Skip to main content
compliance · gcp

Standalone Compute Engine VMs without deletion protection

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

Compute Engine VMs without `deletionProtection` can be deleted by one console click, a mistyped `gcloud compute instances delete` or a Terraform plan nobody read. ZopNight flags standalone VMs where protection is off and skips members of managed instance groups, GKE node pools and Dataproc, where Google does not allow the setting.

Signal and threshold

How ZopNight evaluates Standalone Compute Engine VMs without deletion protection.
Field Value
Rule IDsRC-148
Categorycompliance
Severitymedium
Metricnone — pure configuration read
ThresholddeletionProtection false on a VM outside a managed instance group
SourceZopNight
Permissions usedcompute.instances.list

What deletion protection does and does not stop

Setting the deletionProtection flag makes delete requests fail. The deletion protection guide explains that only a user with a role containing compute.instances.create can clear the flag again, which adds a deliberate second step before a long-lived VM disappears.

It does not stop everything. Google lists what still works on a protected VM: shutting it down from inside the guest, stopping, resetting or suspending it, and removal for abuse or project termination. So it is a guard against accidental deletion, not against downtime.

Checking the flag on your VMs

Terminal window
gcloud compute instances list --format="table(name, zone, status, deletionProtection)"

False means the VM can be deleted directly. For one VM: gcloud compute instances describe VM_NAME --zone=ZONE --format="value(deletionProtection)".

The conditions for a finding

  1. The VM is standalone: it does not belong to a managed instance group. Google states that deletion protection cannot be applied to managed instance group members, which covers GKE node pools and Dataproc workers.
  2. ZopNight’s inventory confirms deletion protection is off for the VM.

Both must hold. The rule does not consider the VM’s name, labels, size or uptime.

VMs outside the rule

Members of managed instance groups are skipped, because the fix is impossible for them and the group recreates members anyway. Unmanaged instance group members are still evaluated, since Google allows protection on them. If the setting was not read for a VM, ZopNight does not report it. VMs that are stopped long-term are a separate cost issue, covered by Stopped Standalone GCE VM.

Accident prevention, no saving

The saving is $0. What the flag prevents is losing a VM, and often its boot disk, to one mistaken command. Rebuilding a hand-configured server from memory is the cost it avoids.

Turning deletion protection on

  1. Enable it on a running or stopped VM; Google notes you do not need to stop the instance:

    Terminal window
    gcloud compute instances update VM_NAME --zone=ZONE --deletion-protection
  2. Confirm with the describe command above.

  3. Remember that instance templates cannot carry the setting, so add it to whatever provisioning code creates your standalone VMs.

  4. When a VM really must go, clear it first with --no-deletion-protection, then delete.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·