VMware Engine shared responsibility model

This page describes what you, as a Google Cloud VMware Engine customer, are responsible for and what Google is responsible for.

Introduction

Trusted security in Google Cloud is achieved through the shared responsibilities of customers and Google as a service provider. This model is intended to provide higher security and eliminate single points of failure. The following sections list the responsibilities by role.

Shared responsibility matrix

The following table describes the shared responsibility matrix, detailing the activities managed by Google and the customer:

Activity Responsibility Comments
Monitoring and alerting
VM OS and applications (infrastructure) Google Google monitors the health and availability of VM infrastructure.
VM OS and applications (performance) Customer The customer is responsible for providing VMware expertise and following VMware performance guidelines.
vSAN Google Google monitors the health and availability of vSAN storage.
Network overlay Google Google monitors the health of NSX infrastructure devices (Edge Gateway devices, Controllers) and the underlying networking of the infrastructure (underlay) provided through physical VLANs.
NSX Customer The customer can self-manage their overlay networking through NSX. All features of NSX are available and are monitored/managed by the customer. The customer can configure firewall rules, public IP addresses, and VPC peering of the underlay.
VPN/Site-to-Site IPsec (service health) Google Google provides VPN as a service using Cloud VPN and monitors the health of the VPN devices.
VPN/Site-to-Site IPsec (VPN devices on-premises and in NSX) Customer The customer must monitor on-premises devices and can also self-manage and monitor VPN devices in NSX.
ESXi hosts Google If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support.
Security and network devices Google Google Cloud and the VMware platform provide default VPN, gateway, and firewall capabilities. Google manages the health of these devices, and the customer manages any customer-specific tools.
HCX Google Google monitors the health and availability of the default HCX deployment.
Support
VM OS and applications Customer The customer is responsible for any OS or application support.
vSAN Google If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support.
Network overlay Google Google provides support for overlay networking.
ESXi hosts - hardware Google If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support, including host replacement.
ESXi hosts - default software Google Google manages software deployed on the node by default.
ESXi hosts - customer-deployed software Customer The customer is responsible for any software they deploy with elevated privileges (for example, Zerto).
Security and network devices Google If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support.
NSX Google If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support.
VPN/Site-to-Site IPsec (service health) Google Google provides VPN as a service via Cloud VPN.
VPN/Site-to-Site IPsec (VPN devices on-premises) Customer Google provides VPN as a service via Cloud VPN. The customer must support on-premises devices.
ISV software support Customer The customer must confirm support with independent software vendors (ISVs) before deploying specific software to the private cloud.
Identity management
Implementation Customer The customer can integrate on-premises ID sources with the Google Cloud console and with vCenter.
Configuration and management Customer The customer manages and configures identity sources, including vCenter and NSX user management (identity, access control).
Installation and provisioning
Private clouds (deployment) Customer The customer triggers the deployment of private clouds via the console, API, or CLI.
ESXi hosts Google Google installs and provisions ESXi hosts.
vSAN Google Google installs and provisions vSAN.
vCenter Google Google deploys and performs the basic configuration of vCenter.
Aria Suite Lifecycle Manager (LCM) Google Google deploys and performs the basic configuration of Aria Suite Lifecycle Manager (LCM).
Aria Suite Customer The customer is responsible for installing and provisioning the Aria Suite, which includes VMware Aria Operations, VMware Aria Operations for Networks, VMware Aria Operations for Logs, VMware Aria Automation, and VMware Identity Manager.
OS and applications Customer The customer installs and provisions operating systems and applications.
Databases Customer The customer installs and provisions databases.
Security and network devices Google Google Cloud and the VMware platform provide default VPN, gateway, and firewall capabilities. The customer manages any customer-specific tools.
NSX Google Google deploys and performs the basic configuration of NSX.
VPN/Site-to-Site IPsec Customer The customer must provision Cloud VPN in their Google Cloud project.
HCX (initial deployment) Google Google deploys and performs the basic configuration of HCX.
Workload migration Customer The customer is responsible for migrating VMs and workloads to the private cloud, and managing migration tools (such as HCX).