Cup'n'String
Join Waitlist

© 2026 Cup'n'String

All Guides/AWS Security Groups Guide
AW

AWS Security Groups

Integration & Setup Manual

AWS Security Groups Integration Guide

Overview

Cup’n’String Guard integrates with AWS VPC Security Groups to enforce AI tool network policies at the cloud layer for EC2-hosted developer environments and CI/CD workers. Guard uses the AWS EC2 API to immediately authorize and revoke ingress/egress rules in Guard-tagged security groups — no staging or activation gate is required, and all operations are idempotent.

Support level

Cloud-Native Rules — immediate authorize/revoke with idempotent semantics. Guard owns only rules tagged with its ownership prefix in designated security groups.

Observe to audit current security group rules against the desired AI tool policy baseline, then Enforce to maintain rules automatically.

Known limitations

  • AWS Security Group rules operate at the VPC network layer — per-process enforcement is not available.
  • Security groups apply to ENIs (network interfaces); they do not distinguish between processes on the same instance.
  • For per-process enforcement on EC2 instances, combine with the Cup’n’String native Linux nftables integration.

Setup outline

  1. Confirm the supported platform and deployment requirements with your administrator.
  2. Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
  3. Review policy in your environment before enabling enforcement, then verify the intended access outcomes.

Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.

Integration Info

Support LevelCloud-Native Rules
CategoryFirewalls
Setup ComplexityMedium
Governed Safeguards
Network

Links

Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.

Supported Environments Matrix