gce/BP/2021_001
Serial port logging is enabled.
Serial port logging is enabled.
GCE unattached bootable disk.
Instance time source is configured with Google NTP server
Verify that GCE VM Instances Don’t Have Legacy Monitoring Agent Installed.
Verify that GCE VM Instances Don’t Have Legacy Logging Agent Installed.
Secure Boot is enabled
GCP project has VM Manager enabled
Compute Engine scopes best practices
Instance has a public ip address
Calculate GCE VM’s IOPS and Throughput Limits
Managed instance groups are not reporting scaleup failures.
OS Config service account has the required permissions.
Google APIs service agent has the Editor role.
Serial logs don’t contain Secure Boot error messages.
Serial logs don’t contain mount error messages.
Project limits were not exceeded.
Serial logs don’t contain Guest OS activation errors
Snapshot creation not failed due to rate limit.
GCE VM is operating within optimal performance thresholds
GCE Shielded VM secure boot validations
Verify Ops Agent is installed on GCE VMs and is sending logs and metrics.
GCE VM Instance Access Scope, GCE VM Attached Service Account Permissions and APIs Required for Logging.
GCE nodes have good disk performance.
GCE VM Instance Access Scope, GCE VM Attached Service Account Permissions and APIs Required for Monitoring.
Serial logs don’t contain disk full messages
Serial logs don’t contain out-of-memory messages
Serial logs don’t contain “Kernel panic” messages
Serial logs don’t contain “BSOD” messages
GCE connectivity: IAP service can connect to SSH/RDP port on instances.
Instance groups named ports are using unique names.
GCE VM instances quota is not near the limit.
Cloud SQL Docker bridge network should be avoided.
GCE CPU quota is not near the limit.
GCE GPU quota is not near the limit.
Compute Engine VM has the proper scope to connect using the Cloud SQL Admin API
GCE External IP addresses quota is not near the limit.
GCE disk quota is not near the limit.
GCE has enough resources available to fulfill requests
GCE VM service account is valid
PAYG licensed Windows instance can reach KMS to activate
GCE snapshot policies are defined only for used disks
Serial logs don’t contain out-of-memory message due to Airflow task run