From 90906a3c78f1105753761c6680ee170a46623665 Mon Sep 17 00:00:00 2001 From: space Date: Sun, 26 Jul 2026 19:11:41 +0200 Subject: [PATCH] fix: open preview security groups by default Co-Authored-By: Codex --- SPEC.md | 2 +- backend/src/services/ec2.ts | 44 ++++++++++++++++++------------------- 2 files changed, 23 insertions(+), 23 deletions(-) diff --git a/SPEC.md b/SPEC.md index b58a592d..86ce9c4b 100644 --- a/SPEC.md +++ b/SPEC.md @@ -177,7 +177,7 @@ pp:previewId = **EC2 setup per preview:** 1. Generate an ephemeral RSA key pair. Store the private key encrypted in `Preview.sshPrivateKey`. Import the public key to AWS as `pp-preview-` and store the name in `Preview.sshKeyName`. -2. Create a security group named `pp-preview-` in the default VPC. Allow inbound: TCP 22 (SSH) and TCP `` from `0.0.0.0/0`. +2. Create a security group named `pp-preview-` in the default VPC. Allow inbound: all traffic from `0.0.0.0/0` and `::/0` (all protocols, including ICMP, and all ports). 3. Launch instance: - AMI: Ubuntu 22.04 LTS (hardcode a per-region AMI map, or resolve via SSM `resolve:ssm:/aws/service/canonical/ubuntu/server/22.04/stable/current/amd64/hvm/ebs-gp2/ami-id`) - Instance type from `RepoConfig.instanceType` diff --git a/backend/src/services/ec2.ts b/backend/src/services/ec2.ts index a065e818..63ae89c5 100644 --- a/backend/src/services/ec2.ts +++ b/backend/src/services/ec2.ts @@ -84,7 +84,9 @@ export async function createPreviewSecurityGroup(ec2: EC2Client, groupName: stri Filters: [{ Name: "group-name", Values: [groupName] }], })); if (describe.SecurityGroups && describe.SecurityGroups.length > 0) { - return describe.SecurityGroups[0].GroupId!; + const groupId = describe.SecurityGroups[0].GroupId!; + await ensurePreviewSecurityGroupOpen(ec2, groupId); + return groupId; } const res = await ec2.send(new CreateSecurityGroupCommand({ @@ -93,30 +95,28 @@ export async function createPreviewSecurityGroup(ec2: EC2Client, groupName: stri })); const groupId = res.GroupId!; - const ingress: any[] = [ - { - IpProtocol: "tcp", - FromPort: 22, - ToPort: 22, - IpRanges: [{ CidrIp: "0.0.0.0/0" }], - }, - ]; - if (port !== 22) { - ingress.push({ - IpProtocol: "tcp", - FromPort: port, - ToPort: port, - IpRanges: [{ CidrIp: "0.0.0.0/0" }], - }); - } - - await ec2.send(new AuthorizeSecurityGroupIngressCommand({ - GroupId: groupId, - IpPermissions: ingress, - })); + await ensurePreviewSecurityGroupOpen(ec2, groupId); return groupId; } +async function ensurePreviewSecurityGroupOpen(ec2: EC2Client, groupId: string): Promise { + try { + await ec2.send(new AuthorizeSecurityGroupIngressCommand({ + GroupId: groupId, + IpPermissions: [ + { + IpProtocol: "-1", + IpRanges: [{ CidrIp: "0.0.0.0/0" }], + Ipv6Ranges: [{ CidrIpv6: "::/0" }], + }, + ], + })); + } catch (e: any) { + if (e.name === "InvalidPermission.Duplicate") return; + throw e; + } +} + const BOOTSTRAP_SCRIPT = `#!/bin/bash set -euo pipefail exec > >(tee -a /var/log/pp-bootstrap.log) 2>&1 -- 2.39.5