Skip to main content
compliance · gcp

Compute Engine VMs with the interactive serial console switched on

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

Compute Engine VMs are flagged when the instance's own metadata sets `serial-port-enable` to `TRUE`. Google warns that the interactive serial console accepts connections from any IP address and does not honour IP allowlists unless VPC Service Controls is in place, so firewall rules that lock down SSH do nothing for this path.

Signal and threshold

How ZopNight evaluates Compute Engine VMs with the interactive serial console switched on.
Field Value
Rule IDsRC-1204
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdinstance metadata serial-port-enable is TRUE
SourceZopNight
Permissions usedcompute.instances.list · compute.instances.get

Why the serial console sidesteps your firewall

The interactive serial console exists for rescue work on a VM that will not boot far enough to accept SSH. It is reached through a Google endpoint, ssh-serialport.googleapis.com on TCP port 9600, not through the VM’s network interface. Google’s serial console guide puts the consequence plainly: the console does not support IP-based restrictions such as allowlists unless you use VPC Service Controls, and clients can attempt to connect from any IP address. Anyone with the right SSH key, username, project ID, zone and instance name gets a console session.

So a VM with no external IP and a tight firewall can still be reachable. That is why the rule carries high severity even though nothing about it costs money.

Checking the metadata yourself

The per-instance item is what this rule reads. Look for serial-port-enable in the output:

Terminal window
gcloud compute instances describe VM_NAME --zone=ZONE \
--format="value(metadata.items)"

Project metadata can switch the console on for every VM too, and a per-instance value overrides the project value either way:

Terminal window
gcloud compute project-info describe \
--format="value(commonInstanceMetadata.items)"

When a finding is raised

ZopNight records the instance-level serial-port-enable value during inventory and fires only when it is exactly true. There is no time window: a console left on for one day is flagged the same as one left on for a year.

Cases this check does not flag

A VM with the item set to false, or with no item at all, is silent. Because only the instance value is read, a VM that gets the console solely from project-wide metadata is not flagged here, so review the project setting separately with the command above.

High severity, zero saving

No cost is attached. The risk is an interactive login path that bypasses network controls and is easy to forget once the debugging session that needed it is over.

Closing the console

  1. Turn it off on the instance: gcloud compute instances add-metadata VM_NAME --zone=ZONE --metadata serial-port-enable=FALSE.
  2. Check project metadata and set the same key to FALSE there if it is on.
  3. Enforce it with the compute.disableSerialPortAccess organization policy constraint so nobody can re-enable it casually.
  4. For routine shell access to private VMs, use IAP TCP forwarding instead.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·