AWS安全组规则新增描述后,如何批量修改不同组内同描述规则?
Great question—this is a common pain point since AWS added rule descriptions back in late August 2017. While that description field made identifying and searching rules way easier, the AWS Management Console still doesn’t let you bulk-edit rules across different security groups based on their description. For example, if you’ve got rules tagged "NY Office" spread across multiple groups that allow access from a specific IP, updating that IP without hunting down each group manually is impossible via the UI.
Solution: Automate with AWS CLI or SDKs
The workaround here is to use AWS’s command-line tools or SDKs to target all matching rules in one go. Here’s how to do it step-by-step:
First, identify all matching rules
Use the AWS CLI to list every security group and rule that has the "NY Office" description:aws ec2 describe-security-groups --filters Name="description",Values="NY Office" --query 'SecurityGroups[*].[GroupId, IpPermissions[?Description==`NY Office`]]'This will output a JSON list of security group IDs and the specific rules you need to update.
Bulk-update with a shell script
Wrap the CLI commands in a script to automatically revoke the old IP rule and authorize the new one for all matching entries. You’ll needjqinstalled to parse the JSON output:# Define your old/new IP and target description OLD_IP="192.168.1.0/24" NEW_IP="10.0.0.0/24" TARGET_DESCRIPTION="NY Office" # Fetch all relevant security groups and rules SG_DATA=$(aws ec2 describe-security-groups --filters Name="description",Values="$TARGET_DESCRIPTION" --query 'SecurityGroups[*].[GroupId, IpPermissions[?Description==`'"$TARGET_DESCRIPTION"'`]]' --output json) # Loop through each security group and rule echo "$SG_DATA" | jq -c '.[]' | while read -r SG_ENTRY; do SG_ID=$(echo "$SG_ENTRY" | jq -r '.[0]') RULES=$(echo "$SG_ENTRY" | jq -c '.[1][]') echo "Updating security group: $SG_ID" echo "$RULES" | while read -r RULE; do FROM_PORT=$(echo "$RULE" | jq -r '.FromPort') TO_PORT=$(echo "$RULE" | jq -r '.ToPort') PROTOCOL=$(echo "$RULE" | jq -r '.IpProtocol') # Remove the old rule aws ec2 revoke-security-group-ingress --group-id "$SG_ID" --protocol "$PROTOCOL" --port "$FROM_PORT-$TO_PORT" --cidr "$OLD_IP" # Add the new rule with the same description aws ec2 authorize-security-group-ingress --group-id "$SG_ID" --protocol "$PROTOCOL" --port "$FROM_PORT-$TO_PORT" --cidr "$NEW_IP" --description "$TARGET_DESCRIPTION" echo "Updated rule: $FROM_PORT-$TO_PORT/$PROTOCOL | $OLD_IP → $NEW_IP" done donePro tip: Test this script in a non-production environment first to avoid accidental changes!
Use Python’s Boto3 SDK for more control
If you prefer Python, the Boto3 SDK gives you more flexibility to handle edge cases (like egress rules or non-CIDR sources). Here’s a quick snippet:import boto3 ec2_client = boto3.client('ec2') old_ip = "192.168.1.0/24" new_ip = "10.0.0.0/24" target_description = "NY Office" # Get all security groups with matching rules response = ec2_client.describe_security_groups( Filters=[{'Name': 'description', 'Values': [target_description]}] ) for sg in response['SecurityGroups']: sg_id = sg['GroupId'] print(f"Processing security group: {sg_id}") for permission in sg['IpPermissions']: if permission.get('Description') == target_description: # Extract rule details from_port = permission['FromPort'] to_port = permission['ToPort'] protocol = permission['IpProtocol'] # Revoke old rule ec2_client.revoke_security_group_ingress( GroupId=sg_id, IpPermissions=[{ 'FromPort': from_port, 'ToPort': to_port, 'IpProtocol': protocol, 'IpRanges': [{'CidrIp': old_ip}] }] ) # Authorize new rule ec2_client.authorize_security_group_ingress( GroupId=sg_id, IpPermissions=[{ 'FromPort': from_port, 'ToPort': to_port, 'IpProtocol': protocol, 'IpRanges': [{'CidrIp': new_ip, 'Description': target_description}] }] ) print(f"Updated rule: {from_port}-{to_port}/{protocol} | {old_ip} → {new_ip}")
Important Notes
- Ensure your IAM user/role has permissions for
ec2:DescribeSecurityGroups,ec2:RevokeSecurityGroupIngress, andec2:AuthorizeSecurityGroupIngress. - For egress rules, swap the
Ingresscommands withEgress(e.g.,revoke-security-group-egress). - Always validate the output of the initial
describe-security-groupscommand to make sure you’re targeting the right rules before running the full update.
内容的提问来源于stack exchange,提问作者Yaron

