You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS安全组规则新增描述后,如何批量修改不同组内同描述规则?

AWS Security Group Rule Bulk Updates by Description

Great question—this is a common pain point since AWS added rule descriptions back in late August 2017. While that description field made identifying and searching rules way easier, the AWS Management Console still doesn’t let you bulk-edit rules across different security groups based on their description. For example, if you’ve got rules tagged "NY Office" spread across multiple groups that allow access from a specific IP, updating that IP without hunting down each group manually is impossible via the UI.

Solution: Automate with AWS CLI or SDKs

The workaround here is to use AWS’s command-line tools or SDKs to target all matching rules in one go. Here’s how to do it step-by-step:

  1. First, identify all matching rules
    Use the AWS CLI to list every security group and rule that has the "NY Office" description:

    aws ec2 describe-security-groups --filters Name="description",Values="NY Office" --query 'SecurityGroups[*].[GroupId, IpPermissions[?Description==`NY Office`]]'
    

    This will output a JSON list of security group IDs and the specific rules you need to update.

  2. Bulk-update with a shell script
    Wrap the CLI commands in a script to automatically revoke the old IP rule and authorize the new one for all matching entries. You’ll need jq installed to parse the JSON output:

    # Define your old/new IP and target description
    OLD_IP="192.168.1.0/24"
    NEW_IP="10.0.0.0/24"
    TARGET_DESCRIPTION="NY Office"
    
    # Fetch all relevant security groups and rules
    SG_DATA=$(aws ec2 describe-security-groups --filters Name="description",Values="$TARGET_DESCRIPTION" --query 'SecurityGroups[*].[GroupId, IpPermissions[?Description==`'"$TARGET_DESCRIPTION"'`]]' --output json)
    
    # Loop through each security group and rule
    echo "$SG_DATA" | jq -c '.[]' | while read -r SG_ENTRY; do
        SG_ID=$(echo "$SG_ENTRY" | jq -r '.[0]')
        RULES=$(echo "$SG_ENTRY" | jq -c '.[1][]')
        
        echo "Updating security group: $SG_ID"
        echo "$RULES" | while read -r RULE; do
            FROM_PORT=$(echo "$RULE" | jq -r '.FromPort')
            TO_PORT=$(echo "$RULE" | jq -r '.ToPort')
            PROTOCOL=$(echo "$RULE" | jq -r '.IpProtocol')
            
            # Remove the old rule
            aws ec2 revoke-security-group-ingress --group-id "$SG_ID" --protocol "$PROTOCOL" --port "$FROM_PORT-$TO_PORT" --cidr "$OLD_IP"
            
            # Add the new rule with the same description
            aws ec2 authorize-security-group-ingress --group-id "$SG_ID" --protocol "$PROTOCOL" --port "$FROM_PORT-$TO_PORT" --cidr "$NEW_IP" --description "$TARGET_DESCRIPTION"
            
            echo "Updated rule: $FROM_PORT-$TO_PORT/$PROTOCOL | $OLD_IP → $NEW_IP"
        done
    done
    

    Pro tip: Test this script in a non-production environment first to avoid accidental changes!

  3. Use Python’s Boto3 SDK for more control
    If you prefer Python, the Boto3 SDK gives you more flexibility to handle edge cases (like egress rules or non-CIDR sources). Here’s a quick snippet:

    import boto3
    
    ec2_client = boto3.client('ec2')
    
    old_ip = "192.168.1.0/24"
    new_ip = "10.0.0.0/24"
    target_description = "NY Office"
    
    # Get all security groups with matching rules
    response = ec2_client.describe_security_groups(
        Filters=[{'Name': 'description', 'Values': [target_description]}]
    )
    
    for sg in response['SecurityGroups']:
        sg_id = sg['GroupId']
        print(f"Processing security group: {sg_id}")
        
        for permission in sg['IpPermissions']:
            if permission.get('Description') == target_description:
                # Extract rule details
                from_port = permission['FromPort']
                to_port = permission['ToPort']
                protocol = permission['IpProtocol']
                
                # Revoke old rule
                ec2_client.revoke_security_group_ingress(
                    GroupId=sg_id,
                    IpPermissions=[{
                        'FromPort': from_port,
                        'ToPort': to_port,
                        'IpProtocol': protocol,
                        'IpRanges': [{'CidrIp': old_ip}]
                    }]
                )
                
                # Authorize new rule
                ec2_client.authorize_security_group_ingress(
                    GroupId=sg_id,
                    IpPermissions=[{
                        'FromPort': from_port,
                        'ToPort': to_port,
                        'IpProtocol': protocol,
                        'IpRanges': [{'CidrIp': new_ip, 'Description': target_description}]
                    }]
                )
                
                print(f"Updated rule: {from_port}-{to_port}/{protocol} | {old_ip} → {new_ip}")
    

Important Notes

  • Ensure your IAM user/role has permissions for ec2:DescribeSecurityGroups, ec2:RevokeSecurityGroupIngress, and ec2:AuthorizeSecurityGroupIngress.
  • For egress rules, swap the Ingress commands with Egress (e.g., revoke-security-group-egress).
  • Always validate the output of the initial describe-security-groups command to make sure you’re targeting the right rules before running the full update.

内容的提问来源于stack exchange,提问作者Yaron

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:34:58