Shielded VM provides hardened Compute Engine instances with Secure Boot, vTPM, and integrity monitoring for enhanced security and verifiable boot integrity.
What is Google Cloud Shielded VM?
Shielded VM is a security feature for Compute Engine instances that provides verifiable integrity, so users can be confident their VMs have not been compromised by boot- or kernel-level malware or rootkits. The feature uses three main technologies: Secure Boot verifies the integrity of the bootloader and kernel, a virtual Trusted Platform Module (vTPM) provides secure key storage and Measured Boot, and integrity monitoring detects changes to the boot process.
These features prevent malware from loading during the boot process and enable verification that VMs are running in a trusted state. Shielded VM uses UEFI firmware for a modern, secure boot process. The vTPM stores measurements of each boot component that can be used for attestation.
Shielded VM can be enabled for compatible VM instances. Most Google-provided OS images support the feature. Custom images must be UEFI-compatible. Integrity events can be logged and used for alerts.
Typical Use Cases
Security-Critical Production Workloads
A financial services company enables Shielded VM for production systems. Secure Boot prevents loading tampered bootloaders, and integrity monitoring helps detect boot anomalies early.
Compliance for Regulated Industries
A healthcare company uses Shielded VM for workloads with high compliance requirements. Boot integrity verification supports audit documentation. The vTPM enables secure key storage for encryption applications.
Protection Against Persistent Malware
An e-commerce company protects web servers with Shielded VM. Rootkits that would infect the boot process are blocked by Secure Boot. On suspected compromise, the vTPM provides data for forensic analysis.
Secure Development Environments
A technology company enables Shielded VM for developer workstations in the cloud. Secure Boot prevents loading unsigned drivers, and integrity monitoring detects unauthorized changes.
Benefits
- Verifiable boot integrity without additional infrastructure
- Protection against rootkits and bootkits at the firmware level
- Supports compliance evidence for regulated industries
- Simple activation for compatible VM images
Integration with innFactory
As a certified Google Cloud Partner, innFactory supports you with Shielded VM: activation, image compatibility, integrity monitoring setup, and compliance implementation.
Contact us for a consultation on Shielded VM and Google Cloud security.
Available Tiers & Options
Shielded VM
- Secure Boot
- Integrity monitoring
- vTPM support
- Requires compatible images
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Google Cloud Shielded VM?
Shielded VM is a security feature for Compute Engine instances that provides verifiable integrity. Using Secure Boot, a virtual Trusted Platform Module (vTPM), and integrity monitoring, it helps ensure VMs have not been compromised by boot- or kernel-level malware or rootkits.
Does Shielded VM cost extra?
Shielded VM is built into Compute Engine as a security feature, and typically no separate additional cost applies. For binding pricing details, check the current Compute Engine pricing page.
What is Secure Boot?
Secure Boot verifies that the bootloader and OS kernel are digitally signed and trusted. This prevents loading malware or tampered bootloaders at VM startup.
What does the vTPM do?
The virtual Trusted Platform Module (vTPM) stores cryptographic keys and measurements of the boot process. It enables Measured Boot, attestation, and secure key storage, for example for disk encryption.
How does integrity monitoring work?
Integrity monitoring compares boot measurements against an expected baseline. Deviations are logged, allowing alerts to be configured for potential boot compromise.
Which images support Shielded VM?
Most Google-provided images support Shielded VM. Custom images must be UEFI-compatible for the feature to be enabled.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
