See which AWS security groups can reach which, and which are open to the internet. aws-security-viz reads the EC2
security group configuration from the AWS API, or from the JSON written by aws ec2 describe-security-groups, and draws
it as a graph.
- Output formats: a self-contained HTML viewer (the default; offline, with collapsed VPCs, "can X reach Y" queries, several layouts and light and dark themes, see the viewer tour), JSON, Mermaid, DOT, and any image format Graphviz supports.
- One region, several regions, or all regions in a single graph.
- Risky public ingress (
0.0.0.0/0or::/0on a sensitive port) is drawn as a dashed crimson edge, and--fail-on-riskturns it into exit status 2 for CI.
Other formats such as DOT, PNG, SVG and Mermaid are covered in the documentation. Graphviz draws this one:
Documentation: https://anaynayak.github.io/aws-security-viz/
Ruby 3.3 or newer. Graphviz is needed only for image formats such as png and svg.
gem install aws_security_viz
Or run the published image, which has Ruby and Graphviz built in:
docker pull ghcr.io/anaynayak/aws-security-viz:<version>
aws ec2 describe-security-groups > security_groups.json
aws_security_viz -o security_groups.json -f viz.html
Open viz.html in a browser. To query AWS directly, use --profile <profile_name> --region us-west-1 in place of -o.
- Quickstart
- Outputs and the HTML viewer
- Configuration, opts.yml and exit codes
- Credentials and IAM
- Filtering and risk checks, including CI
- Troubleshooting
Also: SECURITY.md, CHANGELOG.md, CONTRIBUTING.md and CODE_OF_CONDUCT.md.
MIT, see LICENSE.md. The HTML viewer inlines vendored copies of Cytoscape.js, cytoscape-fcose, cose-base, layout-base, dagre and cytoscape-dagre, which are also MIT licensed; their notices are under lib/aws_security_viz/vendor/ and ship inside the gem.
