All templates

Automated Tencent Cloud Security Group Audit

Every Monday, WebRun signs in to Tencent Cloud, walks each security group and its inbound rules, finds the rules open to any source address, matches them to the CVM instances and VPCs they protect, writes the audit into Notion, and texts you through Twilio when a sensitive port is exposed.

Runs on WebRun · Strict Lockdown policy
Every Monday at 7:00 AM WebRunorchestrates each step
1 Tencent Cloud read security groups and rules
2 Notion write the exposure audit
3 Twilio text you on a critical opening
In short

How do I find Tencent Cloud security groups left open to the internet?

Every Monday WebRun signs in to Tencent Cloud, reads every security group and its inbound rules, and finds the ones open to the whole internet on sensitive ports. It writes the audit into Notion with the CVM instances behind each rule and texts you via Twilio when exposure is critical.

  • A port opened for a quick test is caught within the week
  • Every open rule is tied to the instances it exposes
  • Sensitive ports raise a text, everything else waits in the audit

Built for infrastructure engineers · DevOps teams · cloud security leads · managed hosting providers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens cloud.tencent.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Tencent Cloud - read security groups and rules
    cloud.tencent.com
    WebRun in Tencent Cloud: read security groups and rules
    WebRun opens Tencent Cloud to read security groups and rules.
    • Sign in to the Tencent Cloud console and list your security groups across each region
    • Read the inbound rules on each group and capture the source range, protocol, and port
    • Flag any rule whose source is the whole internet rather than a known range
    • Match every flagged group to the CVM instances and VPC that use it

    Done when Every wide-open inbound rule is listed with its port and the instances behind it.

  3. 2
    Notion - write the exposure audit
    notion.so
    WebRun in Notion: write the exposure audit
    WebRun opens Notion to write the exposure audit.
    • Write this week's exposure audit into your infrastructure page in Notion
    • List each open rule with its security group, port, protocol, region, and attached instances
    • Sort sensitive ports such as database and remote-access ports to the top
    • Note what changed since last Monday, including rules that were closed

    Done when The infrastructure page holds a dated audit of every rule open to the internet.

  4. 3
    Twilio - text you on a critical opening
    twilio.com
    WebRun in Twilio: text you on a critical opening
    WebRun opens Twilio to text you on a critical opening.
    • Send an SMS through Twilio to the on-call engineer's own number for critical exposures
    • Keep it to one line: the port, the security group, and the instance count behind it
    • Only fire on the ports you marked sensitive, so the text still means something

    Done when The engineer has been told about any sensitive port open to the world.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
cloud.tencent.com
ScheduleRuns automatically on this cadence
Every Monday at 7:00 AM
DeliveryHow each run's result reaches you
Exposure audit · Notion
OutputWhat each run produces - A weekly audit of inbound rules open to any source, each with its port, security group, region, and instances.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it close a rule on its own?

No. WebRun reads security groups and reports what it finds. Closing or narrowing a rule stays a human change, so no automated run can take a live service offline.

Which ports count as critical?

You name them at setup, commonly database, remote desktop, and SSH ports. Only those trigger the Twilio text, and everything else waits in the Notion audit.

Does it cover more than one region?

Yes. WebRun walks each region you grant access to and groups the audit by region and VPC, so a rule left open in a rarely used region still shows up.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.