services / Google Cloud / Compute Engine instance groups
Create and alter (unmanaged) instance groups.
Allows creation, modification, and destruction of manually managed instance groups. Generally requires exercise of multiple risks to exploit.
compute.instanceGroups.use
No known or documented application; may be necessary to assign the group to a load balancer.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog