Network Security Groups

aj-geddes/useful-ai-prompts/skills/network-security-groups

by aj-geddes3f5182cfd739No license355 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 7 months ago

Configure network security groups and firewall rules to control inbound/outbound traffic and implement network segmentation.

Includes scriptsSecurityDevOps & Cloud
AI-generated overview

Configures network security groups and firewall rules for traffic control and network segmentation across AWS, GCP and Kubernetes.

What it does
This skill guides the configuration of network security groups and firewall rules to control inbound and outbound traffic and to segment networks. It provides reference guides for AWS security groups, GCP firewall rules, Kubernetes network policies, and a security group management script, plus a quick-start CloudFormation example and a best-practices checklist. It also ships an executable security checklist script.
When to use it
Use it when you need to restrict inbound or outbound traffic, segment networks, or apply least-privilege access controls. It also fits zero-trust networking, DDoS mitigation, database access restriction, VPN access control, and multi-tier application security.
Requirements
Runs scripts: it ships an executable shell script (scripts/security-checklist.sh). Reference material covers AWS, GCP and Kubernetes, so access to those platforms may be needed to apply the configurations.

Network Security Groups

Table of Contents

Overview

Implement network security groups and firewall rules to enforce least privilege access, segment networks, and protect infrastructure from unauthorized access.

When to Use

  • Inbound traffic control
  • Outbound traffic filtering
  • Network segmentation
  • Zero-trust networking
  • DDoS mitigation
  • Database access restriction
  • VPN access control
  • Multi-tier application security

Quick Start

Minimal working example:

yaml
# aws-security-groups.yamlResources:  # VPC Security Group  VPCSecurityGroup:    Type: AWS::EC2::SecurityGroup    Properties:      GroupDescription: VPC security group      VpcId: vpc-12345678      SecurityGroupIngress:        # Allow HTTP from anywhere        - IpProtocol: tcp          FromPort: 80          ToPort: 80          CidrIp: 0.0.0.0/0          Description: "HTTP from anywhere"
        # Allow HTTPS from anywhere        - IpProtocol: tcp          FromPort: 443          ToPort: 443          CidrIp: 0.0.0.0/0          Description: "HTTPS from anywhere"
        # Allow SSH from admin network only        - IpProtocol: tcp// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
AWS Security Groups [blocked]AWS Security Groups
Kubernetes Network Policies [blocked]Kubernetes Network Policies
GCP Firewall Rules [blocked]GCP Firewall Rules
Security Group Management Script [blocked]Security Group Management Script

Best Practices

✅ DO

  • Implement least privilege access
  • Use security groups for segmentation
  • Document rule purposes
  • Regularly audit rules
  • Separate inbound and outbound rules
  • Use security group references
  • Monitor rule changes
  • Test access before enabling

❌ DON'T

  • Allow 0.0.0.0/0 for databases
  • Open all ports unnecessarily
  • Mix environments in single SG
  • Ignore egress rules
  • Allow all protocols
  • Forget to document rules
  • Use single catch-all rule
  • Deploy without firewall

Source and attribution

Source:aj-geddes/useful-ai-promptsinskills/network-security-groupsat commit3f5182c

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal