Automate AWS Security Group provisioning from YAML to CloudFormation. Scenario-based templates, override system, security validation, and drift detection. Docker-based, config-driven.
Automate your AWS Security Group infrastructure with ease. SG Provisioner by Axon Tech Labs simplifies complex security group provisioning by transforming human-readable YAML into fully validated CloudFormation templates. It eliminates manual rule configuration errors, ensures architectural consistency across tiers, and handles the heavy lifting of IAM policy generation.
Designed for platform teams, DevOps engineers, network engineers, and cloud architects who need consistent, repeatable Security Group deployments across AWS accounts and regions. Select a pre-built scenario for your architecture (3-tier web, 2-tier web, database-specific variants), apply overrides for your specific requirements, and the tool generates CloudFormation templates with correct cross-tier references and automatic circular dependency resolution.
Key Capabilities:
Scenario-Based Provisioning: Choose from 9 pre-built scenarios covering common 2-tier and 3-tier architectures. Each scenario defines tiers, ingress/egress rules, and cross-tier references - no manual rule writing required.
Override System: Customize base scenarios without creating new YAML files. Override ports, add ingress/egress rules per tier, and the tool merges your changes cleanly.
Security Validation: Built-in validator blocks dangerous patterns before deployment - database ports open to the internet, missing rule descriptions, and references to non-existent tiers.
Safe Deployments: Validates YAML schemas and CloudFormation templates before execution, with support for isolated test deployments and change previews.
Infrastructure Integrity: Detects environment drift via on-demand checks to ensure your live AWS Security Groups stay aligned with your configuration.
Audit-Ready Documentation: Produces pre-deployment review reports (with override highlighting) and post-deployment HTML reports for compliance and internal reviews.
SSM Integration: Stores Security Group IDs in AWS Systems Manager Parameter Store for downstream consumers (EC2, RDS, ECS, Lambda, SageMaker).
12 Actions:
validate-config - Check YAML configuration for schema compliance and syntax errors
list-scenarios - List all available scenario templates
show-scenario - Display the details of the selected scenario
create-policy - Generate and export the least-privilege IAM policy tailored to your resources
create-prov-template - Generate a CloudFormation template based on your configuration and scenario
validate-prov-template - Verify provisioning template syntax and resource references before deployment
create-review-report - Generate a pre-deployment HTML review report with override highlighting
show-changes - Preview projected infrastructure changes before deploying
test-deploy - Run a test deployment with an isolated suffix to verify permissions and resource limits
create-security-groups - Provision all Security Groups via CloudFormation
check-drift - Detect differences between your live environment and defined configuration
delete-security-groups - Remove the CloudFormation stack and all associated Security Groups permanently
How It Works:
Configure: Select a scenario and define your overrides in a simple YAML file
Execute: Run the Docker container with your config mounted
Review: Generate your CloudFormation template and review report, then validate before deploying
Deploy: Deploy to AWS via CloudFormation for immediate, reliable Security Group creation
Technical Requirements:
Docker 20.10 or later
AWS account with EC2, CloudFormation, and SSM permissions
AWS credentials (access key or IAM role)
VPC deployed and VPC ID available
512 MB RAM minimum
Highlights
<ul><li><b>9 Pre-Built Scenarios</b> - 3-tier and 2-tier architectures for PostgreSQL, MySQL, Redshift, Oracle, SQL Server, DocumentDB, and generic web.</li><li><b>Override System</b> - Customize port numbers and add rules without creating new scenario files.</li><li><b>Security Validation</b> - Blocks dangerous patterns (open DB ports, missing descriptions) before deployment.</li></ul>
<ul><li><b>Circular Dependency Resolution</b> - Cross-tier references automatically generated as standalone resources.</li><li><b>SSM Parameter Store Integration</b> - SG IDs stored for downstream consumers (EC2, RDS, ECS, Lambda, SageMaker).</li><li><b>Drift Detection</b> - Identify manual changes to deployed Security Groups.</li><li><b>Workload Discriminator</b> - Deploy multiple SG sets in the same environment without naming collisions.</li></ul>
<ul><li><b>CloudFormation Native</b> - Standard AWS CloudFormation templates you own, inspect, and customize.</li><li><b>Least-Privilege IAM</b> - Auto-generated IAM policies scoped to your specific deployment.</li><li><b>Pre-Deployment Review Reports</b> - HTML reports with override highlighting for stakeholder review.</li><li><b>Docker-Based</b> - Consistent execution across any environment.</li><li><b>YAML Configuration</b> - Infrastructure-as-code friendly, version controllable.</li></ul>
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing bills through a single contract dimension measured in units. You subscribe to SG Provisioner and pay one committed rate for the tool's security group provisioning capability. There are no separate tiers, instance sizes, or usage-based add-ons to choose between. The unit represents access to the tool itself, which you run to build scenario-based security group templates. Pricing does not scale by the number of security groups, scenarios, or workloads you deploy. You get one flat structure covering all provisioning actions available in the tool.
Top-of-mind questions for buyers
What does one unit of SG Provisioner give me access to?
One unit gives you access to the SG Provisioner tool, run as a Docker container. You use it to build, validate, and deploy security groups from 9 pre-built architecture scenarios, including 2-tier, 3-tier, RDS, DocumentDB, and Redshift patterns. AWS credentials are required for license validation on most actions.
Does my cost increase if I deploy more security group sets or workloads in the same VPC?
No. You can deploy multiple named security group sets in one VPC using the workload discriminator, each with its own CloudFormation stack and SSM parameters. The unit covers tool access, so the number of workloads, scenarios, or security groups you deploy does not change what you pay.
Is this billed hourly by usage or as a committed subscription?
This is a contract subscription, not usage-based hourly billing. You commit to a fixed rate for tool access rather than paying per action or per hour of runtime. Running commands like validate, test-deploy, or create-security-groups does not meter separate charges.
docs.axontechlabs.com+1
Helpful?
Vendor refund policy
30-day money-back guarantee for monthly subscriptions. Pro-rated refunds for annual subscriptions within first 30 days.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Version 1.2.1 Release Notes
New Features
Example configuration files now bundled inside the Docker image at /app/examples/configs/. Three globalbank examples covering SSM VPC resolution (3-tier), direct VPC resolution (3-tier with overrides), and SSM VPC resolution (2-tier). Extract with:
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
ZEDOC's Inflammatory Arthritis Digital Care Pathway automates the collection and analysis of patient-reported outcomes according to ICHOM's validated Standard Set - helping you to measure, monitor, and improve care from the patient's perspective.
ZEDOC's Cataract Surgery Digital Care Pathway automates the collection and analysis of patient-reported outcomes according to ICHOM's validated Standard Set - helping you to measure and assess the impact of cataract surgery on visual function from the patient's perspective.
ZEDOC's COVID-19 Digital Care Pathway is an end-to-end solution for remote monitoring of individuals with suspected for confirmed COVID-19. Automating the collection and analysis of COVID-19 symptoms, the pathway alerts clinical teams of deterioration as it happens.
ZEDOC's Localised Prostate Cancer Digital Care Pathway automates the collection and analysis of patient-reported outcome measures (PROMs) according to ICHOM's validated Standard Set - helping you to measure, assess, and improve care from the patient's perspective.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.