object5
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present
    shielded_instance_config:
      enable_integrity_monitoring: no
      enable_secure_boot: yes
      enable_vtpm: yes

변경 후

yaml
- name: create a instance
  google.cloud.gcp_compute_instance:
    name: test-object
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present
    shielded_instance_config:
      enable_integrity_monitoring: yes
      enable_secure_boot: yes
      enable_vtpm: yes

참조