Skip to content

Google Cloud

Deploy the Sophos Remote Testing Appliance (RTA) as a virtual machine in your own Google Cloud project. We publish the appliance as a custom Compute Engine image in a Sophos-owned project and grant your Google account or project IAM access to launch VMs from it directly, with no image copy or download required.

How delivery works on Google Cloud

Your engagement lead provides:

Item What it is
Source project The Sophos-owned project that hosts the image: the --image-project value.
Image name The name of the custom Compute Engine image, e.g. rta-generic-20250601.
Google identity to share with Your Google account email, a Google Group, or your GCP project's service account: whichever you provide us so we can grant access.

Once we grant access, you launch a VM directly from our image. There is nothing to copy or upload. The image is generic: it has no engagement identity baked in, so on first boot the appliance comes up in activation mode and its console shows an Appliance Registration screen with a one-time activation code. Read the code from the serial console (you must enable the display device; see below) and give it to your Sophos engagement lead to activate the appliance. Once activated, it provisions itself, brings up the outbound VPN tunnel, and the console switches to the live status dashboard.

Enable the display device: it is off by default

GCP does not enable the virtual display device on new VMs unless you explicitly request it. Without it the RTA console is inaccessible. Check the Enable display device checkbox (Console) or pass --enable-display-device (CLI) every time you create an RTA instance.

The image project is outside your organization

The image project is Sophos-owned, not part of your GCP organization. The Console's source project picker defaults to your organization only, so you must switch the organization filter to "No organization" or "All" before searching for the project name your engagement lead provided. The CLI flag --image-project=IMAGE_PROJECT works without any extra steps.

Requirements

Resource Minimum Recommended
Machine type 2 vCPU / 8 GB (e2-standard-2) e2-standard-4 (4 vCPU / 16 GB)
Boot disk 40 GB 40 GB
Networking Outbound internet; no public IP / no inbound rules required VPC subnet with VPN reach to engagement targets
Display device Required (enable explicitly) Required

Choose a deployment method

  • GUI (Cloud Console)

    Point-and-click: create a VM instance in the Compute Engine console, selecting our shared image as the boot disk source.

  • CLI (gcloud)

    One gcloud compute instances create command. The fastest path: no console navigation, no org-picker workaround needed.

  • AI assistant (LLM)

    A copy-paste prompt that has your AI assistant drive the gcloud CLI deployment, pausing for your confirmation at each step.