Agentless, cloud-native backup for Google Cloud
Post Reply
pawan.k@infosys.com
Novice
Posts: 4
Liked: 2 times
Joined: Jun 05, 2023 5:53 am
Full Name: Pawan Kumar
Contact:

Worker Instances configuration to suite Infosys GCP organization policies

Post by pawan.k@infosys.com » 2 people like this post

Hi Team,
We have certain Organization policies in place for Creating VMs on GCP
1.VMs can only use Trusted images- Infosys Hardened Images- Any VMs created on should use images from the trusted images (infosys hardened images) only.
2. VMs should have shielded VM option enabled- GCP best practices.

So when worker instance are created without these 2 above mentioned policies, there will be a non compliance which will be triggered in our security dashboard.

So we would like you to give provision to edit worker instance configuration according to our organization best practices.
Gostev
Chief Product Officer
Posts: 31582
Liked: 6729 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Worker Instances configuration to suite Infosys GCP organization policies

Post by Gostev » 1 person likes this post

Hi, Pawan. GCP PM will answer your main question but after reading your post I got curious myself: what Linux distribution do you use as the base for these images?
Alec King
VP, Product Management
Posts: 1447
Liked: 362 times
Joined: Jan 01, 2006 1:01 am
Contact:

Re: Worker Instances configuration to suite Infosys GCP organization policies

Post by Alec King »

Hello Pawan,

The question regarding using your infosys hardened image would be the need to deploy and run the Veeam APIs and other tools required for backup, restore, FLR inside that VM. Without knowing the exact configuration of your hardened image we would not be able to QA test against it, and we could not be sure that our toolkit will work.
On security in general, we do use the LTS build 22.04 of Ubuntu so we have the latest updates and security patches, and we do already have Secure Boot and Block Project-wide SSH Keys enabled by default.

Regarding Shielded VM, it may be possible to deploy our Worker VMs using that option. We will do some investigation and post results here soon.

Thank you for the feedback!
pawan.k@infosys.com
Novice
Posts: 4
Liked: 2 times
Joined: Jun 05, 2023 5:53 am
Full Name: Pawan Kumar
Contact:

Re: Worker Instances configuration to suite Infosys GCP organization policies

Post by pawan.k@infosys.com »

Hi Alec,
Thank you for writing back.

I will get back to you with the hardened images configuration in a while.

Regarding Shielded Vms, can I know by when can we expect an update on this?
Alec King
VP, Product Management
Posts: 1447
Liked: 362 times
Joined: Jan 01, 2006 1:01 am
Contact:

Re: Worker Instances configuration to suite Infosys GCP organization policies

Post by Alec King »

Hi Pawan,
Please feel free to email me directly concerning the hardened images, rather than publish details here in the forum. Just reach out to your local Veeam representative if you don't already have my contact details.
Regarding Shielded VM, we are investigating, and hope to have an update sometime over the next few weeks.
Thanks!
pawan.k@infosys.com
Novice
Posts: 4
Liked: 2 times
Joined: Jun 05, 2023 5:53 am
Full Name: Pawan Kumar
Contact:

Re: Worker Instances configuration to suite Infosys GCP organization policies

Post by pawan.k@infosys.com »

Hi Alec,
Regarding Hardened Images, i spoke to my manager and he was like it can be passed.

Any updated regarding Shielded VMs?.

Thank you.
Alec King
VP, Product Management
Posts: 1447
Liked: 362 times
Joined: Jan 01, 2006 1:01 am
Contact:

Re: Worker Instances configuration to suite Infosys GCP organization policies

Post by Alec King »

Hi Pawan, OK thank you for the update! Regarding Shielded VMs, we continue to research whether this can be included to a future version. Will update here ASAP.
Thanks!
pawan.k@infosys.com
Novice
Posts: 4
Liked: 2 times
Joined: Jun 05, 2023 5:53 am
Full Name: Pawan Kumar
Contact:

Re: Worker Instances configuration to suite Infosys GCP organization policies

Post by pawan.k@infosys.com »

HI Alec,
Any updates on this?? and can you keep Prasanna (Prasanna.Keshava@veeam.com) in loop for this issue.
And can we get a fast update on this cause our security posture is not looking good as there are a lot of triggers regarding Shielded VMs.

Regards,
Pawan Kumar K
Alec King
VP, Product Management
Posts: 1447
Liked: 362 times
Joined: Jan 01, 2006 1:01 am
Contact:

Re: Worker Instances configuration to suite Infosys GCP organization policies

Post by Alec King »

Hello Pawan, We are currently testing all Shielded VM options for Veeam Workers. If the testing does not reveal any issues then I hope we will include this in the next version.
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest