GCE

Compute Engine

gce/BP/2021_001

Serial port logging is enabled.

gce/BP/2022_003

GCE unattached bootable disk.

gce/BP/2023_001

Instance time source is configured with Google NTP server

gce/BP/2024_001

Verify that GCE VM Instances Don’t Have Legacy Monitoring Agent Installed.

gce/BP/2024_002

Verify that GCE VM Instances Don’t Have Legacy Logging Agent Installed.

gce/BP_EXT/2021_003

Secure Boot is enabled

gce/BP_EXT/2022_001

GCP project has VM Manager enabled

gce/BP_EXT/2023_001

Compute Engine scopes best practices

gce/BP_EXT/2024_001

Instance has a public ip address

gce/BP_EXT/2024_002

Calculate GCE VM’s IOPS and Throughput Limits

gce/ERR/2021_001

Managed instance groups are not reporting scaleup failures.

gce/ERR/2021_002

OS Config service account has the required permissions.

gce/ERR/2021_003

Google APIs service agent has the Editor role.

gce/ERR/2021_004

Serial logs don’t contain Secure Boot error messages.

gce/ERR/2021_005

Serial logs don’t contain mount error messages.

gce/ERR/2022_001

Project limits were not exceeded.

gce/ERR/2022_002

Serial logs don’t contain Guest OS activation errors

gce/ERR/2024_001

Snapshot creation not failed due to rate limit.

gce/ERR/2024_002

GCE VM is operating within optimal performance thresholds

gce/ERR/2024_003

GCE Shielded VM secure boot validations

gce/ERR/2024_004

Verify Ops Agent is installed on GCE VMs and is sending logs and metrics.

gce/WARN/2021_001

GCE VM Instance Access Scope, GCE VM Attached Service Account Permissions and APIs Required for Logging.

gce/WARN/2021_002

GCE nodes have good disk performance.

gce/WARN/2021_003

GCE VM Instance Access Scope, GCE VM Attached Service Account Permissions and APIs Required for Monitoring.

gce/WARN/2021_004

Serial logs don’t contain disk full messages

gce/WARN/2021_005

Serial logs don’t contain out-of-memory messages

gce/WARN/2021_006

Serial logs don’t contain “Kernel panic” messages

gce/WARN/2021_007

Serial logs don’t contain “BSOD” messages

gce/WARN/2022_001

GCE connectivity: IAP service can connect to SSH/RDP port on instances.

gce/WARN/2022_002

Instance groups named ports are using unique names.

gce/WARN/2022_003

GCE VM instances quota is not near the limit.

gce/WARN/2022_004

Cloud SQL Docker bridge network should be avoided.

gce/WARN/2022_005

GCE CPU quota is not near the limit.

gce/WARN/2022_006

GCE GPU quota is not near the limit.

gce/WARN/2022_007

Compute Engine VM has the proper scope to connect using the Cloud SQL Admin API

gce/WARN/2022_008

GCE External IP addresses quota is not near the limit.

gce/WARN/2022_009

GCE disk quota is not near the limit.

gce/WARN/2022_010

GCE has enough resources available to fulfill requests

gce/WARN/2022_011

GCE VM service account is valid

gce/WARN/2022_012

PAYG licensed Windows instance can reach KMS to activate

gce/WARN/2023_001

GCE snapshot policies are defined only for used disks

gce/WARN/2023_002

Serial logs don’t contain out-of-memory message due to Airflow task run