Skip to main content
This page is the canonical reference for what workload scanning covers. Where an asset can’t be scanned, the reason is listed here, and the same reason appears next to the asset in the Plerion dashboard, so a gap is never silent.

Supported today


Not supported, with reasons

A VM that falls into one of these categories is skipped with the reason above shown against it, never silently dropped from results.
Google-managed projects are excluded from Plerion entirely, not just from workload scanning. See Projects Plerion does not scan.

CMEK-encrypted disks: supported, encryption-stripped

Workload scanning does scan VMs backed by a customer-managed encryption key (CMEK). The snapshot it takes inherits your key, but the scan disk created from that snapshot in the scanning project carries Google-managed encryption instead of your key: Plerion isn’t granted, and doesn’t need, access to decrypt with your CMEK key to create it. This means CMEK-backed VMs get full scan coverage, with one disclosed trade-off: for the short window the scan disk exists, its confidentiality boundary is Google-managed rather than customer-managed. See How scanning works for the full mechanics. Tagging a project PlerionAccess: Denied (see the GCP integration overview) removes Plerion’s own Cloud KMS access to that project. It is a key-access control, not a scanning one: project selection is what decides which projects Plerion scans. To stop scanning a project, exclude it from the organization integration’s project selection under Manage projects.
Excluding a project that is already onboarded deletes its integration and all of the findings and scan history Plerion holds for it. This cannot be undone, and it stops posture scanning as well as workload scanning. Plerion asks you to confirm before doing it. Excluding a project that has not been onboarded yet simply prevents it from ever being added.

Regions

Workload scanning always creates the scan disk and scanner VM in the same region as the source disk. Cross-region scanning never happens. If you’ve limited scanning to specific regions with the workload regions setting, VMs outside those regions are skipped as out of scope, not as a coverage gap; see Managing workload scanning.

What’s next

Cloud Functions, Cloud Run, and MIGs are the next workload types planned. This page will be updated as coverage expands.

Next step