MEDIUM
Source
Trivy
ID
AVD-GCP-0041

Instances should have Shielded VM VTPM enabled

The virtual TPM provides numerous security measures to your VM.

Impact

Unable to prevent unwanted system state modification

Follow the appropriate remediation steps below to resolve the issue.

Enable Shielded VM VTPM

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
 resource "google_compute_instance" "good_example" {
   name         = "test"
   machine_type = "e2-medium"
   zone         = "us-central1-a"
 
   tags = ["foo", "bar"]
 
   boot_disk {
     initialize_params {
       image = "debian-cloud/debian-9"
     }
   }
 
   // Local SSD disk
   scratch_disk {
     interface = "SCSI"
   }
 
   shielded_instance_config {
     enable_vtpm = true
   }
 }