Vertex AI Workbench instances running without Shielded VM Secure Boot
What does ZopNight detect here?
Secure Boot is off by default on Vertex AI Workbench instances, according to the `enableSecureBoot` field in Google's Workbench API. ZopNight flags Workbench instances with Secure Boot disabled as a low-severity security finding with no cost saving, and recommends turning on Secure Boot together with vTPM and integrity monitoring.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1236 |
| Category | security |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | Secure Boot disabled |
| Source | ZopNight |
| Permissions used | notebooks.instances.list · notebooks.instances.get |
Where it applies
What Secure Boot protects on a notebook VM
Shielded VM Secure Boot checks the digital signature of every boot component and halts the boot if a check fails. Google’s Shielded VM overview explains that this stops many bootkits and rootkits, which would otherwise load before the operating system and survive reboots.
Workbench does not turn it on for you. The
Workbench API reference
describes enableSecureBoot as “Disabled by default”, next to separate settings for vTPM and
integrity monitoring.
Checking Secure Boot on your instances
gcloud workbench instances list --location=us-central1-a \ --format="table(name,state,gceSetup.shieldedInstanceConfig.enableSecureBoot)"An empty or False value in the last column means Secure Boot is off.
The configuration value checked
ZopNight reads each instance’s Shielded VM configuration during inventory and flags it when Secure Boot is recorded as disabled. There is no threshold or observation window; the check repeats on every scan.
Things outside this check
vTPM and integrity monitoring are recommended alongside Secure Boot but do not trigger this finding on their own. Compute Engine VMs outside Workbench are covered by GCP VM Shielded VM Not Enabled.
A hardening gap, not a cost
The rule reports no saving. What it closes is the window for tampered boot components to run unnoticed on a machine that often holds data access credentials.
Enabling Secure Boot on a Workbench instance
- Check drivers first. Google’s Shielded VM modification guide warns that many Linux images refuse unsigned out-of-tree kernel modules with Secure Boot on, which most often affects GPU drivers.
- Stop the instance:
gcloud workbench instances stop INSTANCE_NAME --location=us-central1-a. - Update it:
gcloud workbench instances update INSTANCE_NAME --location=us-central1-a --shielded-secure-boot=true --shielded-vtpm=true --shielded-integrity-monitoring=true. - Start it again and confirm the kernel and any GPU driver load.