VMware Engine shared responsibility model
This page describes what you, as a Google Cloud VMware Engine customer, are responsible for and what Google is responsible for.
Introduction
Trusted security in Google Cloud is achieved through the shared responsibilities of customers and Google as a service provider. This model is intended to provide higher security and eliminate single points of failure. The following sections list the responsibilities by role.
Shared responsibility matrix
The following table describes the shared responsibility matrix, detailing the activities managed by Google and the customer:
| Activity | Responsibility | Comments |
|---|---|---|
| Monitoring and alerting | ||
| VM OS and applications (infrastructure) | Google monitors the health and availability of VM infrastructure. | |
| VM OS and applications (performance) | Customer | The customer is responsible for providing VMware expertise and following VMware performance guidelines. |
| vSAN | Google monitors the health and availability of vSAN storage. | |
| Network overlay | Google monitors the health of NSX infrastructure devices (Edge Gateway devices, Controllers) and the underlying networking of the infrastructure (underlay) provided through physical VLANs. | |
| NSX | Customer | The customer can self-manage their overlay networking through NSX. All features of NSX are available and are monitored/managed by the customer. The customer can configure firewall rules, public IP addresses, and VPC peering of the underlay. |
| VPN/Site-to-Site IPsec (service health) | Google provides VPN as a service using Cloud VPN and monitors the health of the VPN devices. | |
| VPN/Site-to-Site IPsec (VPN devices on-premises and in NSX) | Customer | The customer must monitor on-premises devices and can also self-manage and monitor VPN devices in NSX. |
| ESXi hosts | If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support. | |
| Security and network devices | Google Cloud and the VMware platform provide default VPN, gateway, and firewall capabilities. Google manages the health of these devices, and the customer manages any customer-specific tools. | |
| HCX | Google monitors the health and availability of the default HCX deployment. | |
| Support | ||
| VM OS and applications | Customer | The customer is responsible for any OS or application support. |
| vSAN | If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support. | |
| Network overlay | Google provides support for overlay networking. | |
| ESXi hosts - hardware | If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support, including host replacement. | |
| ESXi hosts - default software | Google manages software deployed on the node by default. | |
| ESXi hosts - customer-deployed software | Customer | The customer is responsible for any software they deploy with elevated privileges (for example, Zerto). |
| Security and network devices | If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support. | |
| NSX | If a VMware platform (ESXi, vCenter, vSAN, NSX) or infrastructure hardware support need is identified, Google provides support. | |
| VPN/Site-to-Site IPsec (service health) | Google provides VPN as a service via Cloud VPN. | |
| VPN/Site-to-Site IPsec (VPN devices on-premises) | Customer | Google provides VPN as a service via Cloud VPN. The customer must support on-premises devices. |
| ISV software support | Customer | The customer must confirm support with independent software vendors (ISVs) before deploying specific software to the private cloud. |
| Identity management | ||
| Implementation | Customer | The customer can integrate on-premises ID sources with the Google Cloud console and with vCenter. |
| Configuration and management | Customer | The customer manages and configures identity sources, including vCenter and NSX user management (identity, access control). |
| Installation and provisioning | ||
| Private clouds (deployment) | Customer | The customer triggers the deployment of private clouds via the console, API, or CLI. |
| ESXi hosts | Google installs and provisions ESXi hosts. | |
| vSAN | Google installs and provisions vSAN. | |
| vCenter | Google deploys and performs the basic configuration of vCenter. | |
| Aria Suite Lifecycle Manager (LCM) | Google deploys and performs the basic configuration of Aria Suite Lifecycle Manager (LCM). | |
| Aria Suite | Customer | The customer is responsible for installing and provisioning the Aria Suite, which includes VMware Aria Operations, VMware Aria Operations for Networks, VMware Aria Operations for Logs, VMware Aria Automation, and VMware Identity Manager. |
| OS and applications | Customer | The customer installs and provisions operating systems and applications. |
| Databases | Customer | The customer installs and provisions databases. |
| Security and network devices | Google Cloud and the VMware platform provide default VPN, gateway, and firewall capabilities. The customer manages any customer-specific tools. | |
| NSX | Google deploys and performs the basic configuration of NSX. | |
| VPN/Site-to-Site IPsec | Customer | The customer must provision Cloud VPN in their Google Cloud project. |
| HCX (initial deployment) | Google deploys and performs the basic configuration of HCX. | |
| Workload migration | Customer | The customer is responsible for migrating VMs and workloads to the private cloud, and managing migration tools (such as HCX). |