iTnews
  • Home
  • News
  • Technology
  • Cloud

UniSuper's Google cloud deletion traced to "blank parameter" in setup

By Ry Crozier
May 25 2024 12:10PM

Caused the environment to expire.

UniSuper’s Google private cloud environment was deleted because a single parameter in a software tool was left blank, inadvertently placing a one-year expiry on the environment.

UniSuper's Google cloud deletion traced to "blank parameter" in setup

The cloud provider on Saturday finally explained the “rare” and cascading series of events that led to UniSuper’s online services being inaccessible for nine days and having to be rebuilt from backups.

The previous best explanation of the incident was “an inadvertent misconfiguration during the provisioning of UniSuper’s private cloud, which triggered a previously unknown software bug.”

The cloud provider has now published a post-incident report to “publicly clarify the nature of the incident and ensure there is an accurate account in the interest of transparency”.

iTnews previously reported that other customers had been seeking explanations of the incident to understand their own potential exposure. The incident also occurred a week prior to a major but closed-door Google Cloud summit in Sydney attended by customers.

The official post-mortem came days after a widely shared LinkedIn post that appeared to leak aspects of the findings.

'One input parameter was left blank'

Google Cloud said that the incident was isolated to one Google Cloud VMware Engine (GCVE) private cloud run by UniSuper across two zones. It said UniSuper had more than one private cloud.

Owing to specific provisioning requirements, the setup was performed by Google Cloud engineers themselves using an internal tool that's no longer in use.

While saying that Google operators “followed internal control protocols”, the provider said that “one input parameter was left blank when using [the] internal tool to provision the customer’s private cloud.”

“As a result of the blank parameter, the system assigned a then unknown default fixed one-year term value for this parameter,” it said.

“After the end of the system-assigned one year period, the customer’s GCVE private cloud was deleted.”

Google said that UniSuper would have received no warning of the deletion because they didn’t ask for it to happen.

“No customer notification was sent because the deletion was triggered as a result of a parameter being left blank by Google operators using the internal tool, and not due a customer deletion request,” Google said.

“Any customer-initiated deletion would have been preceded by a notification to the customer.”

The recovery and rebuild of the deleted environment were made possible because UniSuper had a “robust and resilient architectural approach to managing risk of outage or failure” on its end, including the use of “third party backup software”.

“The customer’s CIO and technical teams deserve praise for the speed and precision with which they executed the 24x7 recovery, working closely with Google Cloud teams,” it said.

Google said additional backups it made for UniSuper were also accessible.

It said the same incident is no longer possible, in part because customers can now do the more complex configurations themselves - which would trigger warnings if an environment was ever up for deletion.

Google said it also “manually reviewed all GCVE private clouds to ensure that no other GCVE deployments are at risk” of the same set of circumstances.

Google added that it was a “one-time incident” and that its resiliency and stability credentials remained intact.

UniSuper set up GCVE private clouds to replace two data centres it previously ran in Melbourne.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cloudgooglegoogle cloudunisuper

Related Articles

  • Computershare migrates 24,000 VMs onto Nutanix Computershare migrates 24,000 VMs onto Nutanix
  • Western Sydney Uni discloses January "IT network" breach Western Sydney Uni discloses January "IT network" breach
  • Australian Federal Police uses cloud, SASE to upgrade reach and capability Australian Federal Police uses cloud, SASE to upgrade reach and capability
  • Macquarie Uni to spend up to $700m on 10-year digital transformation Macquarie Uni to spend up to $700m on 10-year digital transformation

Partner Content

Securing the Future: Identity Takes Centre Stage in Business Operations
Partner Content Securing the Future: Identity Takes Centre Stage in Business Operations
Robot rise lifts safety for Kiwi crane company
Partner Content Robot rise lifts safety for Kiwi crane company
Focus on three pillars to succeed in cyber security: Interactive
Partner Content Focus on three pillars to succeed in cyber security: Interactive
Why you should use the cloud to secure your cloud
Partner Content Why you should use the cloud to secure your cloud

Sponsored Whitepapers

Gain an independent witness with body-worn cameras
Gain an independent witness with body-worn cameras
Gain an independent witness with body-worn cameras
Gain an independent witness with body-worn cameras
Trust Imperative 4.0
Trust Imperative 4.0
Centralized Remote Connectivity for State & Local Government
Centralized Remote Connectivity for State & Local Government
Global Employee Experience Trends Report
Global Employee Experience Trends Report
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Macquarie Uni to spend up to $700m on 10-year digital transformation

Macquarie Uni to spend up to $700m on 10-year digital transformation

UniSuper's Google cloud deletion traced to "blank parameter" in setup

UniSuper's Google cloud deletion traced to "blank parameter" in setup

Australian Federal Police uses cloud, SASE to upgrade reach and capability

Australian Federal Police uses cloud, SASE to upgrade reach and capability

Western Sydney Uni discloses January "IT network" breach

Western Sydney Uni discloses January "IT network" breach

Digital Nation

COVER STORY: What AI regulation might look like in Australia
COVER STORY: What AI regulation might look like in Australia
More than half of loyalty members concerned about their data
More than half of loyalty members concerned about their data
State of Security 2023
State of Security 2023
How eBay uses interaction analytics to improve CX
How eBay uses interaction analytics to improve CX
Health tech startup Kismet raises $4m in pre-seed funding
Health tech startup Kismet raises $4m in pre-seed funding
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.