Automated Tencent Cloud Security Group Audit
Every Monday, WebRun signs in to Tencent Cloud, walks each security group and its inbound rules, finds the rules open to any source address, matches them to the CVM instances and VPCs they protect, writes the audit into Notion, and texts you through Twilio when a sensitive port is exposed.
How do I find Tencent Cloud security groups left open to the internet?
Every Monday WebRun signs in to Tencent Cloud, reads every security group and its inbound rules, and finds the ones open to the whole internet on sensitive ports. It writes the audit into Notion with the CVM instances behind each rule and texts you via Twilio when exposure is critical.
- A port opened for a quick test is caught within the week
- Every open rule is tied to the instances it exposes
- Sensitive ports raise a text, everything else waits in the audit
Built for infrastructure engineers · DevOps teams · cloud security leads · managed hosting providers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
cloud.tencent.comin a real browser with your saved login - no setup, no API keys. -
1
Tencent Cloud - read security groups and rules
WebRun opens Tencent Cloud to read security groups and rules. - Sign in to the Tencent Cloud console and list your security groups across each region
- Read the inbound rules on each group and capture the source range, protocol, and port
- Flag any rule whose source is the whole internet rather than a known range
- Match every flagged group to the CVM instances and VPC that use it
Done when Every wide-open inbound rule is listed with its port and the instances behind it.
-
2
Notion - write the exposure audit
WebRun opens Notion to write the exposure audit. - Write this week's exposure audit into your infrastructure page in Notion
- List each open rule with its security group, port, protocol, region, and attached instances
- Sort sensitive ports such as database and remote-access ports to the top
- Note what changed since last Monday, including rules that were closed
Done when The infrastructure page holds a dated audit of every rule open to the internet.
-
3
Twilio - text you on a critical opening
WebRun opens Twilio to text you on a critical opening. - Send an SMS through Twilio to the on-call engineer's own number for critical exposures
- Keep it to one line: the port, the security group, and the instance count behind it
- Only fire on the ports you marked sensitive, so the text still means something
Done when The engineer has been told about any sensitive port open to the world.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it close a rule on its own?
No. WebRun reads security groups and reports what it finds. Closing or narrowing a rule stays a human change, so no automated run can take a live service offline.
Which ports count as critical?
You name them at setup, commonly database, remote desktop, and SSH ports. Only those trigger the Twilio text, and everything else waits in the Notion audit.
Does it cover more than one region?
Yes. WebRun walks each region you grant access to and groups the audit by region and VPC, so a rule left open in a rarely used region still shows up.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.