Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The dependable way to clone a Compute Engine VM is to create a machine image, then create a new instance from that image. A machine image normally contains the source VM’s boot disk and attached disks, plus most configuration needed to reproduce the instance. For a different Google Cloud project, use the documented snapshot-to-custom-image-to-new-VM sequence instead. A disk clone copies only one disk, while Create similar copies configuration without copying data.

Choose the copy method that matches your goal

Goal Use What is copied
Duplicate a VM in the same project Machine image, then a new instance Boot disk and, by default, attached disks plus most instance information
Move a VM to another project Snapshot boot disk → custom image → destination VM Boot-disk data; configure destination resources and handle other disks separately
Copy one disk for staging, debugging or scanning Disk clone One supported Persistent Disk or Hyperdisk
Back up one disk for disaster recovery Standard snapshot A geo-redundant backup of one disk
Reuse settings without data Create similar VM properties only; no VM or Persistent Disk data

Google Cloud documentation describes a machine image as containing “most of the information and data needed for cloning an instance.” It is the right starting point when the result should behave like the original rather than merely resemble its hardware settings.

Before you clone: identity, disks and compatibility

Prepare operating-system and application identity

Remove information that must be unique on the clone before generating the machine image. This can include host identity, application node IDs, license bindings, certificates and other installation-specific state. Google gives GCESysprep as an example for Windows. The exact cleanup procedure for Linux and applications is workload-specific, so document how each service should be re-identified before bringing both machines online.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inventory every attached disk

Machine images include the boot disk and, by default, all other attached disks. The boot disk cannot be excluded. Selective inclusion or exclusion of non-boot disks is documented as Preview and requires gcloud beta or REST rather than the standard console flow. If a Linux disk is omitted, inspect /etc/fstab; an entry for a disk that will not exist can prevent boot unless it uses the nofail option.

Check unsupported source instances

Some source instances cannot produce machine images, including instances with attached Hyperdisk volumes and several named machine families. Check the current Compute Engine restrictions before starting. For an unsupported VM, an OS image made from the boot disk may be an alternative, but it will not automatically reproduce every attached disk and VM property.

Plan names, zones and regional resources

The destination needs its own instance name, zone, network and subnet choices, service account, metadata, labels, tags and related resources. If the source VM remains in the same project and zone, the new instance cannot use the same name and zone. Moving regions can require overrides for regional resources.

Clone a VM in the same project with a machine image

1. Create the machine image

In the Google Cloud console, open Compute Engine, select Machine images, choose Create machine image, select the source instance and review which attached disks will be included. The equivalent basic command is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
gcloud compute machine-images create MACHINE_IMAGE_NAME 
  --source-instance=SOURCE_INSTANCE_NAME

Replace both names with resources in the intended project. Image creation can take several minutes; do not start dependent automation until the operation reports completion. Google Cloud also documents an operational limit of up to six machine images of a specific instance every 60 minutes.

2. Create the destination instance

In the console, open Machine images, select the image, and choose the flow to create an instance from it. With gcloud:

gcloud compute instances create INSTANCE_NAME 
  --zone=ZONE 
  --source-machine-image=SOURCE_MACHINE_IMAGE_NAME

Choose a zone and name that satisfy the source-instance naming restriction. Then review the generated VM rather than assuming every source setting transferred unchanged.

3. Reconcile properties that are not preserved

Machine images do not preserve every VM or disk property. Examples called out in the Compute Engine documentation include some disk properties, private IPv6 access, resource policies and Shielded VM configuration. Verify:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • VPC network, subnet, internal and external IP behavior, firewall tags and routes.
  • Service account, access scopes, metadata and startup scripts.
  • Disk type, sizing, auto-delete settings, device names and mount points.
  • Regional reservations, resource policies, confidential-computing choices and Shielded VM settings.
  • Application secrets, licenses, hostnames and monitoring-agent identity.

Encryption caveat when using gcloud

If the source machine image uses a customer-managed encryption key (CMEK), gcloud defaults newly created disks to Google-managed encryption unless you explicitly provide disk configuration for every disk and match the source image’s device names. The console’s create-from-image flow behaves differently and automatically inherits the CMEK. Confirm the resulting disk encryption in the destination before placing sensitive workloads on it.

Copy a VM to another Google Cloud project

Cross-project copying is not the same as creating an instance from a machine image in place. Google’s documented workflow starts with the boot disk in the source project, creates a custom image from a snapshot, and then creates the VM in the destination project.

1. Snapshot the source boot disk

Identify whether the boot disk is zonal or regional, then create the corresponding snapshot in the source project. The exact gcloud command uses the snapshot operation for the disk type; do not substitute a regional-disk command for a zonal disk or vice versa. Keep the snapshot in a location and project that the destination workflow can read.

