services / Google Cloud / Compute Engine managed instances
Create and alter managed instances.
Allows access to general core VM infrastructure, which can support a broad array of organizational functions. Note that the terms "instance" and "VM" are interchangeable within the compute engine documentation, although may have semantic differences within these privileges.
compute.instances.addResourcePolicies
Requires an existing resource policy and `compute.resourcePolicies.use` or `compute.resourcePolicies.useReadOnly` on the policy. Resource policies can automatically start or stop instances.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog