AWS Security Groups
Integration & Setup Manual
AWS Security Groups Integration Guide
Overview
Cup’n’String Guard integrates with AWS VPC Security Groups to enforce AI tool network policies at the cloud layer for EC2-hosted developer environments and CI/CD workers. Guard uses the AWS EC2 API to immediately authorize and revoke ingress/egress rules in Guard-tagged security groups — no staging or activation gate is required, and all operations are idempotent.
Support level
Cloud-Native Rules — immediate authorize/revoke with idempotent semantics. Guard owns only rules tagged with its ownership prefix in designated security groups.
Recommended Guard mode
Observe to audit current security group rules against the desired AI tool policy baseline, then Enforce to maintain rules automatically.
Known limitations
- AWS Security Group rules operate at the VPC network layer — per-process enforcement is not available.
- Security groups apply to ENIs (network interfaces); they do not distinguish between processes on the same instance.
- For per-process enforcement on EC2 instances, combine with the Cup’n’String native Linux nftables integration.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix