Control: GCP > Compute Engine > Instance > Shielded Instance Configuration
Check whether the Shielded VM settings of a GCP Compute Engine instance (Secure Boot, vTPM and Integrity Monitoring) match the Shielded Instance Configuration > * policies, and optionally enforce them.
GCP only accepts Shielded VM configuration changes while the instance is stopped, and the new settings take effect on the next boot. With Enforce: Enabled per ... the control applies the configuration once the instance is stopped; while the instance is running or still stopping it stays in alarm without attempting the update, since GCP would reject it.
Resource Types
This control targets the following resource types:
Policies
The following policies can be used to configure this control:
This control type relies on these other policies when running actions:
- GCP > Compute Engine > Instance > Shielded Instance Configuration > Secure Boot
- GCP > Compute Engine > Instance > Shielded Instance Configuration > vTPM
- GCP > Compute Engine > Instance > Shielded Instance Configuration > Integrity Monitoring
Permissions
Cloud permissions used by this control and its actions:
compute.instances.updateShieldedInstanceConfig
Category
In Your Workspace
Developers
- tmod:@turbot/gcp-computeengine#/control/types/shieldedInstanceConfiguration
- tmod:@turbot/turbot#/control/categories/security
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/gcp-computeengine#/control/types/shieldedInstanceConfiguration"
Get Controls