Working with multiple clients with their own AWS setups and security groups makes it difficult to work remotely sometimes. For instance, updating the many security groups with my current (dynamic) IP address so I can SSH into the server. To solve this problem, I created a shell script to manage the situation.
aws ec2 command line tool, you can issue a set of commands to query, delete and add IP rules to the firewall. The script below allows you to:
- Select a AWS profile to use (setup using the
- Specify one or more security groups to edit (under the same profile)
- Any fixed IP addresses that should remain constant
- The tcp port for the IP rules
Running the Script
Give the appropriate execute permissions to the script, e.g.
chmod 755 aws-security.sh, then call the script using
Please note the following before running the script:
- All existing rules matching the protocol (tcp) and
portwill be deleted by running this script. Please make sure any required IP addresses are added to
- The script will add your current IP address by default. If this already exists in
fixed_ips, a error will be thrown by the aws tool.