Compute Engine
Compute Engine runs virtual machines (VMs) on Google Cloud. The GCP platform runs no hand-managed servers: its VMs are GKE nodes and two optional kinds of small helpers, and the GCP Enterprise Baseline enforces the same hardening on every one of them through organization policy.
What it does
A VM instance runs a boot image on a machine type in one zone. A Shielded VM boots only verified software (secure boot) and records its boot state in a virtual TPM for integrity monitoring. A VM runs as a service account whose roles decide what its software may call. Project metadata applies settings, such as OS Login, to every VM of a project. GKE creates and manages its node VMs itself from node pools, and a GKE Autopilot cluster manages them entirely.
How BuiltForProd uses it
Where VMs run.
| VMs | Project | Created by |
|---|---|---|
| GKE system pool | each stage project | The Web App Blueprint: e2-standard-2, tainted CriticalAddonsOnly, one to two per zone, about $49 per node per month |
| GKE auto-provisioned pools | each stage project | The Web App Blueprint's node auto-provisioning, for the application pods, within CPU and memory limits per stage |
| Runner cluster nodes | acme-core-auto | The optional self-hosted runners on GKE Autopilot (enable_github_runners, off) |
| Bastions | acme-core-network | The optional e2-micro bastions, one per isolation domain (enable_bastion, off) |
Every GKE node uses Container-Optimized OS, Shielded VM with secure boot and integrity monitoring, the GKE metadata server for Workload Identity Federation for GKE, and the node service account sa-acme-gke-nodes instead of the default one. The bastions run Debian 12 as Shielded VMs with OS Login and a service account that holds no roles (Identity-Aware Proxy).
What every VM must satisfy. The organization policies at the organization node apply to every project:
| Constraint | Effect on VMs |
|---|---|
compute.vmExternalIpAccess (deny all) | No VM has an external IP; egress goes through Cloud NAT |
compute.requireOsLogin | SSH only through OS Login |
compute.requireShieldedVm | Only Shielded VM images |
compute.disableSerialPortAccess | No interactive serial console |
compute.skipDefaultNetworkCreation | No default network with its permissive rules |
custom.requirePlatformLabelsInstance (dry run) | Instances without namespace, stage, managed_by labels are logged |
The project baseline also sets enable-oslogin = TRUE as project metadata in every project and de-privileges the default Compute Engine service account, while iam.automaticIamGrantsForDefaultServiceAccounts stops new default accounts from receiving Editor. GKE's default node pool is still created with the node service account and Shielded VM settings, then removed at once, because the Shielded VM constraint applies to it too.
Reaching a VM. No VM listens on the internet. Engineers reach a VM that carries the iap-target tag through Identity-Aware Proxy, with OS Login as their own identity.
Terms you will see
| Term | Meaning |
|---|---|
| Shielded VM | A VM with secure boot, a virtual TPM and integrity monitoring. |
| Node pool | A group of identical GKE node VMs. |
| Node auto-provisioning | GKE creating node pools sized for pending pods. |
| Default service account | The Compute Engine account Google creates per project, de-privileged here. |
| Project metadata | Settings applied to every VM of a project, such as enable-oslogin. |
Where to read more
- GCP Enterprise Baseline overview and the GCP Web App Blueprint overview.
- Organization Policy Service for the constraints listed above.
- Defense in depth for layered host hardening.