<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ECS Security Group :: Ay Docs</title>
    <link>https://ops.docs.72602.space/csp/72602/security-group-auto-update/index.html</link>
    <description>安全组 IP 自动更新 背景 72602-minipc 的 ISP 不定期更换公网 IP，而阿里云 ECS (ecs-99) 安全组限制了 SSH 端口只能从特定 IP 访问。&#xA;当公网 IP 变化时：&#xA;SSH 反向隧道断开 无法通过 ssh aaron@47.110.67.161 -p 10022 访问 无法直接 ssh root@47.110.67.161 解决方案 定时检测公网 IP，变化时统一协调两处 consumer：阿里云 ECS 安全组的 TCP 22 / 10021 / 10022 / 3128 / 56396 与 UDP 51820 规则，以及 ECS 本机 UFW 的 51820/udp（comment wg 72602-minipc）与 3128/tcp （comment squid 72602-minipc）规则。所有云端写操作统一从 72602-minipc 上的同一个 5 分钟 systemd timer 发起；ECS 上只放一个最小化、root-only 的 forced-command 助手负责 UFW 这一侧。</description>
    <generator>Hugo</generator>
    <language>en</language>
    <atom:link href="https://ops.docs.72602.space/csp/72602/security-group-auto-update/index.xml" rel="self" type="application/rss+xml" />
  </channel>
</rss>