Skip to main content

Compute Engine

Compute Engine runs virtual machines (VMs) on Google Cloud. The GCP platform runs no hand-managed servers: its VMs are GKE nodes and two optional kinds of small helpers, and the GCP Enterprise Baseline enforces the same hardening on every one of them through organization policy.

What it does​

A VM instance runs a boot image on a machine type in one zone. A Shielded VM boots only verified software (secure boot) and records its boot state in a virtual TPM for integrity monitoring. A VM runs as a service account whose roles decide what its software may call. Project metadata applies settings, such as OS Login, to every VM of a project. GKE creates and manages its node VMs itself from node pools, and a GKE Autopilot cluster manages them entirely.

How BuiltForProd uses it​

Where VMs run.

VMsProjectCreated by
GKE system pooleach stage projectThe Web App Blueprint: e2-standard-2, tainted CriticalAddonsOnly, one to two per zone, about $49 per node per month
GKE auto-provisioned poolseach stage projectThe Web App Blueprint's node auto-provisioning, for the application pods, within CPU and memory limits per stage
Runner cluster nodesacme-core-autoThe optional self-hosted runners on GKE Autopilot (enable_github_runners, off)
Bastionsacme-core-networkThe optional e2-micro bastions, one per isolation domain (enable_bastion, off)

Every GKE node uses Container-Optimized OS, Shielded VM with secure boot and integrity monitoring, the GKE metadata server for Workload Identity Federation for GKE, and the node service account sa-acme-gke-nodes instead of the default one. The bastions run Debian 12 as Shielded VMs with OS Login and a service account that holds no roles (Identity-Aware Proxy).

What every VM must satisfy. The organization policies at the organization node apply to every project:

ConstraintEffect on VMs
compute.vmExternalIpAccess (deny all)No VM has an external IP; egress goes through Cloud NAT
compute.requireOsLoginSSH only through OS Login
compute.requireShieldedVmOnly Shielded VM images
compute.disableSerialPortAccessNo interactive serial console
compute.skipDefaultNetworkCreationNo default network with its permissive rules
custom.requirePlatformLabelsInstance (dry run)Instances without namespace, stage, managed_by labels are logged

The project baseline also sets enable-oslogin = TRUE as project metadata in every project and de-privileges the default Compute Engine service account, while iam.automaticIamGrantsForDefaultServiceAccounts stops new default accounts from receiving Editor. GKE's default node pool is still created with the node service account and Shielded VM settings, then removed at once, because the Shielded VM constraint applies to it too.

Reaching a VM. No VM listens on the internet. Engineers reach a VM that carries the iap-target tag through Identity-Aware Proxy, with OS Login as their own identity.

Terms you will see​

TermMeaning
Shielded VMA VM with secure boot, a virtual TPM and integrity monitoring.
Node poolA group of identical GKE node VMs.
Node auto-provisioningGKE creating node pools sized for pending pods.
Default service accountThe Compute Engine account Google creates per project, de-privileged here.
Project metadataSettings applied to every VM of a project, such as enable-oslogin.

Where to read more​