2. Create a custom image from the snapshot

Create the custom image from the completed snapshot, specifying the source project and image name. Wait for the image operation to finish before attempting instance creation. If the source VM has required data disks, repeat the backup or transfer process for those disks; the primary sequence covers the boot disk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Create the destination VM

In the destination project, create an instance whose boot disk uses the custom image. Select a destination zone, VPC network and subnet, service account, metadata, labels and tags deliberately. Attach separately copied data disks and restore their mount configuration. The destination subnet and disk-access permissions must be valid in the destination project; source-project settings do not automatically grant access.

4. Verify IAM before troubleshooting the command

The account creating the destination instance needs permission to create instances and to read the image or snapshot as applicable, along with network and disk permissions. Google documents a predefined Compute Instance Admin (v1) role with the required permission set, but an organization may instead use a narrower custom role or another predefined role. Follow the least-privilege policy approved by your administrator rather than granting broad access by default.

Disk clone, snapshot or machine image?

Disk clones

A disk clone is a ready-to-use copy of one supported Persistent Disk or Hyperdisk. It is useful for a staging environment, debugging, malware scanning or scaling out a workload that resides on one disk. Location and disk-type rules apply, and a CMEK- or CSEK-protected source clone must use the same encryption key. The source VM cannot power on while the clone is being created, so schedule the operation around maintenance and recovery requirements.

Standard snapshots

Google recommends standard snapshots rather than disk clones for disaster recovery. Snapshots are geo-redundant backups of a single disk. For a complete VM or several disks captured together, use a machine image instead.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create similar

The console’s Create similar action is useful when you want to reproduce machine type and other properties manually. It does not copy data from the VM or attached Persistent Disk volumes, so it is not a cloning or backup mechanism.

Validation checklist after the clone boots

  1. Confirm the instance is in the intended project, zone, network and subnet.
  2. List attached disks and compare device names, sizes, types, encryption keys and auto-delete behavior.
  3. Check that expected filesystems mounted and that /etc/fstab contains no missing required device.
  4. Regenerate or verify host identity, SSH keys, certificates, application node IDs and license state.
  5. Test service-account access, Secret Manager access, routes, firewall rules and private service connectivity.
  6. Check monitoring, logging, alerting and backup agents for duplicate identity or conflicting schedules.
  7. Run an application-level health check before directing users or traffic to the clone.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common failures

Machine-image creation is rejected

The source may use an unsupported machine family or attached Hyperdisk, or you may lack permission to read the instance and disks. Check current machine-image restrictions, remove unsupported attachments where appropriate, and verify IAM. If the instance cannot be imaged, consider an OS image from its boot disk and plan separate data-disk copies.

The new VM fails to boot

A missing disk referenced by Linux /etc/fstab, an omitted boot dependency, or a changed device name is a common cause. Compare the machine-image disk selection with the source, use nofail only where it is operationally safe, and inspect serial-console boot output.

Permission denied in a cross-project copy

Grant the creating identity the narrowly scoped instance, image or snapshot, network and disk permissions required by the destination workflow. Also check that the image or snapshot is shared or readable from the destination project according to your organization’s IAM policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The clone has the wrong encryption

When using gcloud, explicitly configure CMEK for every recreated disk and match device names. If you used the console, verify that inherited CMEK is present rather than assuming it from the source.

Clone creation conflicts with location or name rules

Choose a different instance name when the source remains in the same project and zone. For disk clones, review supported source and destination locations and disk types; a clone is not a general cross-zone migration shortcut.

Performance, reliability and cost planning

Image, snapshot and clone operations are asynchronous storage operations. Allow time for completion and avoid starting multiple dependent actions before the preceding operation is ready. Capture during a controlled maintenance window when application consistency matters; a machine image reproduces disk contents, but it does not automatically coordinate in-flight database transactions. Test the resulting VM before deleting the source or its backups.

Keep a written inventory of included disks, encryption keys, IAM grants and destination overrides. For repeated cloning, script names, zones, labels and post-creation checks, while leaving secrets and identity regeneration as explicit steps. Clean up temporary snapshots, images and test instances according to your retention policy so storage and project quotas do not accumulate silently.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

If your workflow also needs a clean visual record of the source or destination web console, ScreenshotNeo provides a single-call website screenshot API. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; failed bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP server lets Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.

For example, this captures a page as WebP:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for options such as full-page capture, CSS-selector elements, device presets, retina scale, PDF output, custom CSS or JavaScript, click and wait actions, request blocking, headers, cookies, user-agent, timezone, geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture and usage reporting.

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots, and every feature is available on every plan. Create a free ScreenshotNeo account.

Frequently Asked Questions

Can I clone a running production VM without shutting it down?

The documented machine-image workflow can create an image from an instance, but application-consistent results depend on the workload. Coordinate database and stateful services with their own quiescing or backup procedures before imaging.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does a machine image preserve the VM’s external IP address?

Do not assume it does. Review and configure destination networking and IP requirements explicitly; addresses and other project resources commonly need their own destination-side setup.

Is a disk clone suitable for moving a VM between regions?

No. Disk clones have disk-type and location constraints and copy one disk only. Use the documented snapshot, image and destination-instance workflow for cross-project or broader migration needs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.