It would be good if AWS et al had an easy way to manage third party ip ranges for security groups. When I was deploying a site we came across this issue and so whitelisted Cloudflares ip ranges but it made me uneasy because what happens if a new IP address is added? How do we manage this list and what sort of notice is provided?