services / Google Cloud / Compute Engine managed instances
Create and alter managed instances.
Allows access to general core VM infrastructure, which can support a broad array of organizational functions. Note that the terms "instance" and "VM" are interchangeable within the compute engine documentation, although may have semantic differences within these privileges.
compute.instances.setMinCpuPlatform
Allows reconfiguration of the minimum CPU platform (microarchitecture) the instance can use. The machine must be stopped. Could potentially interrupt services that require features from a specific CPU platform (e.g. a specific number of available threads, vCPUs, or instructions).
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog