Standalone Compute Engine VMs without deletion protection
What does ZopNight detect here?
Compute Engine VMs without `deletionProtection` can be deleted by one console click, a mistyped `gcloud compute instances delete` or a Terraform plan nobody read. ZopNight flags standalone VMs where protection is off and skips members of managed instance groups, GKE node pools and Dataproc, where Google does not allow the setting.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-148 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | deletionProtection false on a VM outside a managed instance group |
| Source | ZopNight |
| Permissions used | compute.instances.list |
Where it applies
What deletion protection does and does not stop
Setting the deletionProtection flag makes delete requests fail. The
deletion protection guide
explains that only a user with a role containing compute.instances.create can clear the flag
again, which adds a deliberate second step before a long-lived VM disappears.
It does not stop everything. Google lists what still works on a protected VM: shutting it down from inside the guest, stopping, resetting or suspending it, and removal for abuse or project termination. So it is a guard against accidental deletion, not against downtime.
Checking the flag on your VMs
gcloud compute instances list --format="table(name, zone, status, deletionProtection)"False means the VM can be deleted directly. For one VM:
gcloud compute instances describe VM_NAME --zone=ZONE --format="value(deletionProtection)".
The conditions for a finding
- The VM is standalone: it does not belong to a managed instance group. Google states that deletion protection cannot be applied to managed instance group members, which covers GKE node pools and Dataproc workers.
- ZopNight’s inventory confirms deletion protection is off for the VM.
Both must hold. The rule does not consider the VM’s name, labels, size or uptime.
VMs outside the rule
Members of managed instance groups are skipped, because the fix is impossible for them and the group recreates members anyway. Unmanaged instance group members are still evaluated, since Google allows protection on them. If the setting was not read for a VM, ZopNight does not report it. VMs that are stopped long-term are a separate cost issue, covered by Stopped Standalone GCE VM.
Accident prevention, no saving
The saving is $0. What the flag prevents is losing a VM, and often its boot disk, to one mistaken command. Rebuilding a hand-configured server from memory is the cost it avoids.
Turning deletion protection on
-
Enable it on a running or stopped VM; Google notes you do not need to stop the instance:
Terminal window gcloud compute instances update VM_NAME --zone=ZONE --deletion-protection -
Confirm with the describe command above.
-
Remember that instance templates cannot carry the setting, so add it to whatever provisioning code creates your standalone VMs.
-
When a VM really must go, clear it first with
--no-deletion-protection, then delete.